2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-19288 | MEDIUM | 5.4 | 0.5% | Sep 9, 2021 | A stored cross-site scripting (XSS) vulnerability in the /localhost/u component of Jeesns 1.4.2 allows attackers to exec... |
| CVE-2020-19287 | MEDIUM | 5.4 | 0.6% | Sep 9, 2021 | A stored cross-site scripting (XSS) vulnerability in the /group/post component of Jeesns 1.4.2 allows attackers to execu... |
| CVE-2020-19286 | MEDIUM | 5.4 | 0.5% | Sep 9, 2021 | A stored cross-site scripting (XSS) vulnerability in the /question/detail component of Jeesns 1.4.2 allows attackers to ... |
| CVE-2020-19285 | MEDIUM | 5.4 | 0.6% | Sep 9, 2021 | A stored cross-site scripting (XSS) vulnerability in the /group/apply component of Jeesns 1.4.2 allows attackers to exec... |
| CVE-2020-19284 | MEDIUM | 5.4 | 0.5% | Sep 9, 2021 | A stored cross-site scripting (XSS) vulnerability in the /group/comment component of Jeesns 1.4.2 allows attackers to ex... |
| CVE-2020-19283 | MEDIUM | 6.1 | 3.0% | Sep 9, 2021 | A reflected cross-site scripting (XSS) vulnerability in the /newVersion component of Jeesns 1.4.2 allows attackers to ex... |
| CVE-2020-19282 | MEDIUM | 6.1 | 3.0% | Sep 9, 2021 | A reflected cross-site scripting (XSS) vulnerability in Jeesns 1.4.2 allows attackers to execute arbitrary web scripts o... |
| CVE-2020-19281 | MEDIUM | 5.4 | 0.5% | Sep 9, 2021 | A stored cross-site scripting (XSS) vulnerability in the /manage/loginusername component of Jeesns 1.4.2 allows attacker... |
| CVE-2020-19268 | MEDIUM | 5.7 | 0.3% | Sep 9, 2021 | A cross-site request forgery (CSRF) in index.php/Dswjcms/User/tfAdd of Dswjcms 1.6.4 allows authenticated attackers to a... |
| CVE-2020-19266 | MEDIUM | 6.1 | 0.6% | Sep 9, 2021 | A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Site/articleList component of Dswjcms 1.6.4 a... |
| CVE-2020-19265 | MEDIUM | 6.1 | 0.6% | Sep 9, 2021 | A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Basis/links component of Dswjcms 1.6.4 allows... |
| CVE-2020-19264 | MEDIUM | 6.5 | 0.5% | Sep 9, 2021 | A cross-site request forgery (CSRF) in MipCMS v5.0.1 allows attackers to arbitrarily add users via index.php?s=/user/Api... |
| CVE-2020-19515 | MEDIUM | 6.1 | 2.0% | Sep 9, 2021 | qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php. |
| CVE-2020-19144 | MEDIUM | 6.5 | 1.5% | Sep 9, 2021 | Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the 'in _TIFFmemcpy' funtion in the... |
| CVE-2020-19143 | MEDIUM | 6.5 | 1.4% | Sep 9, 2021 | Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "TIFFVGetField" funtion in the ... |
| CVE-2020-27940 | MEDIUM | 4.3 | 0.7% | Sep 8, 2021 | This issue was addressed with improved file handling. This issue is fixed in Apple TV app for Fire OS 6.1.0.6A142:7.1.0.... |
| CVE-2020-29012 | MEDIUM | 5.3 | 0.5% | Sep 8, 2021 | An insufficient session expiration vulnerability in FortiSandbox versions 3.2.1 and below may allow an attacker to reuse... |
| CVE-2020-19855 | MEDIUM | 6.1 | 0.6% | Sep 8, 2021 | phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php. |
| CVE-2020-15939 | MEDIUM | 4.3 | 0.6% | Sep 6, 2021 | An improper access control vulnerability (CWE-284) in FortiSandbox versions 3.2.1 and below and 3.1.4 and below may allo... |
| CVE-2020-20349 | MEDIUM | 5.4 | 0.5% | Sep 1, 2021 | WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background link... |
| CVE-2020-20348 | MEDIUM | 5.4 | 0.5% | Sep 1, 2021 | WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu managem... |
| CVE-2020-20347 | MEDIUM | 5.4 | 0.5% | Sep 1, 2021 | WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management mo... |
| CVE-2020-20345 | MEDIUM | 5.4 | 0.7% | Sep 1, 2021 | WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows ... |
| CVE-2020-20344 | MEDIUM | 5.4 | 0.5% | Sep 1, 2021 | WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search function under the backgr... |
| CVE-2020-20343 | MEDIUM | 6.5 | 0.4% | Sep 1, 2021 | WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now