2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-5393MEDIUM6.1In Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS.
CVE-2020-5843MEDIUM4.8Codoforum 4.8.3 allows XSS in the admin dashboard via a category to the Manage Users screen.
CVE-2020-5846HIGH8.8An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm...
CVE-2020-5513MEDIUM6.8Gila CMS 1.11.8 allows /cm/delete?t=../ Directory Traversal.
CVE-2020-5512MEDIUM6.8Gila CMS 1.11.8 allows /admin/media?path=../ Path Traversal.
CVE-2020-5204HIGH8.8In uftpd before 2.11, there is a buffer overflow vulnerability in handle_PORT in ftpcmd.c that is caused by a buffer tha...
CVE-2020-5515HIGH7.2Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.
CVE-2020-5514CRITICAL9.1Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= UR...
CVE-2020-5840HIGH7.5An issue was discovered in HashBrown CMS before 1.3.2. Server/Entity/Resource/Connection.js allows an attacker to reach ...
CVE-2020-5519CRITICAL9.8The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server...
CVE-2020-5192HIGH8.8PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages an...
CVE-2020-5191MEDIUM6.1PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.
CVE-2020-5306MEDIUM4.8Codoforum 4.8.3 allows XSS via a post using parameters display name, title name, or content.
CVE-2020-5305MEDIUM4.8Codoforum 4.8.3 allows XSS in the admin dashboard via a name field of a new user, i.e., on the Manage Users screen.
CVE-2020-5499CRITICAL9.8Baidu Rust SGX SDK through 1.0.8 has an enclave ID race. There are non-deterministic results in which, sometimes, two gl...
CVE-2020-5497MEDIUM6.1The OpenID Connect reference implementation for MITREid Connect through 1.3.3 allows XSS due to userInfoJson being inclu...
CVE-2020-5496HIGH8.8FontForge 20190801 has a heap-based buffer overflow in the Type2NotDefSplines() function in splinesave.c.
CVE-2020-5395HIGH8.8FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.
CVE-2020-1871HIGH8.2USG9500 with software of V500R001C30SPC100; V500R001C30SPC200; V500R001C30SPC600; V500R001C60SPC500; V500R005C00SPC100; ...
CVE-2020-1785MEDIUM5.5Mate 10 Pro;Honor V10;Honor 10;Nova 4 smartphones have a denial of service vulnerability. The system does not properly c...
CVE-2020-5313HIGH7.1libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.
CVE-2020-5312CRITICAL9.8libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.
CVE-2020-5311CRITICAL9.8libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.
CVE-2020-5310HIGH8.8libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.
CVE-2020-5179HIGH7.2Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to execute arbitrary OS commands by nav...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now