2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-20345 | MEDIUM | 5.4 | 0.7% | Sep 1, 2021 | WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows ... |
| CVE-2020-20344 | MEDIUM | 5.4 | 0.5% | Sep 1, 2021 | WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search function under the backgr... |
| CVE-2020-20343 | MEDIUM | 6.5 | 0.4% | Sep 1, 2021 | WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component... |
| CVE-2020-20341 | HIGH | 7.5 | 1.3% | Sep 1, 2021 | YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function. |
| CVE-2020-20340 | HIGH | 7.5 | 1.3% | Sep 1, 2021 | A SQL injection vulnerability in the 4.edu.php\conn\function.php component of S-CMS v1.0 allows attackers to access sens... |
| CVE-2020-9002 | HIGH | 7.5 | 1.0% | Sep 1, 2021 | An issue was discovered in iPortalis iCS 7.1.13.0. An attacker can gain privileges by intercepting a request and changin... |
| CVE-2020-9000 | HIGH | 7.5 | 1.1% | Sep 1, 2021 | An issue was discovered in iPortalis iCS 7.1.13.0. Attackers can send a sequence of requests to rapidly cause .NET Input... |
| CVE-2020-20495 | CRITICAL | 9.1 | 1.5% | Sep 1, 2021 | bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter. |
| CVE-2020-20490 | HIGH | 7.5 | 1.1% | Aug 31, 2021 | A heap buffer-overflow in the client_example1.c component of libiec_iccp_mod v1.5 leads to a denial of service (DOS). |
| CVE-2020-20486 | HIGH | 7.5 | 1.1% | Aug 31, 2021 | IEC104 v1.0 contains a stack-buffer overflow in the parameter Iec10x_Sta_Addr. |
| CVE-2020-19049 | MEDIUM | 5.4 | 0.7% | Aug 31, 2021 | Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Descr... |
| CVE-2020-19048 | MEDIUM | 5.4 | 0.7% | Aug 31, 2021 | Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Title... |
| CVE-2020-19047 | HIGH | 8.8 | 0.7% | Aug 31, 2021 | Cross Site Request Forgey (CSRF) in iWebShop v5.3 allows remote atatckers to execute arbitrary code via malicious POST r... |
| CVE-2020-19046 | MEDIUM | 5.4 | 0.9% | Aug 31, 2021 | Cross Site Scripting (XSS) in S-CMS v1.0 allows remote attackers to execute arbitrary code via the component '/admin/tpl... |
| CVE-2020-13639 | MEDIUM | 6.1 | 0.8% | Aug 31, 2021 | A stored XSS vulnerability was discovered in the ECT Provider in OutSystems before 2020-09-04, affecting generated appli... |
| CVE-2020-22848 | CRITICAL | 9.8 | 2.9% | Aug 30, 2021 | A remote code execution (RCE) vulnerability in the \Playsong.php component of cscms v4.1 allows attackers to execute arb... |
| CVE-2020-35635 | HIGH | 8.8 | 2.4% | Aug 30, 2021 | A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_... |
| CVE-2020-35634 | HIGH | 8.8 | 2.4% | Aug 30, 2021 | A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read v... |
| CVE-2020-35633 | HIGH | 8.8 | 2.3% | Aug 30, 2021 | A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read v... |
| CVE-2020-18127 | MEDIUM | 6.5 | 1.2% | Aug 30, 2021 | An issue in the /config/config.php component of Indexhibit 2.1.5 allows attackers to arbitrarily view files. |
| CVE-2020-18126 | MEDIUM | 5.4 | 0.5% | Aug 30, 2021 | Multiple stored cross-site scripting (XSS) vulnerabilities in the Sections module of Indexhibit 2.1.5 allows attackers t... |
| CVE-2020-18125 | MEDIUM | 6.1 | 0.6% | Aug 30, 2021 | A reflected cross-site scripting (XSS) vulnerability in the /plugin/ajax.php component of Indexhibit 2.1.5 allows attack... |
| CVE-2020-18124 | MEDIUM | 5.7 | 0.4% | Aug 30, 2021 | A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily reset account pass... |
| CVE-2020-18123 | MEDIUM | 6.5 | 0.4% | Aug 30, 2021 | A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily delete admin accou... |
| CVE-2020-18121 | HIGH | 8.8 | 1.0% | Aug 30, 2021 | A configuration issue in Indexhibit 2.1.5 allows authenticated attackers to modify .php files, leading to getshell. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now