2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-28400HIGH7.5Affected devices contain a vulnerability that allows an unauthenticated attacker to trigger a denial of service conditio...
CVE-2020-26153MEDIUM6.1A cross-site scripting (XSS) vulnerability in wp-content/plugins/event-espresso-core-reg/admin_pages/messages/templates/...
CVE-2020-11307CRITICAL9.8Buffer overflow in modem due to improper array index check before copying into it in Snapdragon Auto, Snapdragon Compute...
CVE-2020-19907HIGH8.8A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to e...
CVE-2020-18544CRITICAL9.8SQL Injection in WMS v1.0 allows remote attackers to execute arbitrary code via the "username" parameter in the componen...
CVE-2020-23079HIGH7.5SSRF vulnerability in Halo <=1.3.2 exists in the SMTP configuration, which can detect the server intranet.
CVE-2020-19038CRITICAL9.1File Deletion vulnerability in Halo 0.4.3 via delBackup.
CVE-2020-19037MEDIUM5.3Incorrect Access Control vulnearbility in Halo 0.4.3, which allows a malicious user to bypass encrption to view encrpted...
CVE-2020-18982MEDIUM5.4Cross Sie Scripting (XSS) vulnerability in Halo 0.4.3 via CommentAuthorUrl.
CVE-2020-4938HIGH8.8IBM MQ Appliance 9.1 and 9.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malici...
CVE-2020-19204MEDIUM5.4An authenticated Stored Cross-Site Scriptiong (XSS) vulnerability exists in Lightning Wire Labs IPFire 2.21 (x86_64) - C...
CVE-2020-19203MEDIUM5.4An authenticated Cross-Site Scripting (XSS) vulnerability was found in widgets/widgets/wake_on_lan_widget.php, a compone...
CVE-2020-19201MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was found in status_filter_reload.php, a page in the pfSense software ...
CVE-2020-18980CRITICAL9.8Remote Code Executon vulnerability in Halo 0.4.3 via the remoteAddr and themeName parameters.
CVE-2020-18979MEDIUM6.1Cross Siste Scripting (XSS) vulnerablity in Halo 0.4.3 via the X-forwarded-for Header parameter.
CVE-2020-7872HIGH7.8DaviewIndy v8.98.7.0 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malform...
CVE-2020-21133CRITICAL9.8SQL Injection vulnerability in Metinfo 7.0.0 beta in member/getpassword.php?lang=cn&a=dovalid.
CVE-2020-21132CRITICAL9.8SQL Injection vulnerability in Metinfo 7.0.0beta in index.php.
CVE-2020-21131HIGH7.2SQL Injection vulnerability in MetInfo 7.0.0beta via admin/?n=language&c=language_web&a=doAddLanguage.
CVE-2020-35987MEDIUM5.4A stored cross site scripting (XSS) vulnerability in the 'Entities List' feature of Rukovoditel 2.7.2 allows authenticat...
CVE-2020-35986MEDIUM5.4A stored cross site scripting (XSS) vulnerability in the 'Users Access Groups' feature of Rukovoditel 2.7.2 allows authe...
CVE-2020-35985MEDIUM5.4A stored cross site scripting (XSS) vulnerability in the 'Global Lists" feature of Rukovoditel 2.7.2 allows authenticate...
CVE-2020-35984MEDIUM5.4A stored cross site scripting (XSS) vulnerability in the 'Users Alerts' feature of Rukovoditel 2.7.2 allows authenticate...
CVE-2020-25879MEDIUM5.4A stored cross site scripting (XSS) vulnerability in the 'Manage Users' feature of Codoforum v5.0.2 allows authenticated...
CVE-2020-25878MEDIUM4.8A stored cross site scripting (XSS) vulnerability in the 'Admin-Tools' feature of BlackCat CMS 1.3.6 allows authenticate...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now