2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15744CRITICAL9.8Stack-based Buffer Overflow vulnerability in the ONVIF server component of Victure PC420 smart camera allows an attacker...
CVE-2020-18116HIGH8.8A lack of filtering for searched keywords in the search bar of YouDianCMS 8.0 allows attackers to perform SQL injection.
CVE-2020-18114CRITICAL9.8An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a we...
CVE-2020-18106CRITICAL9.8The GET parameter "id" in WMS v1.0 is passed without filtering, which allows attackers to perform SQL injection.
CVE-2020-19002MEDIUM6.1Cross Site Scripting (XSS) in Mezzanine v4.3.1 allows remote attackers to execute arbitrary code via the 'Description' f...
CVE-2020-19001CRITICAL9.8Command Injection in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary system commands via line 64 ...
CVE-2020-19000MEDIUM6.1Cross Site Scripting (XSS) in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary code via line 54 of...
CVE-2020-18999MEDIUM6.1Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin...
CVE-2020-18998MEDIUM6.1Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin...
CVE-2020-23226MEDIUM6.1Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1.2.12 in (1) reports_admin.php, (2) data_queries.ph...
CVE-2020-20675CRITICAL9.8Nuishop v2.3 contains a SQL injection vulnerability in /goods/getGoodsListByConditions/.
CVE-2020-18477HIGH8.8SQL Injection vulnerability in Hucart CMS 5.7.4 via the purchase enquiry field found in the Message con_content field.
CVE-2020-18476HIGH8.8SQL Injection vulnerability in Hucart CMS 5.7.4 via the basic information field found in the avatar usd_image field.
CVE-2020-18475MEDIUM5.4Cross Site Scripting (XSS) vulnerabilty exists in Hucart CMS 5.7.4 is via the mes_title field. The first user inserts a ...
CVE-2020-18470MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in the Name of application field found in the General Configuration page...
CVE-2020-18469MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in the Copyright Text field found in the Application page under the Conf...
CVE-2020-18468MEDIUM5.4Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the ...
CVE-2020-18467MEDIUM5.4Cross Site Scripting (XSS) vulnerabilty exists in BigTree-CMS 4.4.3 in the tag name field found in the Tags page under t...
CVE-2020-14161MEDIUM6.1It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /conver...
CVE-2020-14160HIGH7.5An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote a...
CVE-2020-19822HIGH7.2A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbit...
CVE-2020-19821HIGH8.8A SQL injection vulnerability in admin.php of DOYOCMS 2.3 allows attackers to execute arbitrary SQL commands via the ord...
CVE-2020-19709MEDIUM6.1Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a c...
CVE-2020-19705CRITICAL9.8thinkphp-zcms as of 20190715 allows SQL injection via index.php?m=home&c=message&a=add.
CVE-2020-19704MEDIUM5.4A stored cross-site scripting (XSS) vulnerability via ResourceController.java in spring-boot-admin as of 20190710 allows...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now