Skip to main content

Year archive

CVEs published in 2020

Archive summary

18,322 CVEs published in 2020 — 2,625 Critical, 7,666 High, 7,546 Medium, 485 Low, 0 Unrated.

CVE-2020-26165

Published Dec 31, 2020

qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php because unserialize is used.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35930

Published Dec 31, 2020

Seo Panel 4.8.0 allows stored XSS by an Authenticated User via the url parameter, as demonstrated by the seo/seopanel/websites.php URI.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-25011

Published Dec 31, 2020

NetBox through 2.6.2 allows an Authenticated User to conduct an XSS attack against an admin via a GFM-rendered field, as demonstrated by /dcim/sites/add/ comments.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25799

Published Dec 31, 2020

LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Quota component of the Survey page. When the survey quota being viewed, e.g. by an administrative user, the Java…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25797

Published Dec 31, 2020

LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Add Participants Function (First and last name parameters). When the survey participant being edited, e.g. by an…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19945

Published Dec 31, 2020

A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitations of a pathname to a restricted directory, this vulnerabi…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-19944

Published Dec 31, 2020

A cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices. If exploited, this vulnerability allows a remote attacker to gain…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35897

Published Dec 31, 2020

An issue was discovered in the atom crate before 0.3.6 for Rust. An unsafe Send implementation allows a cross-thread data race.

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35896

Published Dec 31, 2020

An issue was discovered in the ws crate through 2020-09-25 for Rust. The outgoing buffer is not properly limited, leading to a remote memory-consumption attack.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35895

Published Dec 31, 2020

An issue was discovered in the stack crate before 0.3.1 for Rust. ArrayVec has an out-of-bounds write via element insertion.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35891

Published Dec 31, 2020

An issue was discovered in the ordnung crate through 2020-09-03 for Rust. compact::Vec violates memory safety via a remove() double free.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35890

Published Dec 31, 2020

An issue was discovered in the ordnung crate through 2020-09-03 for Rust. compact::Vec violates memory safety via out-of-bounds access for large capacity.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35889

Published Dec 31, 2020

An issue was discovered in the crayon crate through 2020-08-31 for Rust. A TOCTOU issue has a resultant memory safety violation via HandleLike.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35888

Published Dec 31, 2020

An issue was discovered in the arr crate through 2020-08-25 for Rust. Uninitialized memory is dropped by Array::new_from_template.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35887

Published Dec 31, 2020

An issue was discovered in the arr crate through 2020-08-25 for Rust. There is a buffer overflow in Index and IndexMut.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35886

Published Dec 31, 2020

An issue was discovered in the arr crate through 2020-08-25 for Rust. An attacker can smuggle non-Sync/Send types across a thread boundary to cause a data race.

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 18,322 CVEsPage 1 of 733