2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-26707CRITICAL9.8An issue was discovered in the add function in Shenzhim AAPTJS 1.3.1 which allows attackers to execute arbitrary code vi...
CVE-2020-26705CRITICAL9.1The parseXML function in Easy-XML 0.5.0 was discovered to have a XML External Entity (XXE) vulnerability which allows fo...
CVE-2020-25912CRITICAL9.1A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10...
CVE-2020-25911CRITICAL9.1A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which ...
CVE-2020-22079CRITICAL9.8Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attacke...
CVE-2020-21250CRITICAL9.8CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php.
CVE-2020-24932CRITICAL9.8An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complai...
CVE-2020-28960CRITICAL9.8Chichen Tech CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the file product_list.php via ...
CVE-2020-23037CRITICAL9.8Portable Ltd Playable v9.18 contains a code injection vulnerability in the filename parameter, which allows attackers to...
CVE-2020-27304CRITICAL9.8The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the b...
CVE-2020-12141CRITICAL9.1An out-of-bounds read in the SNMP stack in Contiki-NG 4.4 and earlier allows an attacker to cause a denial of service an...
CVE-2020-22724CRITICAL9.8A remote command execution vulnerability exists in add_server_service of PPTP_SERVER in Mercury Router MER1200 v1.0.1 an...
CVE-2020-27372CRITICAL9.8A buffer overflow vulnerability exists in Brandy Basic V Interpreter 1.21 in the run_interpreter function.
CVE-2020-22617CRITICAL9.8Ardour v5.12 contains a use-after-free vulnerability in the component ardour/libs/pbd/xml++.cc when using xmlFreeDoc and...
CVE-2020-21726CRITICAL9.8OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the cid par...
CVE-2020-21725CRITICAL9.8OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the pid par...
CVE-2020-21865CRITICAL9.8ThinkPHP50-CMS v1.0 contains a remote code execution (RCE) vulnerability in the component /public/?s=captcha.
CVE-2020-21653CRITICAL9.1Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploit...
CVE-2020-21652CRITICAL9.8Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be...
CVE-2020-21651CRITICAL9.8Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be ...
CVE-2020-21648CRITICAL9.1WDJA CMS v1.5.2 contains an arbitrary file deletion vulnerability in the component admin/cache/manage.php.
CVE-2020-21012CRITICAL9.8Sourcecodester Hotel and Lodge Management System 2.0 is vulnerable to unauthenticated SQL injection and can allow remote...
CVE-2020-20797CRITICAL9.8FlameCMS 3.3.5 contains a time-based blind SQL injection vulnerability in /account/register.php.
CVE-2020-20796CRITICAL9.8FlameCMS 3.3.5 contains a SQL injection vulnerability in /master/article.php via the "Id" parameter.
CVE-2020-18685CRITICAL9.8Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of unchecked...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now