2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28145 | HIGH | 7.5 | 1.2% | Oct 12, 2021 | Arbitrary file deletion vulnerability was discovered in wuzhicms v 4.0.1 via coreframe\app\attachment\admin\index.php, w... |
| CVE-2020-27372 | CRITICAL | 9.8 | 1.4% | Oct 11, 2021 | A buffer overflow vulnerability exists in Brandy Basic V Interpreter 1.21 in the run_interpreter function. |
| CVE-2020-22617 | CRITICAL | 9.8 | 1.2% | Oct 8, 2021 | Ardour v5.12 contains a use-after-free vulnerability in the component ardour/libs/pbd/xml++.cc when using xmlFreeDoc and... |
| CVE-2020-4654 | MEDIUM | 6.5 | 0.7% | Oct 8, 2021 | IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information due ... |
| CVE-2020-21729 | MEDIUM | 5.4 | 0.6% | Oct 7, 2021 | JEECMS x1.1 contains a stored cross-site scripting (XSS) vulnerability in the component of /member-vipcenter.htm, which ... |
| CVE-2020-21726 | CRITICAL | 9.8 | 1.2% | Oct 7, 2021 | OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the cid par... |
| CVE-2020-21725 | CRITICAL | 9.8 | 1.2% | Oct 7, 2021 | OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the pid par... |
| CVE-2020-21865 | CRITICAL | 9.8 | 1.9% | Oct 7, 2021 | ThinkPHP50-CMS v1.0 contains a remote code execution (RCE) vulnerability in the component /public/?s=captcha. |
| CVE-2020-21658 | MEDIUM | 6.5 | 0.5% | Oct 6, 2021 | A Cross-Site Request Forgery (CSRF) in WDJA CMS v1.5.2 allows attackers to arbitrarily add administrator accounts via a ... |
| CVE-2020-21656 | MEDIUM | 5.4 | 0.4% | Oct 6, 2021 | XYHCMS v3.6 contains a stored cross-site scripting (XSS) vulnerability in the component xyhai.php?s=/Link/index. |
| CVE-2020-21654 | HIGH | 7.2 | 1.1% | Oct 6, 2021 | emlog v6.0 contains a vulnerability in the component admin\template.php, which allows attackers to getshell via a crafte... |
| CVE-2020-21653 | CRITICAL | 9.1 | 1.2% | Oct 6, 2021 | Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploit... |
| CVE-2020-21652 | CRITICAL | 9.8 | 2.7% | Oct 6, 2021 | Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be... |
| CVE-2020-21651 | CRITICAL | 9.8 | 3.2% | Oct 6, 2021 | Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be ... |
| CVE-2020-21650 | HIGH | 8.8 | 3.1% | Oct 6, 2021 | Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be... |
| CVE-2020-21649 | HIGH | 8.1 | 0.8% | Oct 6, 2021 | Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploit... |
| CVE-2020-21648 | CRITICAL | 9.1 | 1.3% | Oct 6, 2021 | WDJA CMS v1.5.2 contains an arbitrary file deletion vulnerability in the component admin/cache/manage.php. |
| CVE-2020-19003 | MEDIUM | 5.3 | 0.8% | Oct 6, 2021 | An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to ... |
| CVE-2020-15941 | MEDIUM | 5.4 | 1.1% | Oct 6, 2021 | A path traversal vulnerability [CWE-22] in FortiClientEMS versions 6.4.1 and below; 6.2.8 and below may allow an authent... |
| CVE-2020-21506 | MEDIUM | 6.1 | 0.6% | Oct 5, 2021 | waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php?m=Config&a=add... |
| CVE-2020-21505 | MEDIUM | 6.1 | 0.6% | Oct 5, 2021 | waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php/Link/addsave. |
| CVE-2020-21504 | MEDIUM | 6.1 | 0.6% | Oct 5, 2021 | waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php?&m=Public&a=lo... |
| CVE-2020-21503 | HIGH | 7.5 | 1.0% | Oct 5, 2021 | waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing da... |
| CVE-2020-21496 | MEDIUM | 6.1 | 0.7% | Oct 4, 2021 | A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers... |
| CVE-2020-21495 | MEDIUM | 6.1 | 0.7% | Oct 4, 2021 | A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now