2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-22226CRITICAL9.8Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionS...
CVE-2020-22225CRITICAL9.8Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionL...
CVE-2020-22224MEDIUM6.1Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via ...
CVE-2020-22223CRITICAL9.8Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionL...
CVE-2020-22222MEDIUM6.1Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via ...
CVE-2020-23567MEDIUM5.5Irfanview v4.53 allows attackers to to cause a denial of service (DoS) via a crafted JPEG 2000 file. Related to "Integer...
CVE-2020-23566MEDIUM5.5Irfanview v4.53 was discovered to contain an infinity loop via JPEG2000!ShowPlugInSaveOptions_W+0x1ecd8.
CVE-2020-23565HIGH7.8Irfanview v4.53 allows attackers to execute arbitrary code via a crafted JPEG 2000 file. Related to a "Data from Faultin...
CVE-2020-21139MEDIUM6.5EC Cloud E-Commerce System v1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to ...
CVE-2020-25368CRITICAL9.8A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B0...
CVE-2020-25366CRITICAL9.1An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a deni...
CVE-2020-25367CRITICAL9.8A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B0...
CVE-2020-6931HIGH7.8HP Print and Scan Doctor may potentially be vulnerable to local elevation of privilege.
CVE-2020-28416HIGH7.8HP has identified a security vulnerability with the I.R.I.S. OCR (Optical Character Recognition) software available with...
CVE-2020-18263HIGH7.5PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability in the component search.php via the search paramete...
CVE-2020-18262CRITICAL9.8ED01-CMS v1.0 was discovered to contain a SQL injection in the component cposts.php via the cid parameter.
CVE-2020-18261CRITICAL9.8An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitra...
CVE-2020-18259MEDIUM6.1ED01-CMS v1.0 was discovered to contain a reflective cross-site scripting (XSS) vulnerability in the component sposts.ph...
CVE-2020-24743CRITICAL9.8An issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escal...
CVE-2020-24000CRITICAL9.8SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive inf...
CVE-2020-23680HIGH7.8An issue was discovered in function StartPage in text2pdf.c in pdfcorner text2pdf 1.1, allows attackers to cause denial ...
CVE-2020-23679CRITICAL9.8Buffer overflow vulnerability in Renleilei1992 Linux_Network_Project 1.0, allows attackers to execute arbitrary code, vi...
CVE-2020-23126MEDIUM6.1Chamilo LMS version 1.11.10 contains an XSS vulnerability in the personal profile edition form, affecting the user him/h...
CVE-2020-23109HIGH8.1Buffer overflow vulnerability in function convert_colorspace in heif_colorconversion.cc in libheif v1.6.2, allows attack...
CVE-2020-20982CRITICAL9.6Cross Site Scripting (XSS) vulnerability in shadoweb wdja v1.5.1, allows attackers to execute arbitrary code and gain es...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now