2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-18976 | MEDIUM | 5.5 | 0.7% | Aug 25, 2021 | Buffer Overflow in Tcpreplay v4.3.2 allows attackers to cause a Denial of Service via the 'do_checksum' function in 'che... |
| CVE-2020-18972 | MEDIUM | 5.5 | 0.8% | Aug 25, 2021 | Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive informa... |
| CVE-2020-18971 | MEDIUM | 5.5 | 0.7% | Aug 25, 2021 | Stack-based Buffer Overflow in PoDoFo v0.9.6 allows attackers to cause a denial of service via the component 'src/base/P... |
| CVE-2020-18778 | MEDIUM | 6.5 | 0.9% | Aug 23, 2021 | In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_p_mb_intfi in vc1_block.c that allows an attacker to... |
| CVE-2020-18776 | MEDIUM | 6.5 | 0.9% | Aug 23, 2021 | In Libav 12.3, there is a segmentation fault in vc1_decode_b_mb_intfr in vc1_block.c that allows an attacker to cause de... |
| CVE-2020-18775 | MEDIUM | 6.5 | 0.9% | Aug 23, 2021 | In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_b_mb_intfi in vc1_block.c that allows an attacker to... |
| CVE-2020-18774 | MEDIUM | 6.5 | 1.3% | Aug 23, 2021 | A float point exception in the printLong function in tags_int.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial ... |
| CVE-2020-18773 | MEDIUM | 6.5 | 1.3% | Aug 23, 2021 | An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of ser... |
| CVE-2020-36477 | MEDIUM | 5.9 | 0.8% | Aug 23, 2021 | An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 certificates when matching the expected com... |
| CVE-2020-25353 | MEDIUM | 6.5 | 1.0% | Aug 20, 2021 | A server-side request forgery (SSRF) vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability allowed... |
| CVE-2020-25352 | MEDIUM | 5.4 | 2.0% | Aug 20, 2021 | A stored cross-site scripting (XSS) vulnerability in the /devices.php function inrConfig 3.9.5 has been fixed for versio... |
| CVE-2020-25351 | MEDIUM | 6.5 | 1.1% | Aug 20, 2021 | An information disclosure vulnerability in rConfig 3.9.5 has been fixed for version 3.9.6. This vulnerability allowed re... |
| CVE-2020-18878 | MEDIUM | 5.3 | 2.0% | Aug 20, 2021 | Directory Traversal in Skycaiji v1.3 allows remote attackers to obtain sensitive information via the component 'index.ph... |
| CVE-2020-18899 | MEDIUM | 6.5 | 1.7% | Aug 19, 2021 | An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to c... |
| CVE-2020-18898 | MEDIUM | 6.5 | 1.4% | Aug 19, 2021 | A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of se... |
| CVE-2020-20645 | MEDIUM | 5.4 | 0.5% | Aug 19, 2021 | Cross Site Scripting (XSS) vulnerability exists in EyouCMS1.3.6 in the basic_information area. |
| CVE-2020-18748 | MEDIUM | 6.1 | 0.9% | Aug 19, 2021 | Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a math... |
| CVE-2020-28146 | MEDIUM | 6.1 | 1.5% | Aug 18, 2021 | Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter. |
| CVE-2020-23069 | MEDIUM | 6.5 | 1.6% | Aug 18, 2021 | Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a mal... |
| CVE-2020-23341 | MEDIUM | 6.1 | 0.8% | Aug 17, 2021 | A reflected cross site scripting (XSS) vulnerability in the /header.tmpl.php component of ATutor 2.2.4 allows attackers ... |
| CVE-2020-15955 | MEDIUM | 5.9 | 0.9% | Aug 17, 2021 | In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session betw... |
| CVE-2020-28846 | MEDIUM | 6.5 | 0.4% | Aug 17, 2021 | Cross Site Request Forgery (CSRF) vulnerability exists in SeaCMS 10.7 in admin_manager.php, which could let a malicious ... |
| CVE-2020-4992 | MEDIUM | 6.5 | 0.4% | Aug 17, 2021 | IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.16 is vulnerable to cross-site request forgery which could allow an at... |
| CVE-2020-4706 | MEDIUM | 5.4 | 0.9% | Aug 17, 2021 | IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to HTTP header injection, caused by improper validation of input ... |
| CVE-2020-18702 | MEDIUM | 6.1 | 1.3% | Aug 16, 2021 | Cross Site Scripting (XSS) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the 'Username' paramet... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now