2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-36006MEDIUM6.5AppCMS 2.0.101 in /admin/info.php has an arbitrary file deletion vulnerability which allows attackers to delete arbitrar...
CVE-2020-36005MEDIUM6.5AppCMS 2.0.101 in /admin/app.php has an arbitrary file deletion vulnerability which allows attackers to delete arbitrary...
CVE-2020-36004MEDIUM6.5AppCMS 2.0.101 in /admin/download_frame.php has a SQL injection vulnerability which allows attackers to obtain sensitive...
CVE-2020-35973MEDIUM5.4An issue was discovered in zzcms2020. There is a XSS vulnerability that can insert and execute JS code arbitrarily via /...
CVE-2020-35972MEDIUM4.3An issue was discovered in YzmCMS V5.8. There is a CSRF vulnerability that can add member user accounts via member/membe...
CVE-2020-35971MEDIUM5.4A storage XSS vulnerability is found in YzmCMS v5.8, which can be used by attackers to inject JS code and attack malicio...
CVE-2020-21005MEDIUM6.5WellCMS 2.0 beta3 is vulnerable to File Upload. A user can log in to the CMS background and upload a picture. Because th...
CVE-2020-21003MEDIUM4.8Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php.
CVE-2020-5030MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2020-4977MEDIUM5.4IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability all...
CVE-2020-4732MEDIUM6.5IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due t...
CVE-2020-22056MEDIUM6.5A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the config_input function in af_acrossove...
CVE-2020-22054MEDIUM6.5A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_dict_set function in dict.c.
CVE-2020-22051MEDIUM6.5A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the filter_frame function in vf_tile.c.
CVE-2020-6950MEDIUM6.5Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or c...
CVE-2020-27661MEDIUM6.5A divide-by-zero issue was found in dwc2_handle_packet in hw/usb/hcd-dwc2.c in the hcd-dwc2 USB host controller emulatio...
CVE-2020-22049MEDIUM6.5A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the wtvfile_open_sector function in wtvde...
CVE-2020-22048MEDIUM6.5A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_frame_pool_get function in framepo...
CVE-2020-22046MEDIUM6.5A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the avpriv_float_dsp_allocl function in l...
CVE-2020-35510MEDIUM5.9A flaw was found in jboss-remoting in versions before 5.0.20.SP1-redhat-00001. A malicious attacker could cause threads ...
CVE-2020-35503MEDIUM6A NULL pointer dereference flaw was found in the megasas-gen2 SCSI host bus adapter emulation of QEMU in versions before...
CVE-2020-14388MEDIUM6.3A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were ...
CVE-2020-14371MEDIUM6.5A credential leak vulnerability was found in Red Hat Satellite. This flaw exposes the compute resources credentials thro...
CVE-2020-14340MEDIUM5.9A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles...
CVE-2020-14336MEDIUM6.5A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network pack...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now