2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26707 | CRITICAL | 9.8 | 1.8% | Oct 31, 2021 | An issue was discovered in the add function in Shenzhim AAPTJS 1.3.1 which allows attackers to execute arbitrary code vi... |
| CVE-2020-26705 | CRITICAL | 9.1 | 1.3% | Oct 31, 2021 | The parseXML function in Easy-XML 0.5.0 was discovered to have a XML External Entity (XXE) vulnerability which allows fo... |
| CVE-2020-25912 | CRITICAL | 9.1 | 1.4% | Oct 31, 2021 | A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10... |
| CVE-2020-25911 | CRITICAL | 9.1 | 2.3% | Oct 31, 2021 | A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which ... |
| CVE-2020-22079 | CRITICAL | 9.8 | 4.0% | Oct 29, 2021 | Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attacke... |
| CVE-2020-21250 | CRITICAL | 9.8 | 1.1% | Oct 27, 2021 | CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php. |
| CVE-2020-24932 | CRITICAL | 9.8 | 1.6% | Oct 27, 2021 | An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complai... |
| CVE-2020-28960 | CRITICAL | 9.8 | 1.5% | Oct 22, 2021 | Chichen Tech CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the file product_list.php via ... |
| CVE-2020-23037 | CRITICAL | 9.8 | 1.4% | Oct 22, 2021 | Portable Ltd Playable v9.18 contains a code injection vulnerability in the filename parameter, which allows attackers to... |
| CVE-2020-27304 | CRITICAL | 9.8 | 3.1% | Oct 21, 2021 | The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the b... |
| CVE-2020-12141 | CRITICAL | 9.1 | 1.5% | Oct 19, 2021 | An out-of-bounds read in the SNMP stack in Contiki-NG 4.4 and earlier allows an attacker to cause a denial of service an... |
| CVE-2020-22724 | CRITICAL | 9.8 | 5.4% | Oct 14, 2021 | A remote command execution vulnerability exists in add_server_service of PPTP_SERVER in Mercury Router MER1200 v1.0.1 an... |
| CVE-2020-27372 | CRITICAL | 9.8 | 1.4% | Oct 11, 2021 | A buffer overflow vulnerability exists in Brandy Basic V Interpreter 1.21 in the run_interpreter function. |
| CVE-2020-22617 | CRITICAL | 9.8 | 1.2% | Oct 8, 2021 | Ardour v5.12 contains a use-after-free vulnerability in the component ardour/libs/pbd/xml++.cc when using xmlFreeDoc and... |
| CVE-2020-21726 | CRITICAL | 9.8 | 1.2% | Oct 7, 2021 | OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the cid par... |
| CVE-2020-21725 | CRITICAL | 9.8 | 1.2% | Oct 7, 2021 | OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the pid par... |
| CVE-2020-21865 | CRITICAL | 9.8 | 1.9% | Oct 7, 2021 | ThinkPHP50-CMS v1.0 contains a remote code execution (RCE) vulnerability in the component /public/?s=captcha. |
| CVE-2020-21653 | CRITICAL | 9.1 | 1.2% | Oct 6, 2021 | Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploit... |
| CVE-2020-21652 | CRITICAL | 9.8 | 2.7% | Oct 6, 2021 | Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be... |
| CVE-2020-21651 | CRITICAL | 9.8 | 3.2% | Oct 6, 2021 | Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be ... |
| CVE-2020-21648 | CRITICAL | 9.1 | 1.3% | Oct 6, 2021 | WDJA CMS v1.5.2 contains an arbitrary file deletion vulnerability in the component admin/cache/manage.php. |
| CVE-2020-21012 | CRITICAL | 9.8 | 3.4% | Oct 1, 2021 | Sourcecodester Hotel and Lodge Management System 2.0 is vulnerable to unauthenticated SQL injection and can allow remote... |
| CVE-2020-20797 | CRITICAL | 9.8 | 1.1% | Sep 30, 2021 | FlameCMS 3.3.5 contains a time-based blind SQL injection vulnerability in /account/register.php. |
| CVE-2020-20796 | CRITICAL | 9.8 | 1.0% | Sep 30, 2021 | FlameCMS 3.3.5 contains a SQL injection vulnerability in /master/article.php via the "Id" parameter. |
| CVE-2020-18685 | CRITICAL | 9.8 | 1.3% | Sep 30, 2021 | Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of unchecked... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now