2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-28145HIGH7.5Arbitrary file deletion vulnerability was discovered in wuzhicms v 4.0.1 via coreframe\app\attachment\admin\index.php, w...
CVE-2020-27372CRITICAL9.8A buffer overflow vulnerability exists in Brandy Basic V Interpreter 1.21 in the run_interpreter function.
CVE-2020-22617CRITICAL9.8Ardour v5.12 contains a use-after-free vulnerability in the component ardour/libs/pbd/xml++.cc when using xmlFreeDoc and...
CVE-2020-4654MEDIUM6.5IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information due ...
CVE-2020-21729MEDIUM5.4JEECMS x1.1 contains a stored cross-site scripting (XSS) vulnerability in the component of /member-vipcenter.htm, which ...
CVE-2020-21726CRITICAL9.8OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the cid par...
CVE-2020-21725CRITICAL9.8OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the pid par...
CVE-2020-21865CRITICAL9.8ThinkPHP50-CMS v1.0 contains a remote code execution (RCE) vulnerability in the component /public/?s=captcha.
CVE-2020-21658MEDIUM6.5A Cross-Site Request Forgery (CSRF) in WDJA CMS v1.5.2 allows attackers to arbitrarily add administrator accounts via a ...
CVE-2020-21656MEDIUM5.4XYHCMS v3.6 contains a stored cross-site scripting (XSS) vulnerability in the component xyhai.php?s=/Link/index.
CVE-2020-21654HIGH7.2emlog v6.0 contains a vulnerability in the component admin\template.php, which allows attackers to getshell via a crafte...
CVE-2020-21653CRITICAL9.1Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploit...
CVE-2020-21652CRITICAL9.8Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be...
CVE-2020-21651CRITICAL9.8Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be ...
CVE-2020-21650HIGH8.8Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be...
CVE-2020-21649HIGH8.1Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploit...
CVE-2020-21648CRITICAL9.1WDJA CMS v1.5.2 contains an arbitrary file deletion vulnerability in the component admin/cache/manage.php.
CVE-2020-19003MEDIUM5.3An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to ...
CVE-2020-15941MEDIUM5.4A path traversal vulnerability [CWE-22] in FortiClientEMS versions 6.4.1 and below; 6.2.8 and below may allow an authent...
CVE-2020-21506MEDIUM6.1waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php?m=Config&a=add...
CVE-2020-21505MEDIUM6.1waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php/Link/addsave.
CVE-2020-21504MEDIUM6.1waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php?&m=Public&a=lo...
CVE-2020-21503HIGH7.5waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing da...
CVE-2020-21496MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers...
CVE-2020-21495MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now