2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-21529MEDIUM5.5fig2dev 3.2.7b contains a stack buffer overflow in the bezier_spline function in genepic.c.
CVE-2020-14130MEDIUM5.3Some js interfaces in the Xiaomi community were exposed, causing sensitive functions to be maliciously called on Xiaomi ...
CVE-2020-21482MEDIUM5.4A cross-site scripting (XSS) vulnerability in RGCMS v1.06 allows attackers to obtain the administrator's cookie via a cr...
CVE-2020-21321MEDIUM4.3emlog v6.0 contains a Cross-Site Request Forgery (CSRF) via /admin/link.php?action=addlink, which allows attackers to ar...
CVE-2020-21122MEDIUM5.3UReport v2.2.9 contains a Server-Side Request Forgery (SSRF) in the designer page which allows attackers to detect intra...
CVE-2020-19158MEDIUM5.4Cross Site Scripting (XSS) in S-CMS build 20191014 and earlier allows remote attackers to execute arbitrary code via the...
CVE-2020-19157MEDIUM6.1Cross Site Scripting (CSS) in Wenku CMS v3.4 allows remote attackers to execute arbitrary code via the 'Intro' parameter...
CVE-2020-19156MEDIUM5.4Cross Site Scripting (XSS) in Ari Adminer v1 allows remote attackers to execute arbitrary code via the 'Title' parameter...
CVE-2020-19154MEDIUM6.5Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the...
CVE-2020-19148MEDIUM5.4Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'N...
CVE-2020-19147MEDIUM6.5Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the...
CVE-2020-19146MEDIUM6.5Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the...
CVE-2020-21082MEDIUM6.1A cross-site scripting (XSS) vulnerability in the background administrator article management module of Maccms 8.0 allow...
CVE-2020-21081MEDIUM6.5A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowled...
CVE-2020-21050MEDIUM6.5Libsixel prior to v1.8.3 contains a stack buffer overflow in the function gif_process_raster at fromgif.c.
CVE-2020-21049MEDIUM6.5An invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (...
CVE-2020-21048MEDIUM6.5An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a...
CVE-2020-27970MEDIUM5.3Yandex Browser before 20.10.0 allows remote attackers to spoof the address bar
CVE-2020-19295MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the /weibo/topic component of Jeesns 1.4.2 allows attackers to e...
CVE-2020-19294MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /article/comment component of Jeesns 1.4.2 allows attackers to ...
CVE-2020-19293MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /article/add component of Jeesns 1.4.2 allows attackers to exec...
CVE-2020-19292MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /question/ask component of Jeesns 1.4.2 allows attackers to exe...
CVE-2020-19291MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /weibo/publishdata component of Jeesns 1.4.2 allows attackers t...
CVE-2020-19290MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /weibo/comment component of Jeesns 1.4.2 allows attackers to ex...
CVE-2020-19289MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /member/picture/album component of Jeesns 1.4.2 allows attacker...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now