2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-37003MEDIUM6.4Sellacious eCommerce 4.6 contains a persistent cross-site scripting vulnerability in the Manage Your Addresses module th...
CVE-2020-36998MEDIUM6.4Forma.lms The E-Learning Suite 2.3.0.2 contains a persistent cross-site scripting vulnerability in multiple course and p...
CVE-2020-36996MEDIUM6.4PHPFusion 9.03.50 contains a persistent cross-site scripting vulnerability in the print.php page that fails to properly ...
CVE-2020-36966MEDIUM6.4Dolibarr 11.0.3 contains a persistent cross-site scripting vulnerability in LDAP synchronization settings that allows at...
CVE-2020-37021HIGH8.510-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local a...
CVE-2020-37020HIGH8.5SonarQube 8.3.1 contains an unquoted service path vulnerability that allows local attackers to gain SYSTEM privileges by...
CVE-2020-37018MEDIUM6.4GOautodial 4.0 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malic...
CVE-2020-37017HIGH8.5CodeMeter 6.60 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary ...
CVE-2020-37016HIGH8.5BarcodeOCR 19.3.6 contains an unquoted service path vulnerability that allows local attackers to execute code with eleva...
CVE-2020-37015HIGH7.5The Ruijie Networks Switch eWeb S29_RGOS version 11.4 contains a directory traversal vulnerability that allows unauthent...
CVE-2020-37013HIGH8.4Audio Playback Recorder 3.2.2 contains a local buffer overflow vulnerability in the eject and registration parameters th...
CVE-2020-37012CRITICAL9.8Tea LaTex 1.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary ...
CVE-2020-37011HIGH8.4Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability that allows attackers to trigger an out-of-bounds wri...
CVE-2020-37010CRITICAL9.8BearShare Lite 5.2.5 contains a buffer overflow vulnerability in the Advanced Search keywords input that allows attacker...
CVE-2020-37009HIGH8.8MedDream PACS Server 6.8.3.751 contains an authenticated remote code execution vulnerability that allows authorized user...
CVE-2020-37008HIGH8.7EasyPMS 1.0.0 contains an authentication bypass vulnerability that allows unprivileged users to manipulate SQL queries i...
CVE-2020-37007MEDIUM4.3Liman 0.7 contains a cross-site request forgery vulnerability that allows attackers to manipulate user account settings ...
CVE-2020-37006HIGH8.2berliCRM 1.0.24 contains a SQL injection vulnerability in the 'src_record' parameter that allows remote attackers to man...
CVE-2020-37005HIGH7.1TimeClock Software 1.01 contains an authenticated time-based SQL injection vulnerability that allows attackers to enumer...
CVE-2020-37004HIGH8.2The Ultimate Project Manager CRM PRO version 2.0.5 contains a blind SQL injection vulnerability that allows attackers to...
CVE-2020-37002CRITICAL9.8Ajenti 2.1.36 contains a post-authenticated remote command execution vulnerability that allows remote attackers to execu...
CVE-2020-37001HIGH8.4Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the Pack File feature that allows attack...
CVE-2020-37000CRITICAL9.8Free MP3 CD Ripper 2.8 contains a stack buffer overflow vulnerability that allows remote attackers to execute arbitrary ...
CVE-2020-36999HIGH8.8Elaniin CMS 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard by manipul...
CVE-2020-36997CRITICAL9.8BacklinkSpeed 2.4 contains a buffer overflow vulnerability that allows attackers to corrupt the Structured Exception Han...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now