2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-21788 | MEDIUM | 4.3 | 0.7% | Jun 24, 2021 | In CRMEB 3.1.0+ strict domain name filtering leads to SSRF(Server-Side Request Forgery). The vulnerable code is in file ... |
| CVE-2020-21787 | CRITICAL | 9.8 | 1.8% | Jun 24, 2021 | CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php. |
| CVE-2020-18661 | MEDIUM | 6.1 | 1.1% | Jun 24, 2021 | Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the url parameter to bbs/login.php. |
| CVE-2020-28097 | MEDIUM | 5.9 | 0.5% | Jun 24, 2021 | The vgacon subsystem in the Linux kernel before 5.8.10 mishandles software scrollback. There is a vgacon_scrolldelta out... |
| CVE-2020-7862 | HIGH | 8.8 | 1.1% | Jun 24, 2021 | A vulnerability in agent program of HelpU remote control solution could allow an authenticated remote attacker to execut... |
| CVE-2020-18660 | MEDIUM | 6.1 | 1.3% | Jun 23, 2021 | GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter. |
| CVE-2020-23962 | MEDIUM | 6.1 | 0.7% | Jun 23, 2021 | A cross site scripting (XSS) vulnerability in Catfish CMS 4.9.90 allows attackers to execute arbitrary web scripts or HT... |
| CVE-2020-18659 | MEDIUM | 6.1 | 1.3% | Jun 23, 2021 | Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters... |
| CVE-2020-18658 | MEDIUM | 6.1 | 1.4% | Jun 23, 2021 | Cross Site Scriptiong (XSS) vulnerability in GetSimpleCMS <=3.3.15 via the timezone parameter to settings.php. |
| CVE-2020-18657 | MEDIUM | 6.1 | 1.4% | Jun 23, 2021 | Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url paramete... |
| CVE-2020-20392 | CRITICAL | 9.8 | 1.4% | Jun 23, 2021 | SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php. |
| CVE-2020-20391 | MEDIUM | 5.4 | 0.6% | Jun 23, 2021 | Cross Site Scripting vulnerability in GetSimpleCMS 3.4.0a in admin/snippets.php via (1) Add Snippet and (2) Save snippet... |
| CVE-2020-20389 | MEDIUM | 4.8 | 0.6% | Jun 23, 2021 | Cross Site Scripting (XSS) vulnerability in GetSimpleCMS 3.4.0a in admin/edit.php. |
| CVE-2020-36394 | HIGH | 7 | 0.3% | Jun 22, 2021 | pam_setquota.c in the pam_setquota module before 2020-05-29 for Linux-PAM allows local attackers to set their quota on a... |
| CVE-2020-18654 | MEDIUM | 6.1 | 1.5% | Jun 22, 2021 | Cross Site Scripting (XSS) in Wuzhi CMS v4.1.0 allows remote attackers to execute arbitrary code via the "Title" paramet... |
| CVE-2020-22176 | HIGH | 7.5 | 2.1% | Jun 22, 2021 | PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas... |
| CVE-2020-22175 | HIGH | 7.5 | 2.2% | Jun 22, 2021 | PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\admin\betweendates-detailsre... |
| CVE-2020-22174 | HIGH | 7.5 | 2.2% | Jun 22, 2021 | PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\book-appointment.php. Remote... |
| CVE-2020-22173 | HIGH | 7.5 | 2.2% | Jun 22, 2021 | PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\edit-profile.php. Remote una... |
| CVE-2020-22172 | HIGH | 7.5 | 2.2% | Jun 22, 2021 | PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unaut... |
| CVE-2020-22171 | HIGH | 7.5 | 2.2% | Jun 22, 2021 | PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\registration.php. Remote una... |
| CVE-2020-22170 | HIGH | 7.5 | 2.2% | Jun 22, 2021 | PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unaut... |
| CVE-2020-22169 | HIGH | 7.5 | 2.2% | Jun 22, 2021 | PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\appointment-history.php. Rem... |
| CVE-2020-22168 | HIGH | 7.5 | 2.4% | Jun 22, 2021 | PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\change-emaild.php. Remote un... |
| CVE-2020-22167 | MEDIUM | 5.4 | 0.5% | Jun 22, 2021 | PHPGurukul Hospital Management System in PHP v4.0 has a Persistent Cross-Site Scripting vulnerability in \hms\admin\appo... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now