2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-25926HIGH7.5The DNS client in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Insufficient entropy in the DNS transaction id. The...
CVE-2020-25767HIGH7.5An issue was discovered in HCC Embedded NicheStack IPv4 4.1. The dnc_copy_in routine for parsing DNS domain names does n...
CVE-2020-19669HIGH8.8Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=a...
CVE-2020-22124HIGH7.5A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information.
CVE-2020-22122HIGH7.5A SQL injection vulnerability in /oa.php?c=Staff&a=read of Find a Place LJCMS v 1.3 allows attackers to access sensitive...
CVE-2020-22120HIGH8.8A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticate...
CVE-2020-28146MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.
CVE-2020-23069MEDIUM6.5Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a mal...
CVE-2020-18875HIGH8.8Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client co...
CVE-2020-18746HIGH7.2SQL Injection in AiteCMS v1.0 allows remote attackers to execute arbitrary code via the component "aitecms/login/diy_lis...
CVE-2020-23341MEDIUM6.1A reflected cross site scripting (XSS) vulnerability in the /header.tmpl.php component of ATutor 2.2.4 allows attackers ...
CVE-2020-23334HIGH7.5A WRITE memory access in the AP4_NullTerminatedStringAtom::AP4_NullTerminatedStringAtom component of Bento4 version 06c3...
CVE-2020-23333HIGH7.5A heap-based buffer overflow exists in the AP4_CttsAtom::AP4_CttsAtom component located in /Core/Ap4Utils.h of Bento4 ve...
CVE-2020-23332HIGH7.5A heap-based buffer overflow exists in the AP4_StdcFileByteStream::ReadPartial component located in /StdC/Ap4StdCFileByt...
CVE-2020-23331HIGH7.5An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_DescriptorListWriter::Ac...
CVE-2020-23330HIGH7.5An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_Stz2Atom::GetSampleSize ...
CVE-2020-28594HIGH7.8A use-after-free vulnerability exists in the _3MF_Importer::_handle_end_model() functionality of Prusa Research PrusaSli...
CVE-2020-18164CRITICAL9.8SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter.
CVE-2020-13589HIGH8.8An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management Ap...
CVE-2020-13588HIGH8.8An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management Ap...
CVE-2020-22937CRITICAL9.8A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via...
CVE-2020-29548HIGH8.1An issue was discovered in SmarterTools SmarterMail through 100.0.7537. Meddler-in-the-middle attackers can pipeline com...
CVE-2020-15955MEDIUM5.9In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session betw...
CVE-2020-28846MEDIUM6.5Cross Site Request Forgery (CSRF) vulnerability exists in SeaCMS 10.7 in admin_manager.php, which could let a malicious ...
CVE-2020-4992MEDIUM6.5IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.16 is vulnerable to cross-site request forgery which could allow an at...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now