2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-25877MEDIUM5.4A stored cross site scripting (XSS) vulnerability in the 'Add Page' feature of BlackCat CMS 1.3.6 allows authenticated a...
CVE-2020-25876MEDIUM5.4A stored cross site scripting (XSS) vulnerability in the 'Pages' feature of Codoforum v5.0.2 allows authenticated attack...
CVE-2020-25875MEDIUM5.4A stored cross site scripting (XSS) vulnerability in the 'Smileys' feature of Codoforum v5.0.2 allows authenticated atta...
CVE-2020-25394MEDIUM5.4A stored cross site scripting (XSS) vulnerability in moziloCMS 2.0 allows authenticated attackers to execute arbitrary w...
CVE-2020-25392MEDIUM5.4A cross site scripting (XSS) vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML vi...
CVE-2020-25391MEDIUM5.4A cross site scripting vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML via a cr...
CVE-2020-29014MEDIUM5.3A concurrent execution using shared resource with improper synchronization ('race condition') in the command shell of Fo...
CVE-2020-21333MEDIUM5.4Cross Site Scripting (XSS) vulnerability in PublicCMS 4.0 to get an admin cookie when the Administrator reviews submit c...
CVE-2020-22535MEDIUM6.5Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontrol...
CVE-2020-23580CRITICAL9.8Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board.
CVE-2020-20363MEDIUM4.8Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php.
CVE-2020-18741MEDIUM5.3Improper Authorization in ThinkSAAS v2.7 allows remote attackers to modify the description of any user's photo via the "...
CVE-2020-20586MEDIUM4.5A cross site request forgery (CSRF) vulnerability in the /xyhai.php?s=/Auth/editUser URI of XYHCMS V3.6 allows attackers...
CVE-2020-20585HIGH7.5A blind SQL injection in /admin/?n=logs&c=index&a=dode of Metinfo 7.0 beta allows attackers to access sensitive database...
CVE-2020-20584MEDIUM6.1A cross site scripting vulnerability in baigo CMS v4.0-beta-1 allows attackers to execute arbitrary web scripts or HTML ...
CVE-2020-20583HIGH7.5A SQL injection vulnerability in /question.php of LJCMS Version v4.3.R60321 allows attackers to obtain sensitive databas...
CVE-2020-20582HIGH7.5A server side request forgery (SSRF) vulnerability in /ApiAdminDomainSettings.php of MipCMS 5.0.1 allows attackers to ac...
CVE-2020-28598HIGH7.8An out-of-bounds write vulnerability exists in the Admesh stl_fix_normal_directions() functionality of Prusa Research Pr...
CVE-2020-20217MEDIUM6.5Mikrotik RouterOs before 6.47 (stable tree) suffers from an uncontrolled resource consumption vulnerability in the /nova...
CVE-2020-23702MEDIUM4.8Cross Site Scripting (XSS) vulnerability in PHP-Fusion 9.03.60 via 'New Shout' in /infusions/shoutbox_panel/shoutbox_adm...
CVE-2020-23700MEDIUM4.8Cross Site Scripting (XSS) vulnerability in LavaLite-CMS 5.8.0 via the Menu Links feature.
CVE-2020-25925MEDIUM6.1Cross Site Scripting (XSS) in Webmail Calender in IceWarp WebClient 10.3.5 allows remote attackers to inject arbitrary w...
CVE-2020-25868HIGH7.5Pexip Infinity 22.x through 24.x before 24.2 has Improper Input Validation for call setup. An unauthenticated remote att...
CVE-2020-24149HIGH7.5Server-side request forgery (SSRF) in the Podcast Importer SecondLine (podcast-importer-secondline) plugin 1.1.4 for Wor...
CVE-2020-24148CRITICAL9.1Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now