2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-21678 | MEDIUM | 5.5 | 0.8% | Aug 10, 2021 | A global buffer overflow in the genmp_writefontmacro_latex component in genmp.c of fig2dev 3.2.7b allows attackers to ca... |
| CVE-2020-21677 | MEDIUM | 6.5 | 0.9% | Aug 10, 2021 | A heap-based buffer overflow in the sixel_encoder_output_without_macro function in encoder.c of Libsixel 1.8.4 allows at... |
| CVE-2020-21676 | MEDIUM | 5.5 | 1.1% | Aug 10, 2021 | A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to ca... |
| CVE-2020-21675 | MEDIUM | 5.5 | 1.1% | Aug 10, 2021 | A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows attackers to cause a den... |
| CVE-2020-23172 | MEDIUM | 5.5 | 0.7% | Aug 10, 2021 | A vulnerability in all versions of Kuba allows attackers to overwrite arbitrary files in arbitrary directories with craf... |
| CVE-2020-23171 | MEDIUM | 5.5 | 0.7% | Aug 10, 2021 | A vulnerability in all versions of Nim-lang allows unauthenticated attackers to write files to arbitrary directories via... |
| CVE-2020-28397 | MEDIUM | 5.3 | 0.8% | Aug 10, 2021 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Co... |
| CVE-2020-36472 | MEDIUM | 5.9 | 1.0% | Aug 8, 2021 | An issue was discovered in the max7301 crate before 0.2.0 for Rust. The ImmediateIO and TransactionalIO types implement ... |
| CVE-2020-36471 | MEDIUM | 5.9 | 1.1% | Aug 8, 2021 | An issue was discovered in the generator crate before 0.7.0 for Rust. It does not ensure that a function (for yielding v... |
| CVE-2020-36470 | MEDIUM | 5.9 | 1.0% | Aug 8, 2021 | An issue was discovered in the disrustor crate through 2020-12-17 for Rust. RingBuffer doe not properly limit the number... |
| CVE-2020-36469 | MEDIUM | 5.9 | 1.0% | Aug 8, 2021 | An issue was discovered in the appendix crate through 2020-11-15 for Rust. For the generic K and V type parameters, Send... |
| CVE-2020-36468 | MEDIUM | 5.9 | 1.0% | Aug 8, 2021 | An issue was discovered in the cgc crate through 2020-12-10 for Rust. Ptr::write performs non-atomic write operations on... |
| CVE-2020-36467 | MEDIUM | 5.9 | 1.0% | Aug 8, 2021 | An issue was discovered in the cgc crate through 2020-12-10 for Rust. Ptr::get returns more than one mutable reference t... |
| CVE-2020-36466 | MEDIUM | 5.9 | 1.0% | Aug 8, 2021 | An issue was discovered in the cgc crate through 2020-12-10 for Rust. Ptr implements Send and Sync for all types. |
| CVE-2020-21358 | MEDIUM | 6.5 | 0.4% | Aug 6, 2021 | A cross site request forgery (CSRF) in Wage-CMS 1.5.x-dev allows attackers to arbitrarily add users. |
| CVE-2020-21357 | MEDIUM | 6.1 | 0.8% | Aug 6, 2021 | A stored cross site scripting (XSS) vulnerability in /admin.php?mod=user&act=addnew of PopojiCMS 1.2 allows attackers to... |
| CVE-2020-21356 | MEDIUM | 5.3 | 0.9% | Aug 6, 2021 | An information disclosure vulnerability in upload.php of PopojiCMS 1.2 leads to physical path disclosure of the host whe... |
| CVE-2020-21353 | MEDIUM | 5.4 | 0.5% | Aug 6, 2021 | A stored cross site scripting (XSS) vulnerability in /admin/snippets.php of GetSimple CMS 3.4.0a allows attackers to exe... |
| CVE-2020-18693 | MEDIUM | 5.4 | 1.0% | Aug 6, 2021 | Cross Site Scripting (XSS) in MineWebCMS v1.7.0 allows remote attackers to execute arbitrary code by injecting malicious... |
| CVE-2020-22330 | MEDIUM | 6.1 | 0.6% | Aug 6, 2021 | Cross-Site Scripting (XSS) vulnerability in Subrion 4.2.1 via the title when adding a page. |
| CVE-2020-22392 | MEDIUM | 5.4 | 0.6% | Aug 5, 2021 | Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.2 when adding a blog and then editing an image file. |
| CVE-2020-22732 | MEDIUM | 4.8 | 0.5% | Aug 5, 2021 | CMS Made Simple (CMSMS) 2.2.14 allows stored XSS via the Extensions > Fie Picker.. |
| CVE-2020-24829 | MEDIUM | 5.5 | 1.0% | Aug 4, 2021 | An issue was discovered in GPAC from v0.5.2 to v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overfl... |
| CVE-2020-22352 | MEDIUM | 5.5 | 0.7% | Aug 4, 2021 | The gf_dash_segmenter_probe_input function in GPAC v0.8 allows attackers to cause a denial of service (NULL pointer dere... |
| CVE-2020-24827 | MEDIUM | 5.5 | 0.7% | Aug 4, 2021 | A vulnerability in the dwarf::cursor::skip_form function of Libelfin v0.3 allows attackers to cause a denial of service ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now