2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-18460 | HIGH | 8.8 | 0.4% | Aug 12, 2021 | Cross Site Request Forgery (CSRF) vulnerability exists in 711cms v1.0.7 that can add an admin account via admin.php?c=Ad... |
| CVE-2020-18458 | HIGH | 8 | 0.5% | Aug 12, 2021 | Cross Site Request Forgery (CSRF) vulnerability exists in DamiCMS v6.0.6 that can add an admin account via admin.php?s=/... |
| CVE-2020-18457 | MEDIUM | 6.8 | 0.5% | Aug 12, 2021 | Cross Site Request Forgery (CSRF) vulnerability exists in bycms v1.3.0 that can add an admin account via admin.php/ucent... |
| CVE-2020-18456 | MEDIUM | 4.8 | 0.5% | Aug 12, 2021 | Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in Single... |
| CVE-2020-18455 | MEDIUM | 4.8 | 0.5% | Aug 12, 2021 | Cross Site Scripting (XSS) vulnerability exists in bycms v3.0.4 via the title parameter in the edit function in Document... |
| CVE-2020-18454 | MEDIUM | 6.8 | 0.5% | Aug 12, 2021 | Cross Site Request Forgery (CSRF) vulnerability in bycms v1.3 via admin.php/systems/index/module_id/70/group_id/1.html. |
| CVE-2020-18451 | MEDIUM | 4.8 | 0.5% | Aug 12, 2021 | Cross Site Scripting (XSS) vulnerability exists in DamiCMS v6.0.6 via the title parameter in the doadd function in Label... |
| CVE-2020-18449 | MEDIUM | 5.4 | 0.5% | Aug 12, 2021 | Cross Site Scripting (XSS) vulnerability exists in UKCMS v1.1.10 via data in the index function in Single.php |
| CVE-2020-18446 | MEDIUM | 4.8 | 0.5% | Aug 12, 2021 | Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the param parameter in the insertContent function i... |
| CVE-2020-18445 | MEDIUM | 6.1 | 0.7% | Aug 12, 2021 | Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the upurl function in Page.php. |
| CVE-2020-20981 | HIGH | 7.5 | 1.4% | Aug 12, 2021 | A SQL injection in the /admin/?n=logs&c=index&a=dolist component of Metinfo 7.0 allows attackers to access sensitive dat... |
| CVE-2020-20979 | CRITICAL | 9.8 | 1.6% | Aug 12, 2021 | An arbitrary file upload vulnerability in the move_uploaded_file() function of LJCMS v4.3 allows attackers to execute ar... |
| CVE-2020-20977 | MEDIUM | 5.4 | 0.5% | Aug 12, 2021 | A stored cross site scripting (XSS) vulnerability in index.php/legend/6.html of UK CMS v1.1.10 allows attackers to execu... |
| CVE-2020-20975 | CRITICAL | 9.8 | 1.3% | Aug 12, 2021 | In \lib\admin\action\dataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter. |
| CVE-2020-28165 | CRITICAL | 9.8 | 1.1% | Aug 12, 2021 | The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload a... |
| CVE-2020-24576 | HIGH | 8.8 | 2.1% | Aug 12, 2021 | Netskope Client through 77 allows low-privileged users to elevate their privileges to NT AUTHORITY\SYSTEM. |
| CVE-2020-25566 | CRITICAL | 9.8 | 1.6% | Aug 11, 2021 | In SapphireIMS 5.0, it is possible to take over an account by sending a request to the Save_Password form as shown in PO... |
| CVE-2020-25565 | CRITICAL | 9.8 | 2.1% | Aug 11, 2021 | In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and ga... |
| CVE-2020-25564 | HIGH | 8.8 | 1.2% | Aug 11, 2021 | In SapphireIMS 5.0, it is possible to create local administrator on any client with credentials of a non-privileged user... |
| CVE-2020-25563 | CRITICAL | 9.8 | 1.6% | Aug 11, 2021 | In SapphireIMS 5.0, it is possible to create local administrator on any client without requiring any credentials by dire... |
| CVE-2020-25562 | MEDIUM | 6.5 | 0.5% | Aug 11, 2021 | In SapphireIMS 5.0, there is no CSRF token present in the entire application. This can lead to CSRF vulnerabilities in c... |
| CVE-2020-25561 | HIGH | 7.8 | 0.4% | Aug 11, 2021 | SapphireIMS 5 utilized default sapphire:ims credentials to connect the client to server. This credential is saved in Ser... |
| CVE-2020-25560 | CRITICAL | 9.8 | 2.1% | Aug 11, 2021 | In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and ga... |
| CVE-2020-21363 | MEDIUM | 6.5 | 0.8% | Aug 11, 2021 | An arbitrary file deletion vulnerability exists within Maccms10. |
| CVE-2020-21362 | MEDIUM | 5.4 | 0.5% | Aug 11, 2021 | A cross site scripting (XSS) vulnerability in the background search function of Maccms10 allows attackers to execute arb... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now