2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-25877 | MEDIUM | 5.4 | 0.5% | Jul 9, 2021 | A stored cross site scripting (XSS) vulnerability in the 'Add Page' feature of BlackCat CMS 1.3.6 allows authenticated a... |
| CVE-2020-25876 | MEDIUM | 5.4 | 0.5% | Jul 9, 2021 | A stored cross site scripting (XSS) vulnerability in the 'Pages' feature of Codoforum v5.0.2 allows authenticated attack... |
| CVE-2020-25875 | MEDIUM | 5.4 | 0.5% | Jul 9, 2021 | A stored cross site scripting (XSS) vulnerability in the 'Smileys' feature of Codoforum v5.0.2 allows authenticated atta... |
| CVE-2020-25394 | MEDIUM | 5.4 | 0.4% | Jul 9, 2021 | A stored cross site scripting (XSS) vulnerability in moziloCMS 2.0 allows authenticated attackers to execute arbitrary w... |
| CVE-2020-25392 | MEDIUM | 5.4 | 0.4% | Jul 9, 2021 | A cross site scripting (XSS) vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML vi... |
| CVE-2020-25391 | MEDIUM | 5.4 | 0.4% | Jul 9, 2021 | A cross site scripting vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML via a cr... |
| CVE-2020-29014 | MEDIUM | 5.3 | 0.5% | Jul 9, 2021 | A concurrent execution using shared resource with improper synchronization ('race condition') in the command shell of Fo... |
| CVE-2020-21333 | MEDIUM | 5.4 | 0.5% | Jul 9, 2021 | Cross Site Scripting (XSS) vulnerability in PublicCMS 4.0 to get an admin cookie when the Administrator reviews submit c... |
| CVE-2020-22535 | MEDIUM | 6.5 | 0.8% | Jul 9, 2021 | Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontrol... |
| CVE-2020-23580 | CRITICAL | 9.8 | 2.5% | Jul 8, 2021 | Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board. |
| CVE-2020-20363 | MEDIUM | 4.8 | 0.8% | Jul 8, 2021 | Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php. |
| CVE-2020-18741 | MEDIUM | 5.3 | 0.9% | Jul 8, 2021 | Improper Authorization in ThinkSAAS v2.7 allows remote attackers to modify the description of any user's photo via the "... |
| CVE-2020-20586 | MEDIUM | 4.5 | 0.5% | Jul 8, 2021 | A cross site request forgery (CSRF) vulnerability in the /xyhai.php?s=/Auth/editUser URI of XYHCMS V3.6 allows attackers... |
| CVE-2020-20585 | HIGH | 7.5 | 1.8% | Jul 8, 2021 | A blind SQL injection in /admin/?n=logs&c=index&a=dode of Metinfo 7.0 beta allows attackers to access sensitive database... |
| CVE-2020-20584 | MEDIUM | 6.1 | 1.1% | Jul 8, 2021 | A cross site scripting vulnerability in baigo CMS v4.0-beta-1 allows attackers to execute arbitrary web scripts or HTML ... |
| CVE-2020-20583 | HIGH | 7.5 | 1.3% | Jul 8, 2021 | A SQL injection vulnerability in /question.php of LJCMS Version v4.3.R60321 allows attackers to obtain sensitive databas... |
| CVE-2020-20582 | HIGH | 7.5 | 1.1% | Jul 8, 2021 | A server side request forgery (SSRF) vulnerability in /ApiAdminDomainSettings.php of MipCMS 5.0.1 allows attackers to ac... |
| CVE-2020-28598 | HIGH | 7.8 | 1.3% | Jul 8, 2021 | An out-of-bounds write vulnerability exists in the Admesh stl_fix_normal_directions() functionality of Prusa Research Pr... |
| CVE-2020-20217 | MEDIUM | 6.5 | 2.0% | Jul 8, 2021 | Mikrotik RouterOs before 6.47 (stable tree) suffers from an uncontrolled resource consumption vulnerability in the /nova... |
| CVE-2020-23702 | MEDIUM | 4.8 | 0.6% | Jul 7, 2021 | Cross Site Scripting (XSS) vulnerability in PHP-Fusion 9.03.60 via 'New Shout' in /infusions/shoutbox_panel/shoutbox_adm... |
| CVE-2020-23700 | MEDIUM | 4.8 | 0.6% | Jul 7, 2021 | Cross Site Scripting (XSS) vulnerability in LavaLite-CMS 5.8.0 via the Menu Links feature. |
| CVE-2020-25925 | MEDIUM | 6.1 | 1.0% | Jul 7, 2021 | Cross Site Scripting (XSS) in Webmail Calender in IceWarp WebClient 10.3.5 allows remote attackers to inject arbitrary w... |
| CVE-2020-25868 | HIGH | 7.5 | 1.3% | Jul 7, 2021 | Pexip Infinity 22.x through 24.x before 24.2 has Improper Input Validation for call setup. An unauthenticated remote att... |
| CVE-2020-24149 | HIGH | 7.5 | 1.7% | Jul 7, 2021 | Server-side request forgery (SSRF) in the Podcast Importer SecondLine (podcast-importer-secondline) plugin 1.1.4 for Wor... |
| CVE-2020-24148 | CRITICAL | 9.1 | 14.7% | Jul 7, 2021 | Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now