2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-22166HIGH7.5PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\forgot-password.php. Remote ...
CVE-2020-22165HIGH7.5PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unaut...
CVE-2020-22164HIGH7.5PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\check_availability.php. Remo...
CVE-2020-18648HIGH8.8Cross Site Request Forgery (CSRF) in JuQingCMS v1.0 allows remote attackers to gain local privileges via the component "...
CVE-2020-18647HIGH7.5Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonec...
CVE-2020-18646HIGH7.5Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/publi...
CVE-2020-15732HIGH7.5Improper Certificate Validation vulnerability in the Online Threat Prevention module as used in Bitdefender Total Securi...
CVE-2020-27511HIGH7.5An issue was discovered in the stripTags and unescapeHTML components in Prototype 1.7.3 where an attacker can cause a Re...
CVE-2020-19511MEDIUM6.1Cross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admi...
CVE-2020-19510CRITICAL9.8Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.
CVE-2020-21130MEDIUM6.1Cross Site Scripting (XSS) vulnerability in HisiPHP 2.0.8 via the group name in addgroup.html.
CVE-2020-22390HIGH8.8Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrar...
CVE-2020-21517MEDIUM6.1Cross Site Scripting (XSS) vulnerability in MetInfo 7.0.0 via the gourl parameter in login.php.
CVE-2020-7031Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2020-20474HIGH7.5White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the default_task_edituser...
CVE-2020-20473HIGH7.5White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the control_task.php, con...
CVE-2020-20472MEDIUM5.3White Shark System (WSS) 1.3.2 has a sensitive information disclosure vulnerability. The if_get_addbook.php file does no...
CVE-2020-20471HIGH8.8White Shark System (WSS) 1.3.2 has an unauthorized access vulnerability in default_user_edit.php, remote attackers can e...
CVE-2020-20470MEDIUM5.3White Shark System (WSS) 1.3.2 has web site physical path leakage vulnerability.
CVE-2020-20469HIGH7.5White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the log_edit.php files fa...
CVE-2020-20468MEDIUM6.5White Shark System (WSS) 1.3.2 is vulnerable to CSRF. Attackers can use the user_edit_password.php file to modify the us...
CVE-2020-20467MEDIUM6.5White Shark System (WSS) 1.3.2 is vulnerable to sensitive information disclosure via default_task_add.php, remote attack...
CVE-2020-20466CRITICAL9.8White Shark System (WSS) 1.3.2 is vulnerable to unauthorized access via user_edit_password.php, remote attackers can mod...
CVE-2020-18442LOW3.3Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value "zzip_file_r...
CVE-2020-36389MEDIUM4.3In CiviCRM before 5.28.1 and CiviCRM ESR before 5.27.5 ESR, the CKEditor configuration form allows CSRF.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now