2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-21494MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component install\install.sql of Xiuno BBS 4.0.4 allows attackers to e...
CVE-2020-21493MEDIUM5.3An issue in the component route\user.php of Xiuno BBS v4.0.4 allows attackers to enumerate usernames.
CVE-2020-21434MEDIUM5.4Maccms 10 contains a cross-site scripting (XSS) vulnerability in the Editing function under the Member module. This vuln...
CVE-2020-21431MEDIUM6.5HongCMS v3.0 contains an arbitrary file read and write vulnerability in the component /admin/index.php/template/edit.
CVE-2020-21387MEDIUM6.1A cross-site scripting (XSS) vulnerability in the parameter type_en of Maccms 10 allows attackers to obtain the administ...
CVE-2020-21386HIGH8.8A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gai...
CVE-2020-28119MEDIUM6.1Cross site scripting vulnerability in 53KF < 2.0.0.2 that allows for arbitrary code to be executed via crafted HTML stat...
CVE-2020-21228MEDIUM6.1JIZHICMS 1.5.1 contains a cross-site scripting (XSS) vulnerability in the component /user/release.html, which allows att...
CVE-2020-21014MEDIUM6.5emlog v6.0.0 contains an arbitrary file deletion vulnerability in admin/plugin.php.
CVE-2020-21013HIGH7.2emlog v6.0.0 contains a SQL injection via /admin/comment.php.
CVE-2020-21012CRITICAL9.8Sourcecodester Hotel and Lodge Management System 2.0 is vulnerable to unauthenticated SQL injection and can allow remote...
CVE-2020-20799MEDIUM5.4JeeCMS 1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web ...
CVE-2020-20797CRITICAL9.8FlameCMS 3.3.5 contains a time-based blind SQL injection vulnerability in /account/register.php.
CVE-2020-20796CRITICAL9.8FlameCMS 3.3.5 contains a SQL injection vulnerability in /master/article.php via the "Id" parameter.
CVE-2020-20746HIGH7.2A stack-based buffer overflow in the httpd server on Tenda AC9 V15.03.06.60_EN allows remote attackers to execute arbitr...
CVE-2020-20665HIGH7.5rudp v0.6 was discovered to contain a memory leak in the component main.c.
CVE-2020-20664MEDIUM6.5libiec_iccp_mod v1.5 contains a segmentation violation in the component server_example1.c.
CVE-2020-20663MEDIUM6.5libiec_iccp_mod v1.5 contains a heap-buffer-overflow in the component mms_client_connection.c.
CVE-2020-20662MEDIUM6.5libiec_iccp_mod v1.5 contains a heap-buffer-overflow in the component mms_client_example1.c.
CVE-2020-18685CRITICAL9.8Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of unchecked...
CVE-2020-18684CRITICAL9.8Floodlight through 1.2 has an integer overflow in checkFlow in StaticFlowEntryPusherResource.java via priority or port n...
CVE-2020-18683CRITICAL9.8Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of undefined...
CVE-2020-20781MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in /ucms/index.php?do=list_edit of UCMS 1.4.7 allows attackers to exec...
CVE-2020-20131MEDIUM5.4LaraCMS v1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows atackers to execute arbitrary web...
CVE-2020-20129MEDIUM5.4LaraCMS v1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary we...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now