2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-18699 | MEDIUM | 6.1 | 1.3% | Aug 16, 2021 | Cross Site Scripting (XSS) in Lin-CMS-Flask v0.1.1 allows remote attackers to execute arbitrary code by entering scripts... |
| CVE-2020-21066 | MEDIUM | 6.5 | 0.8% | Aug 13, 2021 | An issue was discovered in Bento4 v1.5.1.0. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom... |
| CVE-2020-20990 | MEDIUM | 5.4 | 0.6% | Aug 12, 2021 | A cross site scripting (XSS) vulnerability in the /segments/edit.php component of Domainmod 4.13 allows attackers to exe... |
| CVE-2020-20989 | MEDIUM | 4.3 | 0.5% | Aug 12, 2021 | A cross-site request forgery (CSRF) in /admin/maintenance/ of Domainmod 4.13 allows attackers to arbitrarily delete logs... |
| CVE-2020-20988 | MEDIUM | 5.4 | 1.3% | Aug 12, 2021 | A cross site scripting (XSS) vulnerability in the /domains/cost-by-owner.php component of Domainmod 4.13 allows attacker... |
| CVE-2020-18457 | MEDIUM | 6.8 | 0.5% | Aug 12, 2021 | Cross Site Request Forgery (CSRF) vulnerability exists in bycms v1.3.0 that can add an admin account via admin.php/ucent... |
| CVE-2020-18456 | MEDIUM | 4.8 | 0.5% | Aug 12, 2021 | Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in Single... |
| CVE-2020-18455 | MEDIUM | 4.8 | 0.5% | Aug 12, 2021 | Cross Site Scripting (XSS) vulnerability exists in bycms v3.0.4 via the title parameter in the edit function in Document... |
| CVE-2020-18454 | MEDIUM | 6.8 | 0.5% | Aug 12, 2021 | Cross Site Request Forgery (CSRF) vulnerability in bycms v1.3 via admin.php/systems/index/module_id/70/group_id/1.html. |
| CVE-2020-18451 | MEDIUM | 4.8 | 0.5% | Aug 12, 2021 | Cross Site Scripting (XSS) vulnerability exists in DamiCMS v6.0.6 via the title parameter in the doadd function in Label... |
| CVE-2020-18449 | MEDIUM | 5.4 | 0.5% | Aug 12, 2021 | Cross Site Scripting (XSS) vulnerability exists in UKCMS v1.1.10 via data in the index function in Single.php |
| CVE-2020-18446 | MEDIUM | 4.8 | 0.5% | Aug 12, 2021 | Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the param parameter in the insertContent function i... |
| CVE-2020-18445 | MEDIUM | 6.1 | 0.7% | Aug 12, 2021 | Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the upurl function in Page.php. |
| CVE-2020-20977 | MEDIUM | 5.4 | 0.5% | Aug 12, 2021 | A stored cross site scripting (XSS) vulnerability in index.php/legend/6.html of UK CMS v1.1.10 allows attackers to execu... |
| CVE-2020-25562 | MEDIUM | 6.5 | 0.5% | Aug 11, 2021 | In SapphireIMS 5.0, there is no CSRF token present in the entire application. This can lead to CSRF vulnerabilities in c... |
| CVE-2020-21363 | MEDIUM | 6.5 | 0.8% | Aug 11, 2021 | An arbitrary file deletion vulnerability exists within Maccms10. |
| CVE-2020-21362 | MEDIUM | 5.4 | 0.5% | Aug 11, 2021 | A cross site scripting (XSS) vulnerability in the background search function of Maccms10 allows attackers to execute arb... |
| CVE-2020-21930 | MEDIUM | 5.4 | 0.5% | Aug 10, 2021 | A stored cross site scripting (XSS) vulnerability in the web_attr_2 field of Eyoucms v1.4.1 allows authenticated attacke... |
| CVE-2020-21929 | MEDIUM | 5.4 | 0.5% | Aug 10, 2021 | A stored cross site scripting (XSS) vulnerability in the web_copyright field of Eyoucms v1.4.1 allows authenticated atta... |
| CVE-2020-21697 | MEDIUM | 6.5 | 0.9% | Aug 10, 2021 | A heap-use-after-free in the mpeg_mux_write_packet function in libavformat/mpegenc.c of FFmpeg 4.2 allows to cause a den... |
| CVE-2020-21684 | MEDIUM | 5.5 | 0.8% | Aug 10, 2021 | A global buffer overflow in the put_font in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service ... |
| CVE-2020-21683 | MEDIUM | 5.5 | 0.8% | Aug 10, 2021 | A global buffer overflow in the shade_or_tint_name_after_declare_color in genpstricks.c of fig2dev 3.2.7b allows attacke... |
| CVE-2020-21682 | MEDIUM | 5.5 | 0.9% | Aug 10, 2021 | A global buffer overflow in the set_fill component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of se... |
| CVE-2020-21681 | MEDIUM | 5.5 | 0.8% | Aug 10, 2021 | A global buffer overflow in the set_color component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of s... |
| CVE-2020-21680 | MEDIUM | 5.5 | 0.7% | Aug 10, 2021 | A stack-based buffer overflow in the put_arrow() component in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now