2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-23711CRITICAL9.8SQL Injection vulnerability in NavigateCMS 2.9 via the URL encoded GET input category in navigate.php.
CVE-2020-23710MEDIUM5.4Cross Site Scripting (XSS) vulneraiblity in LimeSurvey 4.2.5 on textbox via the Notifications & data feature.
CVE-2020-28200MEDIUM4.3The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with ...
CVE-2020-15303MEDIUM6.5Infoblox NIOS before 8.5.2 allows entity expansion during an XML upload operation, a related issue to CVE-2003-1564.
CVE-2020-4610HIGH7.8IBM Security Secret Server (IBM Security Verify Privilege Manager 10.8.2 ) could allow a local user to execute code due ...
CVE-2020-4609HIGH7.8IBM Security Sevret Server (IBM Security Verify Privilege Manager 10.8.2) is vulnerable to a buffer overflow, caused by ...
CVE-2020-26801MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was discovered in /Forms/device_vars_1 on TrippLite SU2200RTXL2Ua with...
CVE-2020-17759HIGH8.8An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers fo...
CVE-2020-17753MEDIUM6.5An issue was discovered in function addMeByRC in the smart contract implementation for RC, an Ethereum token, allows att...
CVE-2020-17752CRITICAL9.8Integer overflow vulnerability in payable function of a smart contract implementation for an Ethereum token, as demonstr...
CVE-2020-4945HIGH8.1IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite ar...
CVE-2020-4885MEDIUM4.7IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow a local user to access and change the...
CVE-2020-18671MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php.
CVE-2020-18670MEDIUM5.4Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php.
CVE-2020-18668MEDIUM5.4Cross Site Scripting (XSS) vulnerabililty in WebPort <=1.19.1 via the description parameter to script/listcalls.
CVE-2020-18667CRITICAL9.8SQL Injection vulnerability in WebPort <=1.19.1 via the new connection, parameter name in type-conn.
CVE-2020-21786CRITICAL9.8In IBOS 4.5.4 Open, Arbitrary File Inclusion causes getshell via /system/modules/dashboard/controllers/CronController.ph...
CVE-2020-21785HIGH8.8In IBOS 4.5.4 Open, the database backup has Command Injection Vulnerability.
CVE-2020-21784CRITICAL9.8phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.
CVE-2020-21783MEDIUM6.1In IBOS 4.5.4 the email function has a cross site scripting (XSS) vulnerability in emailbody[content] parameter.
CVE-2020-18666Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-18664. Reason: This candidate is a duplicate of ...
CVE-2020-18665MEDIUM5.3Directory Traversal vulnerability in WebPort <=1.19.1 in tags of system settings.
CVE-2020-18664MEDIUM5.4Cross Site Scripting (XSS) vulnerability in WebPort <=1.19.1via the connection name parameter in type-conn.
CVE-2020-18663MEDIUM6.1Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the act parameter in bbs/move_update.php.
CVE-2020-18662CRITICAL9.8SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now