2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-37003 | MEDIUM | 6.4 | 0.3% | Jan 30, 2026 | Sellacious eCommerce 4.6 contains a persistent cross-site scripting vulnerability in the Manage Your Addresses module th... |
| CVE-2020-36998 | MEDIUM | 6.4 | 0.3% | Jan 30, 2026 | Forma.lms The E-Learning Suite 2.3.0.2 contains a persistent cross-site scripting vulnerability in multiple course and p... |
| CVE-2020-36996 | MEDIUM | 6.4 | 0.2% | Jan 30, 2026 | PHPFusion 9.03.50 contains a persistent cross-site scripting vulnerability in the print.php page that fails to properly ... |
| CVE-2020-36966 | MEDIUM | 6.4 | 0.2% | Jan 30, 2026 | Dolibarr 11.0.3 contains a persistent cross-site scripting vulnerability in LDAP synchronization settings that allows at... |
| CVE-2020-37021 | HIGH | 8.5 | 0.1% | Jan 29, 2026 | 10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local a... |
| CVE-2020-37020 | HIGH | 8.5 | 0.1% | Jan 29, 2026 | SonarQube 8.3.1 contains an unquoted service path vulnerability that allows local attackers to gain SYSTEM privileges by... |
| CVE-2020-37018 | MEDIUM | 6.4 | 0.2% | Jan 29, 2026 | GOautodial 4.0 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malic... |
| CVE-2020-37017 | HIGH | 8.5 | 0.1% | Jan 29, 2026 | CodeMeter 6.60 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary ... |
| CVE-2020-37016 | HIGH | 8.5 | 0.1% | Jan 29, 2026 | BarcodeOCR 19.3.6 contains an unquoted service path vulnerability that allows local attackers to execute code with eleva... |
| CVE-2020-37015 | HIGH | 7.5 | 0.6% | Jan 29, 2026 | The Ruijie Networks Switch eWeb S29_RGOS version 11.4 contains a directory traversal vulnerability that allows unauthent... |
| CVE-2020-37013 | HIGH | 8.4 | 0.2% | Jan 29, 2026 | Audio Playback Recorder 3.2.2 contains a local buffer overflow vulnerability in the eject and registration parameters th... |
| CVE-2020-37012 | CRITICAL | 9.8 | 0.8% | Jan 29, 2026 | Tea LaTex 1.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary ... |
| CVE-2020-37011 | HIGH | 8.4 | 0.4% | Jan 29, 2026 | Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability that allows attackers to trigger an out-of-bounds wri... |
| CVE-2020-37010 | CRITICAL | 9.8 | 0.4% | Jan 29, 2026 | BearShare Lite 5.2.5 contains a buffer overflow vulnerability in the Advanced Search keywords input that allows attacker... |
| CVE-2020-37009 | HIGH | 8.8 | 0.5% | Jan 29, 2026 | MedDream PACS Server 6.8.3.751 contains an authenticated remote code execution vulnerability that allows authorized user... |
| CVE-2020-37008 | HIGH | 8.7 | 0.5% | Jan 29, 2026 | EasyPMS 1.0.0 contains an authentication bypass vulnerability that allows unprivileged users to manipulate SQL queries i... |
| CVE-2020-37007 | MEDIUM | 4.3 | 0.2% | Jan 29, 2026 | Liman 0.7 contains a cross-site request forgery vulnerability that allows attackers to manipulate user account settings ... |
| CVE-2020-37006 | HIGH | 8.2 | 0.3% | Jan 29, 2026 | berliCRM 1.0.24 contains a SQL injection vulnerability in the 'src_record' parameter that allows remote attackers to man... |
| CVE-2020-37005 | HIGH | 7.1 | 0.3% | Jan 29, 2026 | TimeClock Software 1.01 contains an authenticated time-based SQL injection vulnerability that allows attackers to enumer... |
| CVE-2020-37004 | HIGH | 8.2 | 0.2% | Jan 29, 2026 | The Ultimate Project Manager CRM PRO version 2.0.5 contains a blind SQL injection vulnerability that allows attackers to... |
| CVE-2020-37002 | CRITICAL | 9.8 | 0.7% | Jan 29, 2026 | Ajenti 2.1.36 contains a post-authenticated remote command execution vulnerability that allows remote attackers to execu... |
| CVE-2020-37001 | HIGH | 8.4 | 0.1% | Jan 29, 2026 | Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the Pack File feature that allows attack... |
| CVE-2020-37000 | CRITICAL | 9.8 | 0.5% | Jan 29, 2026 | Free MP3 CD Ripper 2.8 contains a stack buffer overflow vulnerability that allows remote attackers to execute arbitrary ... |
| CVE-2020-36999 | HIGH | 8.8 | 0.3% | Jan 29, 2026 | Elaniin CMS 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard by manipul... |
| CVE-2020-36997 | CRITICAL | 9.8 | 0.4% | Jan 29, 2026 | BacklinkSpeed 2.4 contains a buffer overflow vulnerability that allows attackers to corrupt the Structured Exception Han... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now