2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-35938HIGH8.8PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated atta...
CVE-2020-35937HIGH8Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote ...
CVE-2020-35936HIGH8Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authe...
CVE-2020-35935HIGH8.8The Advanced Access Manager plugin before 6.6.2 for WordPress allows privilege escalation on profile updates via the aam...
CVE-2020-35932HIGH8.8Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with ...
CVE-2020-35931HIGH7.8An issue was discovered in Foxit Reader before 10.1.1 (and before 4.1.1 on macOS) and PhantomPDF before 9.7.5 and 10.x b...
CVE-2020-26165HIGH8.8qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/a...
CVE-2020-35896HIGH7.5An issue was discovered in the ws crate through 2020-09-25 for Rust. The outgoing buffer is not properly limited, leadin...
CVE-2020-35894HIGH7.5An issue was discovered in the obstack crate before 0.1.4 for Rust. Unaligned references can occur.
CVE-2020-35893HIGH7.5An issue was discovered in the simple-slab crate before 0.3.3 for Rust. remove() has an off-by-one error, causing memory...
CVE-2020-35891HIGH7.5An issue was discovered in the ordnung crate through 2020-09-03 for Rust. compact::Vec violates memory safety via a remo...
CVE-2020-35890HIGH7.5An issue was discovered in the ordnung crate through 2020-09-03 for Rust. compact::Vec violates memory safety via out-of...
CVE-2020-35889HIGH8.1An issue was discovered in the crayon crate through 2020-08-31 for Rust. A TOCTOU issue has a resultant memory safety vi...
CVE-2020-35882HIGH8.1An issue was discovered in the rocket crate before 0.4.5 for Rust. LocalRequest::clone creates more than one mutable ref...
CVE-2020-35875HIGH7.5An issue was discovered in the tokio-rustls crate before 0.13.1 for Rust. Excessive memory usage may occur when data arr...
CVE-2020-35874HIGH8.1An issue was discovered in the internment crate through 2020-05-28 for Rust. ArcIntern::drop has a race condition and re...
CVE-2020-35871HIGH8.1An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via an Auxdata API d...
CVE-2020-35865HIGH7.5An issue was discovered in the os_str_bytes crate before 2.0.0 for Rust. It has false expectations about char::from_u32_...
CVE-2020-35864HIGH7.5An issue was discovered in the flatbuffers crate through 2020-04-11 for Rust. read_scalar (and read_scalar_at) can trans...
CVE-2020-35861HIGH7.5An issue was discovered in the bumpalo crate before 3.2.1 for Rust. The realloc feature allows the reading of unknown me...
CVE-2020-35857HIGH7.5An issue was discovered in the trust-dns-server crate before 0.18.1 for Rust. DNS MX and SRV null targets are mishandled...
CVE-2020-35909HIGH7.5An issue was discovered in the multihash crate before 0.11.3 for Rust. The from_slice parsing code can panic via unsanit...
CVE-2020-35906HIGH7.8An issue was discovered in the futures-task crate before 0.3.6 for Rust. futures_task::waker may cause a use-after-free ...
CVE-2020-35901HIGH7.5An issue was discovered in the actix-http crate before 2.0.0-alpha.1 for Rust. There is a use-after-free in BodyStream.
CVE-2020-35743HIGH7.6HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of spe...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now