2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-20236MEDIUM6.5Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. ...
CVE-2020-20222MEDIUM6.5Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer proces...
CVE-2020-20214MEDIUM6.5Mikrotik RouterOs 6.44.6 (long-term tree) suffers from an assertion failure vulnerability in the btest process. An authe...
CVE-2020-24740MEDIUM4.3An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=ed...
CVE-2020-23861MEDIUM5.5A heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the read_system_page function at libredwg-0.10....
CVE-2020-24026MEDIUM6.1TinyShop, a free and open source mall based on RageFrame2, has a stored XSS vulnerability that affects version 1.2.0. Ti...
CVE-2020-23856MEDIUM5.5Use-after-Free vulnerability in cflow 1.6 in the void call(char *name, int line) function at src/parser.c, which could c...
CVE-2020-23852MEDIUM5.5A heap based buffer overflow vulnerability exists in ffjpeg through 2020-07-02 in the jfif_decode(void *ctxt, BMP *pb) f...
CVE-2020-23851MEDIUM5.5A stack-based buffer overflow vulnerability exists in ffjpeg through 2020-07-02 in the jfif_decode(void *ctxt, BMP *pb) ...
CVE-2020-20254MEDIUM6.5Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/lcdstat proc...
CVE-2020-20253MEDIUM6.5Mikrotik RouterOs before 6.47 (stable tree) suffers from a divison by zero vulnerability in the /nova/bin/lcdstat proces...
CVE-2020-18194MEDIUM6.1Cross Site Scripting (XSS) in emlog v6.0.0 allows remote attackers to execute arbitrary code by adding a crafted script ...
CVE-2020-21839MEDIUM6.5An issue was discovered in GNU LibreDWG 0.10. Crafted input will lead to an memory leak in dwg_decode_eed ../../src/deco...
CVE-2020-21835MEDIUM6.5A null pointer deference issue exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2337.
CVE-2020-21834MEDIUM6.5A null pointer deference issue exists in GNU LibreDWG 0.10 via get_bmp ../../programs/dwgbmp.c:164.
CVE-2020-29205MEDIUM6.1XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via t...
CVE-2020-24993MEDIUM5.4There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when visito...
CVE-2020-24992MEDIUM5.4There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when an adm...
CVE-2020-21817MEDIUM6.5A null pointer dereference issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:29. which cause...
CVE-2020-21815MEDIUM6.5A null pointer deference issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114, which caus...
CVE-2020-13667MEDIUM5.3Access bypass vulnerability in of Drupal Core Workspaces allows an attacker to access data without correct permissions. ...
CVE-2020-16632MEDIUM5.4A XSS Vulnerability in /uploads/dede/action_search.php in DedeCMS V5.7 SP2 allows an authenticated user to execute remot...
CVE-2020-17891MEDIUM6.1TP-Link Archer C1200 firmware version 1.13 Build 2018/01/24 rel.52299 EU has a XSS vulnerability allowing a remote attac...
CVE-2020-23689MEDIUM4.8In YFCMF v2.3.1, there is a stored XSS vulnerability in the comments section of the news page.
CVE-2020-18167MEDIUM4.8Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands int...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now