2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-22765MEDIUM6.1Cross Site Scripting (XSS) vulnerability in NukeViet cms 4.4.0 via the editor in the News module.
CVE-2020-22761HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in FlatPress 1.1 via the DeleteFile function in flat/admin.php.
CVE-2020-21854MEDIUM6.1Cross Site Scripting vulnerabiity exists in WDScanner 1.1 in the system management page.
CVE-2020-21809CRITICAL9.8SQL Injection vulnerability in NukeViet CMS module Shops 4.0.29 and 4.3 via the (1) listid parameter in detail.php and t...
CVE-2020-21808CRITICAL9.8SQL Injection vulnerability in NukeViet CMS 4.0.10 - 4.3.07 via:the topicsid parameter in modules/news/admin/addtotopics...
CVE-2020-21806CRITICAL9.8SQL Injection Vulnerability in ECTouch v2 via the shop page in index.php..
CVE-2020-20701MEDIUM4.8A stored cross site scripting (XSS) vulnerability in /app/config/of S-CMS PHP v3.0 allows attackers to execute arbitrary...
CVE-2020-20700MEDIUM4.8A stored cross site scripting (XSS) vulnerability in /app/form_add/of S-CMS PHP v3.0 allows attackers to execute arbitra...
CVE-2020-20699MEDIUM4.8A cross site scripting (XSS) vulnerability in S-CMS PHP v3.0 allows attackers to execute arbitrary web scripts or HTML v...
CVE-2020-20698HIGH7.2A remote code execution (RCE) vulnerability in /1.com.php of S-CMS PHP v3.0 allows attackers to getshell via modificatio...
CVE-2020-19118MEDIUM5.4Cross Site Scripting (XSS) vulnerabiity in YzmCMS 5.2 via the site_code parameter in admin/index/init.html.
CVE-2020-18175CRITICAL9.8SQL Injection vulnerability in Metinfo 6.1.3 via a dosafety_emailadd action in basic.php.
CVE-2020-18158MEDIUM5.4Cross Site Scripting (XSS) vulnerability in HuCart 5.7.4 via nickname in index.php.
CVE-2020-18157HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in MetInfo 6.1.3 via a doaddsave action in admin/index.php.
CVE-2020-18013CRITICAL9.8SQL Injextion vulnerability exists in Whatsns 4.0 via the ip parameter in index.php?admin_banned/add.htm.
CVE-2020-16839HIGH7.5On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be chan...
CVE-2020-15948MEDIUM6.1eGain Chat 15.5.5 allows XSS via the Name (aka full_name) field.
CVE-2020-14999HIGH7.5A logic bug in system monitoring driver of Acronis Agent after 12.5.21540 and before 12.5.23094 allowed to bypass Window...
CVE-2020-11511HIGH8.1The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP ...
CVE-2020-10590HIGH7.5Replicated Classic 2.x versions have an improperly secured API that exposes sensitive data from the Replicated Admin Con...
CVE-2020-5353HIGH8.8The Dell Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 default configuration for N...
CVE-2020-5329MEDIUM6.1Dell EMC Avamar Server contains an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulne...
CVE-2020-36239CRITICAL9.8Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8...
CVE-2020-5004MEDIUM5.4IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ...
CVE-2020-4974MEDIUM6.3IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attac...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now