Skip to main content

Year archive

CVEs published in 2020

Archive summary

18,322 CVEs published in 2020 — 2,625 Critical, 7,666 High, 7,546 Medium, 485 Low, 0 Unrated.

CVE-2020-35243

Published Dec 26, 2020

Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserInfoInDb.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35242

Published Dec 26, 2020

Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserTeamInfoInDbAndMemory.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-28759

Published Dec 26, 2020

The serializer module in OAID Tengine lite-v1.0 has a Buffer Overflow and crash. NOTE: another person has stated "I don't think there is an proof of overflow so far.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35364

Published Dec 26, 2020

Beijing Huorong Internet Security 5.0.55.2 allows a non-admin user to escalate privileges by injecting code into a process, and then waiting for a Huorong services restart or a sy…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35362

Published Dec 26, 2020

DEXT5Upload 2.7.1262310 and earlier is affected by Directory Traversal in handler/dext5handler.jsp. This could allow remote files to be downloaded via a dext5CMD=downloadRequest a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35284

Published Dec 26, 2020

Flamingo (aka FlamingoIM) through 2020-09-29 allows ../ directory traversal because the only ostensibly unpredictable part of a file-transfer request is an MD5 computation; howeve…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35450

Published Dec 26, 2020

Gobby 0.4.11 allows a NULL pointer dereference in the D-Bus handler for certain set_language calls.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35359

Published Dec 26, 2020

Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the connection limit.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35437

Published Dec 26, 2020

Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35347

Published Dec 26, 2020

CXUUCMS V3 3.1 has a CSRF vulnerability that can add an administrator account via admin.php?c=adminuser&a=add.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35346

Published Dec 26, 2020

CXUUCMS V3 3.1 is affected by a reflected XSS vulnerability that allows remote attackers to inject arbitrary web script or HTML via the imgurl parameter of admin.php?c=content&a=a…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-20412

Published Dec 26, 2020

lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE: this may overlap CVE…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35388

Published Dec 26, 2020

rainrocka xinhu 2.1.9 allows remote attackers to obtain sensitive information via an index.php?a=gettotal request in which the ajaxbool value is manipulated to be true.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-29172

Published Dec 26, 2020

A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27515

Published Dec 26, 2020

A Cross Site Scripting (XSS) vulnerability in Savsoft Quiz v5.0 allows remote attackers to inject arbitrary web script or HTML via the Skype ID field.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25917

Published Dec 26, 2020

Stratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control. A low privileged user on the platform, for example a user with "helpdesk" privileges, can perform…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 326-350 of 18,322 CVEsPage 14 of 733