2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-22403HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in Express cart v1.1.16 allows attackers to add an administrator account...
CVE-2020-18462HIGH7.2File Upload vulnerabilty in AikCms v2.0.0 in poster_edit.php because the background file management office does not veri...
CVE-2020-18460HIGH8.8Cross Site Request Forgery (CSRF) vulnerability exists in 711cms v1.0.7 that can add an admin account via admin.php?c=Ad...
CVE-2020-18458HIGH8Cross Site Request Forgery (CSRF) vulnerability exists in DamiCMS v6.0.6 that can add an admin account via admin.php?s=/...
CVE-2020-20981HIGH7.5A SQL injection in the /admin/?n=logs&c=index&a=dolist component of Metinfo 7.0 allows attackers to access sensitive dat...
CVE-2020-24576HIGH8.8Netskope Client through 77 allows low-privileged users to elevate their privileges to NT AUTHORITY\SYSTEM.
CVE-2020-25564HIGH8.8In SapphireIMS 5.0, it is possible to create local administrator on any client with credentials of a non-privileged user...
CVE-2020-25561HIGH7.8SapphireIMS 5 utilized default sapphire:ims credentials to connect the client to server. This credential is saved in Ser...
CVE-2020-21976HIGH8.8An arbitrary file upload in the <input type="file" name="user_image"> component of NewsOne CMS v1.1.0 allows attackers t...
CVE-2020-28589HIGH8.8An improper array index validation vulnerability exists in the LoadObj functionality of tinyobjloader v2.0-rc1 and tinyo...
CVE-2020-21688HIGH8.8A heap-use-after-free in the av_freep function in libavutil/mem.c of FFmpeg 4.2 allows attackers to execute arbitrary co...
CVE-2020-23150HIGH7.5A SQL injection vulnerability in config.inc.php of rConfig 3.9.5 allows attackers to access sensitive database informati...
CVE-2020-23149HIGH7.5The dbName parameter in ajaxDbInstall.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a SQL injection...
CVE-2020-23148HIGH7.5The userLogin parameter in ldap/login.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a LDAP injectio...
CVE-2020-24742HIGH7.8An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working direc...
CVE-2020-36465HIGH7.5An issue was discovered in the generic-array crate before 0.13.3 for Rust. It violates soundness by using the arr! macro...
CVE-2020-36464HIGH7.5An issue was discovered in the heapless crate before 0.6.1 for Rust. The IntoIter Clone implementation clones an entire ...
CVE-2020-36463HIGH8.1An issue was discovered in the multiqueue crate through 2020-12-25 for Rust. There are unconditional implementations of ...
CVE-2020-36462HIGH8.1An issue was discovered in the syncpool crate before 0.1.6 for Rust. There is an unconditional implementation of Send fo...
CVE-2020-36461HIGH8.1An issue was discovered in the noise_search crate through 2020-12-10 for Rust. There are unconditional implementations o...
CVE-2020-36460HIGH8.1An issue was discovered in the model crate through 2020-11-10 for Rust. The Shared data structure has an implementation ...
CVE-2020-36459HIGH8.1An issue was discovered in the dces crate through 2020-12-09 for Rust. The World type is marked as Send but lacks bounds...
CVE-2020-36458HIGH8.1An issue was discovered in the lexer crate through 2020-11-10 for Rust. For ReaderResult<T, E>, there is an implementati...
CVE-2020-36457HIGH8.1An issue was discovered in the lever crate before 0.1.1 for Rust. AtomicBox<T> implements the Send and Sync traits for a...
CVE-2020-36456HIGH8.1An issue was discovered in the toolshed crate through 2020-11-15 for Rust. In CopyCell<T>, the Send trait lacks bounds o...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now