2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-23711 | CRITICAL | 9.8 | 1.5% | Jun 28, 2021 | SQL Injection vulnerability in NavigateCMS 2.9 via the URL encoded GET input category in navigate.php. |
| CVE-2020-23710 | MEDIUM | 5.4 | 0.6% | Jun 28, 2021 | Cross Site Scripting (XSS) vulneraiblity in LimeSurvey 4.2.5 on textbox via the Notifications & data feature. |
| CVE-2020-28200 | MEDIUM | 4.3 | 2.0% | Jun 28, 2021 | The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with ... |
| CVE-2020-15303 | MEDIUM | 6.5 | 0.9% | Jun 28, 2021 | Infoblox NIOS before 8.5.2 allows entity expansion during an XML upload operation, a related issue to CVE-2003-1564. |
| CVE-2020-4610 | HIGH | 7.8 | 0.2% | Jun 25, 2021 | IBM Security Secret Server (IBM Security Verify Privilege Manager 10.8.2 ) could allow a local user to execute code due ... |
| CVE-2020-4609 | HIGH | 7.8 | 0.3% | Jun 25, 2021 | IBM Security Sevret Server (IBM Security Verify Privilege Manager 10.8.2) is vulnerable to a buffer overflow, caused by ... |
| CVE-2020-26801 | MEDIUM | 5.4 | 0.7% | Jun 25, 2021 | A stored cross-site scripting (XSS) vulnerability was discovered in /Forms/device_vars_1 on TrippLite SU2200RTXL2Ua with... |
| CVE-2020-17759 | HIGH | 8.8 | 2.5% | Jun 24, 2021 | An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers fo... |
| CVE-2020-17753 | MEDIUM | 6.5 | 1.5% | Jun 24, 2021 | An issue was discovered in function addMeByRC in the smart contract implementation for RC, an Ethereum token, allows att... |
| CVE-2020-17752 | CRITICAL | 9.8 | 1.6% | Jun 24, 2021 | Integer overflow vulnerability in payable function of a smart contract implementation for an Ethereum token, as demonstr... |
| CVE-2020-4945 | HIGH | 8.1 | 1.0% | Jun 24, 2021 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite ar... |
| CVE-2020-4885 | MEDIUM | 4.7 | 0.3% | Jun 24, 2021 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow a local user to access and change the... |
| CVE-2020-18671 | MEDIUM | 5.4 | 0.8% | Jun 24, 2021 | Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php. |
| CVE-2020-18670 | MEDIUM | 5.4 | 0.9% | Jun 24, 2021 | Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php. |
| CVE-2020-18668 | MEDIUM | 5.4 | 0.8% | Jun 24, 2021 | Cross Site Scripting (XSS) vulnerabililty in WebPort <=1.19.1 via the description parameter to script/listcalls. |
| CVE-2020-18667 | CRITICAL | 9.8 | 1.4% | Jun 24, 2021 | SQL Injection vulnerability in WebPort <=1.19.1 via the new connection, parameter name in type-conn. |
| CVE-2020-21786 | CRITICAL | 9.8 | 1.1% | Jun 24, 2021 | In IBOS 4.5.4 Open, Arbitrary File Inclusion causes getshell via /system/modules/dashboard/controllers/CronController.ph... |
| CVE-2020-21785 | HIGH | 8.8 | 2.7% | Jun 24, 2021 | In IBOS 4.5.4 Open, the database backup has Command Injection Vulnerability. |
| CVE-2020-21784 | CRITICAL | 9.8 | 1.4% | Jun 24, 2021 | phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php. |
| CVE-2020-21783 | MEDIUM | 6.1 | 0.7% | Jun 24, 2021 | In IBOS 4.5.4 the email function has a cross site scripting (XSS) vulnerability in emailbody[content] parameter. |
| CVE-2020-18666 | — | — | — | Jun 24, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-18664. Reason: This candidate is a duplicate of ... |
| CVE-2020-18665 | MEDIUM | 5.3 | 1.7% | Jun 24, 2021 | Directory Traversal vulnerability in WebPort <=1.19.1 in tags of system settings. |
| CVE-2020-18664 | MEDIUM | 5.4 | 0.7% | Jun 24, 2021 | Cross Site Scripting (XSS) vulnerability in WebPort <=1.19.1via the connection name parameter in type-conn. |
| CVE-2020-18663 | MEDIUM | 6.1 | 1.1% | Jun 24, 2021 | Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the act parameter in bbs/move_update.php. |
| CVE-2020-18662 | CRITICAL | 9.8 | 5.4% | Jun 24, 2021 | SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now