2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-36006 | MEDIUM | 6.5 | 1.1% | Jun 3, 2021 | AppCMS 2.0.101 in /admin/info.php has an arbitrary file deletion vulnerability which allows attackers to delete arbitrar... |
| CVE-2020-36005 | MEDIUM | 6.5 | 1.1% | Jun 3, 2021 | AppCMS 2.0.101 in /admin/app.php has an arbitrary file deletion vulnerability which allows attackers to delete arbitrary... |
| CVE-2020-36004 | MEDIUM | 6.5 | 0.9% | Jun 3, 2021 | AppCMS 2.0.101 in /admin/download_frame.php has a SQL injection vulnerability which allows attackers to obtain sensitive... |
| CVE-2020-35973 | MEDIUM | 5.4 | 0.6% | Jun 3, 2021 | An issue was discovered in zzcms2020. There is a XSS vulnerability that can insert and execute JS code arbitrarily via /... |
| CVE-2020-35972 | MEDIUM | 4.3 | 0.6% | Jun 3, 2021 | An issue was discovered in YzmCMS V5.8. There is a CSRF vulnerability that can add member user accounts via member/membe... |
| CVE-2020-35971 | MEDIUM | 5.4 | 0.5% | Jun 3, 2021 | A storage XSS vulnerability is found in YzmCMS v5.8, which can be used by attackers to inject JS code and attack malicio... |
| CVE-2020-21005 | MEDIUM | 6.5 | 0.8% | Jun 3, 2021 | WellCMS 2.0 beta3 is vulnerable to File Upload. A user can log in to the CMS background and upload a picture. Because th... |
| CVE-2020-21003 | MEDIUM | 4.8 | 0.5% | Jun 3, 2021 | Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php. |
| CVE-2020-5030 | MEDIUM | 5.4 | 0.5% | Jun 2, 2021 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users... |
| CVE-2020-4977 | MEDIUM | 5.4 | 0.5% | Jun 2, 2021 | IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability all... |
| CVE-2020-4732 | MEDIUM | 6.5 | 0.8% | Jun 2, 2021 | IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due t... |
| CVE-2020-22056 | MEDIUM | 6.5 | 0.9% | Jun 2, 2021 | A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the config_input function in af_acrossove... |
| CVE-2020-22054 | MEDIUM | 6.5 | 1.3% | Jun 2, 2021 | A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_dict_set function in dict.c. |
| CVE-2020-22051 | MEDIUM | 6.5 | 1.0% | Jun 2, 2021 | A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the filter_frame function in vf_tile.c. |
| CVE-2020-6950 | MEDIUM | 6.5 | 10.1% | Jun 2, 2021 | Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or c... |
| CVE-2020-27661 | MEDIUM | 6.5 | 0.3% | Jun 2, 2021 | A divide-by-zero issue was found in dwc2_handle_packet in hw/usb/hcd-dwc2.c in the hcd-dwc2 USB host controller emulatio... |
| CVE-2020-22049 | MEDIUM | 6.5 | 1.3% | Jun 2, 2021 | A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the wtvfile_open_sector function in wtvde... |
| CVE-2020-22048 | MEDIUM | 6.5 | 0.9% | Jun 2, 2021 | A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_frame_pool_get function in framepo... |
| CVE-2020-22046 | MEDIUM | 6.5 | 1.0% | Jun 2, 2021 | A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the avpriv_float_dsp_allocl function in l... |
| CVE-2020-35510 | MEDIUM | 5.9 | 1.1% | Jun 2, 2021 | A flaw was found in jboss-remoting in versions before 5.0.20.SP1-redhat-00001. A malicious attacker could cause threads ... |
| CVE-2020-35503 | MEDIUM | 6 | 0.3% | Jun 2, 2021 | A NULL pointer dereference flaw was found in the megasas-gen2 SCSI host bus adapter emulation of QEMU in versions before... |
| CVE-2020-14388 | MEDIUM | 6.3 | 0.6% | Jun 2, 2021 | A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were ... |
| CVE-2020-14371 | MEDIUM | 6.5 | 0.9% | Jun 2, 2021 | A credential leak vulnerability was found in Red Hat Satellite. This flaw exposes the compute resources credentials thro... |
| CVE-2020-14340 | MEDIUM | 5.9 | 2.2% | Jun 2, 2021 | A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles... |
| CVE-2020-14336 | MEDIUM | 6.5 | 0.9% | Jun 2, 2021 | A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network pack... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now