2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-18460HIGH8.8Cross Site Request Forgery (CSRF) vulnerability exists in 711cms v1.0.7 that can add an admin account via admin.php?c=Ad...
CVE-2020-18458HIGH8Cross Site Request Forgery (CSRF) vulnerability exists in DamiCMS v6.0.6 that can add an admin account via admin.php?s=/...
CVE-2020-18457MEDIUM6.8Cross Site Request Forgery (CSRF) vulnerability exists in bycms v1.3.0 that can add an admin account via admin.php/ucent...
CVE-2020-18456MEDIUM4.8Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in Single...
CVE-2020-18455MEDIUM4.8Cross Site Scripting (XSS) vulnerability exists in bycms v3.0.4 via the title parameter in the edit function in Document...
CVE-2020-18454MEDIUM6.8Cross Site Request Forgery (CSRF) vulnerability in bycms v1.3 via admin.php/systems/index/module_id/70/group_id/1.html.
CVE-2020-18451MEDIUM4.8Cross Site Scripting (XSS) vulnerability exists in DamiCMS v6.0.6 via the title parameter in the doadd function in Label...
CVE-2020-18449MEDIUM5.4Cross Site Scripting (XSS) vulnerability exists in UKCMS v1.1.10 via data in the index function in Single.php
CVE-2020-18446MEDIUM4.8Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the param parameter in the insertContent function i...
CVE-2020-18445MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the upurl function in Page.php.
CVE-2020-20981HIGH7.5A SQL injection in the /admin/?n=logs&c=index&a=dolist component of Metinfo 7.0 allows attackers to access sensitive dat...
CVE-2020-20979CRITICAL9.8An arbitrary file upload vulnerability in the move_uploaded_file() function of LJCMS v4.3 allows attackers to execute ar...
CVE-2020-20977MEDIUM5.4A stored cross site scripting (XSS) vulnerability in index.php/legend/6.html of UK CMS v1.1.10 allows attackers to execu...
CVE-2020-20975CRITICAL9.8In \lib\admin\action\dataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter.
CVE-2020-28165CRITICAL9.8The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload a...
CVE-2020-24576HIGH8.8Netskope Client through 77 allows low-privileged users to elevate their privileges to NT AUTHORITY\SYSTEM.
CVE-2020-25566CRITICAL9.8In SapphireIMS 5.0, it is possible to take over an account by sending a request to the Save_Password form as shown in PO...
CVE-2020-25565CRITICAL9.8In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and ga...
CVE-2020-25564HIGH8.8In SapphireIMS 5.0, it is possible to create local administrator on any client with credentials of a non-privileged user...
CVE-2020-25563CRITICAL9.8In SapphireIMS 5.0, it is possible to create local administrator on any client without requiring any credentials by dire...
CVE-2020-25562MEDIUM6.5In SapphireIMS 5.0, there is no CSRF token present in the entire application. This can lead to CSRF vulnerabilities in c...
CVE-2020-25561HIGH7.8SapphireIMS 5 utilized default sapphire:ims credentials to connect the client to server. This credential is saved in Ser...
CVE-2020-25560CRITICAL9.8In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and ga...
CVE-2020-21363MEDIUM6.5An arbitrary file deletion vulnerability exists within Maccms10.
CVE-2020-21362MEDIUM5.4A cross site scripting (XSS) vulnerability in the background search function of Maccms10 allows attackers to execute arb...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now