2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-20128HIGH7.5LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers.
CVE-2020-12030CRITICAL10There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. ...
CVE-2020-20125MEDIUM6.1EARCLINK ESPCMS-P8 contains a cross-site scripting (XSS) vulnerability in espcms_web\espcms_load.php.
CVE-2020-20124HIGH8.8Wuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php.
CVE-2020-20122CRITICAL9.8Wuzhi CMS v4.1 contains a SQL injection vulnerability in the checktitle() function in /coreframe/app/content/admin/conte...
CVE-2020-20120CRITICAL9.8ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the ...
CVE-2020-20696MEDIUM5.4A cross-site scripting (XSS) vulnerability in /admin/content/post of GilaCMS v1.11.4 allows attackers to execute arbitra...
CVE-2020-20695MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts o...
CVE-2020-20693HIGH8.8A Cross-Site Request Forgery (CSRF) in GilaCMS v1.11.4 allows authenticated attackers to arbitrarily add administrator a...
CVE-2020-20692HIGH7.2GilaCMS v1.11.4 was discovered to contain a SQL injection vulnerability via the $_GET parameter in /src/core/controllers...
CVE-2020-20691MEDIUM6.5An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extensio...
CVE-2020-24930HIGH8.1Beijing Wuzhi Internet Technology Co., Ltd. Wuzhi CMS 4.0.1 is an open source content management system. The five finger...
CVE-2020-20514HIGH8.1A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attac...
CVE-2020-20508MEDIUM6.1Shopkit v2.7 contains a reflective cross-site scripting (XSS) vulnerability in the /account/register component, which al...
CVE-2020-19951HIGH8.8A cross-site request forgery (CSRF) in /controller/pay.class.php of YzmCMS v5.5 allows attackers to access sensitive com...
CVE-2020-19950MEDIUM4.8A cross-site scripting (XSS) vulnerability in the /banner/add.html component of YzmCMS v5.3 allows attackers to execute ...
CVE-2020-19949MEDIUM4.8A cross-site scripting (XSS) vulnerability in the /link/add.html component of YzmCMS v5.3 allows attackers to execute ar...
CVE-2020-24327MEDIUM5.3Server Side Request Forgery (SSRF) vulnerability exists in Discourse 2.3.2 and 2.6 via the email function. When writing ...
CVE-2020-4941MEDIUM4.3IBM Edge 4.2 could reveal sensitive version information about the server from error pages that could aid an attacker in ...
CVE-2020-4809LOW3.3IBM Edge 4.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 1896...
CVE-2020-4805LOW3.3IBM Edge 4.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 1895...
CVE-2020-4803LOW3.3IBM Edge 4.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 1895...
CVE-2020-4690CRITICAL9.8IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for i...
CVE-2020-23481MEDIUM5.4CMS Made Simple 2.2.14 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to ex...
CVE-2020-23478HIGH7.5Leo Editor v6.2.1 was discovered to contain a regular expression denial of service (ReDoS) vulnerability in the componen...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now