2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-36220MEDIUM5.9An issue was discovered in the va-ts crate before 0.0.4 for Rust. Because Demuxer<T> omits a required T: Send bound, a d...
CVE-2020-36219MEDIUM5.9An issue was discovered in the atomic-option crate through 2020-10-31 for Rust. Because AtomicOption<T> implements Sync ...
CVE-2020-36218MEDIUM5.9An issue was discovered in the buttplug crate before 1.0.4 for Rust. ButtplugFutureStateShared does not properly conside...
CVE-2020-36217MEDIUM5.9An issue was discovered in the may_queue crate through 2020-11-10 for Rust. Because Queue does not have bounds on its Se...
CVE-2020-36216MEDIUM5.9An issue was discovered in Input<R> in the eventio crate before 0.5.1 for Rust. Because a non-Send type can be sent to a...
CVE-2020-36214MEDIUM5.9An issue was discovered in the multiqueue2 crate before 0.1.7 for Rust. Because a non-Send type can be sent to a differe...
CVE-2020-36205MEDIUM5.5An issue was discovered in the xcb crate through 2020-12-10 for Rust. base::Error does not have soundness. Because of th...
CVE-2020-36204MEDIUM4.7An issue was discovered in the im crate through 2020-11-09 for Rust. Because TreeFocus does not have bounds on its Send ...
CVE-2020-36203MEDIUM4.7An issue was discovered in the reffers crate through 2020-12-01 for Rust. ARefss can contain a !Send,!Sync object, leadi...
CVE-2020-36202MEDIUM6.1An issue was discovered in the async-h1 crate before 2.3.0 for Rust. Request smuggling can occur when used behind a reve...
CVE-2020-36200MEDIUM6.5TinyCheck before commits 9fd360d and ea53de8 allowed an authenticated attacker to send an HTTP GET request to the crafte...
CVE-2020-36011MEDIUM4.8A cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote att...
CVE-2020-35854MEDIUM4.8Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.
CVE-2020-35853MEDIUM4.84images Image Gallery Management System 1.7.11 is affected by cross-site scripting (XSS) in the Image URL. This vulnerab...
CVE-2020-35843MEDIUM5.5FastStone Image Viewer 7.5 has an out-of-bounds write (via a crafted image file) at FSViewer.exe+0x956e.
CVE-2020-35753MEDIUM6.1The job posting recommendation form in Persis Human Resource Management Portal (Versions 17.2.00 through 17.2.35 and 19....
CVE-2020-35513MEDIUM4.9A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality...
CVE-2020-35309MEDIUM4.8Bakeshop Online Ordering System in PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attacker...
CVE-2020-29241MEDIUM4.8Online News Portal using PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attackers to injec...
CVE-2020-27735MEDIUM6.1An XSS issue was discovered in Wing FTP 6.4.4. An arbitrary IFRAME element can be included in the help pages via a craft...
CVE-2020-27542MEDIUM6.8Rostelecom CS-C2SHW 5.0.082.1 is affected by: Bash command injection. The camera reads configuration from QR code (inclu...
CVE-2020-27298MEDIUM6.5Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Ste...
CVE-2020-27098MEDIUM5.5In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible way to access contacts due to a permissi...
CVE-2020-27097MEDIUM5.5In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible permissions bypass. This could lead to l...
CVE-2020-26941MEDIUM5.5A local (authenticated) low-privileged user can exploit a behavior in an ESET installer to achieve arbitrary file overwr...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now