2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-20236 | MEDIUM | 6.5 | 3.3% | May 18, 2021 | Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. ... |
| CVE-2020-20222 | MEDIUM | 6.5 | 3.2% | May 18, 2021 | Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer proces... |
| CVE-2020-20214 | MEDIUM | 6.5 | 3.1% | May 18, 2021 | Mikrotik RouterOs 6.44.6 (long-term tree) suffers from an assertion failure vulnerability in the btest process. An authe... |
| CVE-2020-24740 | MEDIUM | 4.3 | 0.4% | May 18, 2021 | An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=ed... |
| CVE-2020-23861 | MEDIUM | 5.5 | 0.6% | May 18, 2021 | A heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the read_system_page function at libredwg-0.10.... |
| CVE-2020-24026 | MEDIUM | 6.1 | 0.9% | May 18, 2021 | TinyShop, a free and open source mall based on RageFrame2, has a stored XSS vulnerability that affects version 1.2.0. Ti... |
| CVE-2020-23856 | MEDIUM | 5.5 | 0.4% | May 18, 2021 | Use-after-Free vulnerability in cflow 1.6 in the void call(char *name, int line) function at src/parser.c, which could c... |
| CVE-2020-23852 | MEDIUM | 5.5 | 0.7% | May 18, 2021 | A heap based buffer overflow vulnerability exists in ffjpeg through 2020-07-02 in the jfif_decode(void *ctxt, BMP *pb) f... |
| CVE-2020-23851 | MEDIUM | 5.5 | 0.7% | May 18, 2021 | A stack-based buffer overflow vulnerability exists in ffjpeg through 2020-07-02 in the jfif_decode(void *ctxt, BMP *pb) ... |
| CVE-2020-20254 | MEDIUM | 6.5 | 2.1% | May 18, 2021 | Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/lcdstat proc... |
| CVE-2020-20253 | MEDIUM | 6.5 | 2.1% | May 18, 2021 | Mikrotik RouterOs before 6.47 (stable tree) suffers from a divison by zero vulnerability in the /nova/bin/lcdstat proces... |
| CVE-2020-18194 | MEDIUM | 6.1 | 1.5% | May 17, 2021 | Cross Site Scripting (XSS) in emlog v6.0.0 allows remote attackers to execute arbitrary code by adding a crafted script ... |
| CVE-2020-21839 | MEDIUM | 6.5 | 1.2% | May 17, 2021 | An issue was discovered in GNU LibreDWG 0.10. Crafted input will lead to an memory leak in dwg_decode_eed ../../src/deco... |
| CVE-2020-21835 | MEDIUM | 6.5 | 0.9% | May 17, 2021 | A null pointer deference issue exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2337. |
| CVE-2020-21834 | MEDIUM | 6.5 | 0.9% | May 17, 2021 | A null pointer deference issue exists in GNU LibreDWG 0.10 via get_bmp ../../programs/dwgbmp.c:164. |
| CVE-2020-29205 | MEDIUM | 6.1 | 1.5% | May 17, 2021 | XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via t... |
| CVE-2020-24993 | MEDIUM | 5.4 | 0.5% | May 17, 2021 | There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when visito... |
| CVE-2020-24992 | MEDIUM | 5.4 | 0.5% | May 17, 2021 | There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when an adm... |
| CVE-2020-21817 | MEDIUM | 6.5 | 0.9% | May 17, 2021 | A null pointer dereference issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:29. which cause... |
| CVE-2020-21815 | MEDIUM | 6.5 | 0.9% | May 17, 2021 | A null pointer deference issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114, which caus... |
| CVE-2020-13667 | MEDIUM | 5.3 | 0.9% | May 17, 2021 | Access bypass vulnerability in of Drupal Core Workspaces allows an attacker to access data without correct permissions. ... |
| CVE-2020-16632 | MEDIUM | 5.4 | 0.5% | May 15, 2021 | A XSS Vulnerability in /uploads/dede/action_search.php in DedeCMS V5.7 SP2 allows an authenticated user to execute remot... |
| CVE-2020-17891 | MEDIUM | 6.1 | 1.2% | May 14, 2021 | TP-Link Archer C1200 firmware version 1.13 Build 2018/01/24 rel.52299 EU has a XSS vulnerability allowing a remote attac... |
| CVE-2020-23689 | MEDIUM | 4.8 | 0.6% | May 14, 2021 | In YFCMF v2.3.1, there is a stored XSS vulnerability in the comments section of the news page. |
| CVE-2020-18167 | MEDIUM | 4.8 | 0.9% | May 14, 2021 | Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands int... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now