2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-20345MEDIUM5.4WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows ...
CVE-2020-20344MEDIUM5.4WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search function under the backgr...
CVE-2020-20343MEDIUM6.5WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component...
CVE-2020-20341HIGH7.5YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function.
CVE-2020-20340HIGH7.5A SQL injection vulnerability in the 4.edu.php\conn\function.php component of S-CMS v1.0 allows attackers to access sens...
CVE-2020-9002HIGH7.5An issue was discovered in iPortalis iCS 7.1.13.0. An attacker can gain privileges by intercepting a request and changin...
CVE-2020-9000HIGH7.5An issue was discovered in iPortalis iCS 7.1.13.0. Attackers can send a sequence of requests to rapidly cause .NET Input...
CVE-2020-20495CRITICAL9.1bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter.
CVE-2020-20490HIGH7.5A heap buffer-overflow in the client_example1.c component of libiec_iccp_mod v1.5 leads to a denial of service (DOS).
CVE-2020-20486HIGH7.5IEC104 v1.0 contains a stack-buffer overflow in the parameter Iec10x_Sta_Addr.
CVE-2020-19049MEDIUM5.4Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Descr...
CVE-2020-19048MEDIUM5.4Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Title...
CVE-2020-19047HIGH8.8Cross Site Request Forgey (CSRF) in iWebShop v5.3 allows remote atatckers to execute arbitrary code via malicious POST r...
CVE-2020-19046MEDIUM5.4Cross Site Scripting (XSS) in S-CMS v1.0 allows remote attackers to execute arbitrary code via the component '/admin/tpl...
CVE-2020-13639MEDIUM6.1A stored XSS vulnerability was discovered in the ECT Provider in OutSystems before 2020-09-04, affecting generated appli...
CVE-2020-22848CRITICAL9.8A remote code execution (RCE) vulnerability in the \Playsong.php component of cscms v4.1 allows attackers to execute arb...
CVE-2020-35635HIGH8.8A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_...
CVE-2020-35634HIGH8.8A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read v...
CVE-2020-35633HIGH8.8A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read v...
CVE-2020-18127MEDIUM6.5An issue in the /config/config.php component of Indexhibit 2.1.5 allows attackers to arbitrarily view files.
CVE-2020-18126MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in the Sections module of Indexhibit 2.1.5 allows attackers t...
CVE-2020-18125MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the /plugin/ajax.php component of Indexhibit 2.1.5 allows attack...
CVE-2020-18124MEDIUM5.7A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily reset account pass...
CVE-2020-18123MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily delete admin accou...
CVE-2020-18121HIGH8.8A configuration issue in Indexhibit 2.1.5 allows authenticated attackers to modify .php files, leading to getshell.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now