2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-22403 | HIGH | 8.8 | 0.6% | Aug 12, 2021 | Cross Site Request Forgery (CSRF) vulnerability in Express cart v1.1.16 allows attackers to add an administrator account... |
| CVE-2020-18462 | HIGH | 7.2 | 1.0% | Aug 12, 2021 | File Upload vulnerabilty in AikCms v2.0.0 in poster_edit.php because the background file management office does not veri... |
| CVE-2020-18460 | HIGH | 8.8 | 0.4% | Aug 12, 2021 | Cross Site Request Forgery (CSRF) vulnerability exists in 711cms v1.0.7 that can add an admin account via admin.php?c=Ad... |
| CVE-2020-18458 | HIGH | 8 | 0.5% | Aug 12, 2021 | Cross Site Request Forgery (CSRF) vulnerability exists in DamiCMS v6.0.6 that can add an admin account via admin.php?s=/... |
| CVE-2020-20981 | HIGH | 7.5 | 1.4% | Aug 12, 2021 | A SQL injection in the /admin/?n=logs&c=index&a=dolist component of Metinfo 7.0 allows attackers to access sensitive dat... |
| CVE-2020-24576 | HIGH | 8.8 | 2.1% | Aug 12, 2021 | Netskope Client through 77 allows low-privileged users to elevate their privileges to NT AUTHORITY\SYSTEM. |
| CVE-2020-25564 | HIGH | 8.8 | 1.2% | Aug 11, 2021 | In SapphireIMS 5.0, it is possible to create local administrator on any client with credentials of a non-privileged user... |
| CVE-2020-25561 | HIGH | 7.8 | 0.4% | Aug 11, 2021 | SapphireIMS 5 utilized default sapphire:ims credentials to connect the client to server. This credential is saved in Ser... |
| CVE-2020-21976 | HIGH | 8.8 | 1.8% | Aug 11, 2021 | An arbitrary file upload in the <input type="file" name="user_image"> component of NewsOne CMS v1.1.0 allows attackers t... |
| CVE-2020-28589 | HIGH | 8.8 | 1.9% | Aug 11, 2021 | An improper array index validation vulnerability exists in the LoadObj functionality of tinyobjloader v2.0-rc1 and tinyo... |
| CVE-2020-21688 | HIGH | 8.8 | 1.7% | Aug 10, 2021 | A heap-use-after-free in the av_freep function in libavutil/mem.c of FFmpeg 4.2 allows attackers to execute arbitrary co... |
| CVE-2020-23150 | HIGH | 7.5 | 1.6% | Aug 9, 2021 | A SQL injection vulnerability in config.inc.php of rConfig 3.9.5 allows attackers to access sensitive database informati... |
| CVE-2020-23149 | HIGH | 7.5 | 1.4% | Aug 9, 2021 | The dbName parameter in ajaxDbInstall.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a SQL injection... |
| CVE-2020-23148 | HIGH | 7.5 | 1.6% | Aug 9, 2021 | The userLogin parameter in ldap/login.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a LDAP injectio... |
| CVE-2020-24742 | HIGH | 7.8 | 1.2% | Aug 9, 2021 | An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working direc... |
| CVE-2020-36465 | HIGH | 7.5 | 1.2% | Aug 8, 2021 | An issue was discovered in the generic-array crate before 0.13.3 for Rust. It violates soundness by using the arr! macro... |
| CVE-2020-36464 | HIGH | 7.5 | 1.2% | Aug 8, 2021 | An issue was discovered in the heapless crate before 0.6.1 for Rust. The IntoIter Clone implementation clones an entire ... |
| CVE-2020-36463 | HIGH | 8.1 | 1.1% | Aug 8, 2021 | An issue was discovered in the multiqueue crate through 2020-12-25 for Rust. There are unconditional implementations of ... |
| CVE-2020-36462 | HIGH | 8.1 | 1.2% | Aug 8, 2021 | An issue was discovered in the syncpool crate before 0.1.6 for Rust. There is an unconditional implementation of Send fo... |
| CVE-2020-36461 | HIGH | 8.1 | 1.2% | Aug 8, 2021 | An issue was discovered in the noise_search crate through 2020-12-10 for Rust. There are unconditional implementations o... |
| CVE-2020-36460 | HIGH | 8.1 | 1.1% | Aug 8, 2021 | An issue was discovered in the model crate through 2020-11-10 for Rust. The Shared data structure has an implementation ... |
| CVE-2020-36459 | HIGH | 8.1 | 1.1% | Aug 8, 2021 | An issue was discovered in the dces crate through 2020-12-09 for Rust. The World type is marked as Send but lacks bounds... |
| CVE-2020-36458 | HIGH | 8.1 | 0.8% | Aug 8, 2021 | An issue was discovered in the lexer crate through 2020-11-10 for Rust. For ReaderResult<T, E>, there is an implementati... |
| CVE-2020-36457 | HIGH | 8.1 | 1.2% | Aug 8, 2021 | An issue was discovered in the lever crate before 0.1.1 for Rust. AtomicBox<T> implements the Send and Sync traits for a... |
| CVE-2020-36456 | HIGH | 8.1 | 1.1% | Aug 8, 2021 | An issue was discovered in the toolshed crate through 2020-11-15 for Rust. In CopyCell<T>, the Send trait lacks bounds o... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now