2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-18976MEDIUM5.5Buffer Overflow in Tcpreplay v4.3.2 allows attackers to cause a Denial of Service via the 'do_checksum' function in 'che...
CVE-2020-18972MEDIUM5.5Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive informa...
CVE-2020-18971MEDIUM5.5Stack-based Buffer Overflow in PoDoFo v0.9.6 allows attackers to cause a denial of service via the component 'src/base/P...
CVE-2020-18778MEDIUM6.5In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_p_mb_intfi in vc1_block.c that allows an attacker to...
CVE-2020-18776MEDIUM6.5In Libav 12.3, there is a segmentation fault in vc1_decode_b_mb_intfr in vc1_block.c that allows an attacker to cause de...
CVE-2020-18775MEDIUM6.5In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_b_mb_intfi in vc1_block.c that allows an attacker to...
CVE-2020-18774MEDIUM6.5A float point exception in the printLong function in tags_int.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial ...
CVE-2020-18773MEDIUM6.5An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of ser...
CVE-2020-36477MEDIUM5.9An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 certificates when matching the expected com...
CVE-2020-25353MEDIUM6.5A server-side request forgery (SSRF) vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability allowed...
CVE-2020-25352MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /devices.php function inrConfig 3.9.5 has been fixed for versio...
CVE-2020-25351MEDIUM6.5An information disclosure vulnerability in rConfig 3.9.5 has been fixed for version 3.9.6. This vulnerability allowed re...
CVE-2020-18878MEDIUM5.3Directory Traversal in Skycaiji v1.3 allows remote attackers to obtain sensitive information via the component 'index.ph...
CVE-2020-18899MEDIUM6.5An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to c...
CVE-2020-18898MEDIUM6.5A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of se...
CVE-2020-20645MEDIUM5.4Cross Site Scripting (XSS) vulnerability exists in EyouCMS1.3.6 in the basic_information area.
CVE-2020-18748MEDIUM6.1Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a math...
CVE-2020-28146MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.
CVE-2020-23069MEDIUM6.5Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a mal...
CVE-2020-23341MEDIUM6.1A reflected cross site scripting (XSS) vulnerability in the /header.tmpl.php component of ATutor 2.2.4 allows attackers ...
CVE-2020-15955MEDIUM5.9In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session betw...
CVE-2020-28846MEDIUM6.5Cross Site Request Forgery (CSRF) vulnerability exists in SeaCMS 10.7 in admin_manager.php, which could let a malicious ...
CVE-2020-4992MEDIUM6.5IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.16 is vulnerable to cross-site request forgery which could allow an at...
CVE-2020-4706MEDIUM5.4IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to HTTP header injection, caused by improper validation of input ...
CVE-2020-18702MEDIUM6.1Cross Site Scripting (XSS) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the 'Username' paramet...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now