2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-36514CRITICAL9.8An issue was discovered in the acc_reader crate through 2020-12-27 for Rust. fill_buf may read from uninitialized memory...
CVE-2020-36513CRITICAL9.8An issue was discovered in the acc_reader crate through 2020-12-27 for Rust. read_up_to may read from uninitialized memo...
CVE-2020-36512CRITICAL9.8An issue was discovered in the buffoon crate through 2020-12-31 for Rust. InputStream::read_exact may read from uninitia...
CVE-2020-36511HIGH7.5An issue was discovered in the bite crate through 2020-12-31 for Rust. read::BiteReadExpandedExt::read_framed_max may re...
CVE-2020-35398MEDIUM5.3An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumera...
CVE-2020-3896MEDIUM5.5This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Catalina 10.15.4, Security Update...
CVE-2020-3886HIGH7.8A use after free issue was addressed with improved memory management. This issue is fixed in macOS Catalina 10.15.4, Sec...
CVE-2020-20605MEDIUM6.1Blog CMS v1.0 contains a cross-site scripting (XSS) vulnerability in the /controller/CommentAdminController.java compone...
CVE-2020-20601CRITICAL9.8An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.
CVE-2020-20600MEDIUM5.4MetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=...
CVE-2020-20598MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Editing component of lemon V1.10.0 allows attackers to execute arbitra...
CVE-2020-20597MEDIUM6.1A cross-site scripting (XSS) vulnerability in the potrtalItemName parameter in \web\PortalController.java of lemon V1.10...
CVE-2020-20595MEDIUM6.5A cross-site request forgery (CSRF) in OPMS v1.3 and below allows attackers to arbitrarily add a user account via /user/...
CVE-2020-20593HIGH8A cross-site request forgery (CSRF) in Rockoa v1.9.8 allows an authenticated attacker to arbitrarily add an administrato...
CVE-2020-20426MEDIUM6.1S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in /function/booksave....
CVE-2020-20425MEDIUM6.1S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in the search function...
CVE-2020-19770MEDIUM5.4A cross-site scripting (XSS) vulnerability in the system bulletin component of WUZHI CMS v4.1.0 allows attackers to stea...
CVE-2020-3709Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2020-3708Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2020-3707Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2020-3706Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2020-3705Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2020-3697Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2020-3695Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2020-3682Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now