2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-18699MEDIUM6.1Cross Site Scripting (XSS) in Lin-CMS-Flask v0.1.1 allows remote attackers to execute arbitrary code by entering scripts...
CVE-2020-21066MEDIUM6.5An issue was discovered in Bento4 v1.5.1.0. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom...
CVE-2020-20990MEDIUM5.4A cross site scripting (XSS) vulnerability in the /segments/edit.php component of Domainmod 4.13 allows attackers to exe...
CVE-2020-20989MEDIUM4.3A cross-site request forgery (CSRF) in /admin/maintenance/ of Domainmod 4.13 allows attackers to arbitrarily delete logs...
CVE-2020-20988MEDIUM5.4A cross site scripting (XSS) vulnerability in the /domains/cost-by-owner.php component of Domainmod 4.13 allows attacker...
CVE-2020-18457MEDIUM6.8Cross Site Request Forgery (CSRF) vulnerability exists in bycms v1.3.0 that can add an admin account via admin.php/ucent...
CVE-2020-18456MEDIUM4.8Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in Single...
CVE-2020-18455MEDIUM4.8Cross Site Scripting (XSS) vulnerability exists in bycms v3.0.4 via the title parameter in the edit function in Document...
CVE-2020-18454MEDIUM6.8Cross Site Request Forgery (CSRF) vulnerability in bycms v1.3 via admin.php/systems/index/module_id/70/group_id/1.html.
CVE-2020-18451MEDIUM4.8Cross Site Scripting (XSS) vulnerability exists in DamiCMS v6.0.6 via the title parameter in the doadd function in Label...
CVE-2020-18449MEDIUM5.4Cross Site Scripting (XSS) vulnerability exists in UKCMS v1.1.10 via data in the index function in Single.php
CVE-2020-18446MEDIUM4.8Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the param parameter in the insertContent function i...
CVE-2020-18445MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the upurl function in Page.php.
CVE-2020-20977MEDIUM5.4A stored cross site scripting (XSS) vulnerability in index.php/legend/6.html of UK CMS v1.1.10 allows attackers to execu...
CVE-2020-25562MEDIUM6.5In SapphireIMS 5.0, there is no CSRF token present in the entire application. This can lead to CSRF vulnerabilities in c...
CVE-2020-21363MEDIUM6.5An arbitrary file deletion vulnerability exists within Maccms10.
CVE-2020-21362MEDIUM5.4A cross site scripting (XSS) vulnerability in the background search function of Maccms10 allows attackers to execute arb...
CVE-2020-21930MEDIUM5.4A stored cross site scripting (XSS) vulnerability in the web_attr_2 field of Eyoucms v1.4.1 allows authenticated attacke...
CVE-2020-21929MEDIUM5.4A stored cross site scripting (XSS) vulnerability in the web_copyright field of Eyoucms v1.4.1 allows authenticated atta...
CVE-2020-21697MEDIUM6.5A heap-use-after-free in the mpeg_mux_write_packet function in libavformat/mpegenc.c of FFmpeg 4.2 allows to cause a den...
CVE-2020-21684MEDIUM5.5A global buffer overflow in the put_font in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service ...
CVE-2020-21683MEDIUM5.5A global buffer overflow in the shade_or_tint_name_after_declare_color in genpstricks.c of fig2dev 3.2.7b allows attacke...
CVE-2020-21682MEDIUM5.5A global buffer overflow in the set_fill component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of se...
CVE-2020-21681MEDIUM5.5A global buffer overflow in the set_color component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of s...
CVE-2020-21680MEDIUM5.5A stack-based buffer overflow in the put_arrow() component in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now