2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5393 | MEDIUM | 6.1 | 0.7% | Jan 7, 2020 | In Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS. |
| CVE-2020-5843 | MEDIUM | 4.8 | 0.5% | Jan 7, 2020 | Codoforum 4.8.3 allows XSS in the admin dashboard via a category to the Manage Users screen. |
| CVE-2020-5846 | HIGH | 8.8 | 1.4% | Jan 6, 2020 | An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm... |
| CVE-2020-5513 | MEDIUM | 6.8 | 25.8% | Jan 6, 2020 | Gila CMS 1.11.8 allows /cm/delete?t=../ Directory Traversal. |
| CVE-2020-5512 | MEDIUM | 6.8 | 18.9% | Jan 6, 2020 | Gila CMS 1.11.8 allows /admin/media?path=../ Path Traversal. |
| CVE-2020-5204 | HIGH | 8.8 | 1.1% | Jan 6, 2020 | In uftpd before 2.11, there is a buffer overflow vulnerability in handle_PORT in ftpcmd.c that is caused by a buffer tha... |
| CVE-2020-5515 | HIGH | 7.2 | 26.5% | Jan 6, 2020 | Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection. |
| CVE-2020-5514 | CRITICAL | 9.1 | 44.1% | Jan 6, 2020 | Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= UR... |
| CVE-2020-5840 | HIGH | 7.5 | 1.5% | Jan 6, 2020 | An issue was discovered in HashBrown CMS before 1.3.2. Server/Entity/Resource/Connection.js allows an attacker to reach ... |
| CVE-2020-5519 | CRITICAL | 9.8 | 1.2% | Jan 6, 2020 | The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server... |
| CVE-2020-5192 | HIGH | 8.8 | 16.8% | Jan 6, 2020 | PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages an... |
| CVE-2020-5191 | MEDIUM | 6.1 | 5.5% | Jan 6, 2020 | PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities. |
| CVE-2020-5306 | MEDIUM | 4.8 | 1.1% | Jan 5, 2020 | Codoforum 4.8.3 allows XSS via a post using parameters display name, title name, or content. |
| CVE-2020-5305 | MEDIUM | 4.8 | 0.6% | Jan 5, 2020 | Codoforum 4.8.3 allows XSS in the admin dashboard via a name field of a new user, i.e., on the Manage Users screen. |
| CVE-2020-5499 | CRITICAL | 9.8 | 3.2% | Jan 4, 2020 | Baidu Rust SGX SDK through 1.0.8 has an enclave ID race. There are non-deterministic results in which, sometimes, two gl... |
| CVE-2020-5497 | MEDIUM | 6.1 | 2.1% | Jan 4, 2020 | The OpenID Connect reference implementation for MITREid Connect through 1.3.3 allows XSS due to userInfoJson being inclu... |
| CVE-2020-5496 | HIGH | 8.8 | 2.4% | Jan 3, 2020 | FontForge 20190801 has a heap-based buffer overflow in the Type2NotDefSplines() function in splinesave.c. |
| CVE-2020-5395 | HIGH | 8.8 | 2.5% | Jan 3, 2020 | FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c. |
| CVE-2020-1871 | HIGH | 8.2 | 0.6% | Jan 3, 2020 | USG9500 with software of V500R001C30SPC100; V500R001C30SPC200; V500R001C30SPC600; V500R001C60SPC500; V500R005C00SPC100; ... |
| CVE-2020-1785 | MEDIUM | 5.5 | 0.5% | Jan 3, 2020 | Mate 10 Pro;Honor V10;Honor 10;Nova 4 smartphones have a denial of service vulnerability. The system does not properly c... |
| CVE-2020-5313 | HIGH | 7.1 | 2.8% | Jan 3, 2020 | libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow. |
| CVE-2020-5312 | CRITICAL | 9.8 | 3.7% | Jan 3, 2020 | libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow. |
| CVE-2020-5311 | CRITICAL | 9.8 | 4.2% | Jan 3, 2020 | libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow. |
| CVE-2020-5310 | HIGH | 8.8 | 2.0% | Jan 3, 2020 | libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc. |
| CVE-2020-5179 | HIGH | 7.2 | 2.8% | Jan 2, 2020 | Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to execute arbitrary OS commands by nav... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now