2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-21529 | MEDIUM | 5.5 | 1.1% | Sep 16, 2021 | fig2dev 3.2.7b contains a stack buffer overflow in the bezier_spline function in genepic.c. |
| CVE-2020-14130 | MEDIUM | 5.3 | 0.7% | Sep 16, 2021 | Some js interfaces in the Xiaomi community were exposed, causing sensitive functions to be maliciously called on Xiaomi ... |
| CVE-2020-21482 | MEDIUM | 5.4 | 0.6% | Sep 15, 2021 | A cross-site scripting (XSS) vulnerability in RGCMS v1.06 allows attackers to obtain the administrator's cookie via a cr... |
| CVE-2020-21321 | MEDIUM | 4.3 | 0.5% | Sep 15, 2021 | emlog v6.0 contains a Cross-Site Request Forgery (CSRF) via /admin/link.php?action=addlink, which allows attackers to ar... |
| CVE-2020-21122 | MEDIUM | 5.3 | 0.8% | Sep 15, 2021 | UReport v2.2.9 contains a Server-Side Request Forgery (SSRF) in the designer page which allows attackers to detect intra... |
| CVE-2020-19158 | MEDIUM | 5.4 | 0.7% | Sep 15, 2021 | Cross Site Scripting (XSS) in S-CMS build 20191014 and earlier allows remote attackers to execute arbitrary code via the... |
| CVE-2020-19157 | MEDIUM | 6.1 | 1.0% | Sep 15, 2021 | Cross Site Scripting (CSS) in Wenku CMS v3.4 allows remote attackers to execute arbitrary code via the 'Intro' parameter... |
| CVE-2020-19156 | MEDIUM | 5.4 | 0.8% | Sep 15, 2021 | Cross Site Scripting (XSS) in Ari Adminer v1 allows remote attackers to execute arbitrary code via the 'Title' parameter... |
| CVE-2020-19154 | MEDIUM | 6.5 | 3.6% | Sep 15, 2021 | Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the... |
| CVE-2020-19148 | MEDIUM | 5.4 | 1.0% | Sep 15, 2021 | Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'N... |
| CVE-2020-19147 | MEDIUM | 6.5 | 1.6% | Sep 15, 2021 | Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the... |
| CVE-2020-19146 | MEDIUM | 6.5 | 1.8% | Sep 15, 2021 | Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the... |
| CVE-2020-21082 | MEDIUM | 6.1 | 0.6% | Sep 14, 2021 | A cross-site scripting (XSS) vulnerability in the background administrator article management module of Maccms 8.0 allow... |
| CVE-2020-21081 | MEDIUM | 6.5 | 0.4% | Sep 14, 2021 | A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowled... |
| CVE-2020-21050 | MEDIUM | 6.5 | 1.5% | Sep 14, 2021 | Libsixel prior to v1.8.3 contains a stack buffer overflow in the function gif_process_raster at fromgif.c. |
| CVE-2020-21049 | MEDIUM | 6.5 | 1.3% | Sep 14, 2021 | An invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (... |
| CVE-2020-21048 | MEDIUM | 6.5 | 1.3% | Sep 14, 2021 | An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a... |
| CVE-2020-27970 | MEDIUM | 5.3 | 1.3% | Sep 13, 2021 | Yandex Browser before 20.10.0 allows remote attackers to spoof the address bar |
| CVE-2020-19295 | MEDIUM | 6.1 | 3.3% | Sep 9, 2021 | A reflected cross-site scripting (XSS) vulnerability in the /weibo/topic component of Jeesns 1.4.2 allows attackers to e... |
| CVE-2020-19294 | MEDIUM | 5.4 | 0.5% | Sep 9, 2021 | A stored cross-site scripting (XSS) vulnerability in the /article/comment component of Jeesns 1.4.2 allows attackers to ... |
| CVE-2020-19293 | MEDIUM | 5.4 | 0.5% | Sep 9, 2021 | A stored cross-site scripting (XSS) vulnerability in the /article/add component of Jeesns 1.4.2 allows attackers to exec... |
| CVE-2020-19292 | MEDIUM | 5.4 | 0.5% | Sep 9, 2021 | A stored cross-site scripting (XSS) vulnerability in the /question/ask component of Jeesns 1.4.2 allows attackers to exe... |
| CVE-2020-19291 | MEDIUM | 5.4 | 0.6% | Sep 9, 2021 | A stored cross-site scripting (XSS) vulnerability in the /weibo/publishdata component of Jeesns 1.4.2 allows attackers t... |
| CVE-2020-19290 | MEDIUM | 5.4 | 0.5% | Sep 9, 2021 | A stored cross-site scripting (XSS) vulnerability in the /weibo/comment component of Jeesns 1.4.2 allows attackers to ex... |
| CVE-2020-19289 | MEDIUM | 5.4 | 0.6% | Sep 9, 2021 | A stored cross-site scripting (XSS) vulnerability in the /member/picture/album component of Jeesns 1.4.2 allows attacker... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now