2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-22166 | HIGH | 7.5 | 2.2% | Jun 22, 2021 | PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\forgot-password.php. Remote ... |
| CVE-2020-22165 | HIGH | 7.5 | 6.3% | Jun 22, 2021 | PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unaut... |
| CVE-2020-22164 | HIGH | 7.5 | 2.2% | Jun 22, 2021 | PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\check_availability.php. Remo... |
| CVE-2020-18648 | HIGH | 8.8 | 0.7% | Jun 22, 2021 | Cross Site Request Forgery (CSRF) in JuQingCMS v1.0 allows remote attackers to gain local privileges via the component "... |
| CVE-2020-18647 | HIGH | 7.5 | 1.5% | Jun 22, 2021 | Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonec... |
| CVE-2020-18646 | HIGH | 7.5 | 1.5% | Jun 22, 2021 | Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/publi... |
| CVE-2020-15732 | HIGH | 7.5 | 0.5% | Jun 22, 2021 | Improper Certificate Validation vulnerability in the Online Threat Prevention module as used in Bitdefender Total Securi... |
| CVE-2020-27511 | HIGH | 7.5 | 2.5% | Jun 21, 2021 | An issue was discovered in the stripTags and unescapeHTML components in Prototype 1.7.3 where an attacker can cause a Re... |
| CVE-2020-19511 | MEDIUM | 6.1 | 0.8% | Jun 21, 2021 | Cross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admi... |
| CVE-2020-19510 | CRITICAL | 9.8 | 1.5% | Jun 21, 2021 | Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php. |
| CVE-2020-21130 | MEDIUM | 6.1 | 0.8% | Jun 21, 2021 | Cross Site Scripting (XSS) vulnerability in HisiPHP 2.0.8 via the group name in addgroup.html. |
| CVE-2020-22390 | HIGH | 8.8 | 1.6% | Jun 21, 2021 | Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrar... |
| CVE-2020-21517 | MEDIUM | 6.1 | 1.2% | Jun 21, 2021 | Cross Site Scripting (XSS) vulnerability in MetInfo 7.0.0 via the gourl parameter in login.php. |
| CVE-2020-7031 | — | — | — | Jun 21, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2020-20474 | HIGH | 7.5 | 1.7% | Jun 21, 2021 | White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the default_task_edituser... |
| CVE-2020-20473 | HIGH | 7.5 | 1.7% | Jun 21, 2021 | White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the control_task.php, con... |
| CVE-2020-20472 | MEDIUM | 5.3 | 1.5% | Jun 21, 2021 | White Shark System (WSS) 1.3.2 has a sensitive information disclosure vulnerability. The if_get_addbook.php file does no... |
| CVE-2020-20471 | HIGH | 8.8 | 2.4% | Jun 21, 2021 | White Shark System (WSS) 1.3.2 has an unauthorized access vulnerability in default_user_edit.php, remote attackers can e... |
| CVE-2020-20470 | MEDIUM | 5.3 | 0.9% | Jun 21, 2021 | White Shark System (WSS) 1.3.2 has web site physical path leakage vulnerability. |
| CVE-2020-20469 | HIGH | 7.5 | 1.7% | Jun 21, 2021 | White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the log_edit.php files fa... |
| CVE-2020-20468 | MEDIUM | 6.5 | 0.5% | Jun 21, 2021 | White Shark System (WSS) 1.3.2 is vulnerable to CSRF. Attackers can use the user_edit_password.php file to modify the us... |
| CVE-2020-20467 | MEDIUM | 6.5 | 1.2% | Jun 21, 2021 | White Shark System (WSS) 1.3.2 is vulnerable to sensitive information disclosure via default_task_add.php, remote attack... |
| CVE-2020-20466 | CRITICAL | 9.8 | 1.8% | Jun 21, 2021 | White Shark System (WSS) 1.3.2 is vulnerable to unauthorized access via user_edit_password.php, remote attackers can mod... |
| CVE-2020-18442 | LOW | 3.3 | 0.7% | Jun 18, 2021 | Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value "zzip_file_r... |
| CVE-2020-36389 | MEDIUM | 4.3 | 0.7% | Jun 17, 2021 | In CiviCRM before 5.28.1 and CiviCRM ESR before 5.27.5 ESR, the CKEditor configuration form allows CSRF. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now