2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-36388 | HIGH | 8.8 | 1.5% | Jun 17, 2021 | In CiviCRM before 5.21.3 and 5.22.x through 5.24.x before 5.24.3, users may be able to upload and execute a crafted PHAR... |
| CVE-2020-35373 | MEDIUM | 6.1 | 0.7% | Jun 17, 2021 | In Fiyo CMS 2.0.6.1, the 'tag' parameter results in an unauthenticated XSS attack. |
| CVE-2020-19202 | MEDIUM | 5.4 | 0.6% | Jun 17, 2021 | An authenticated Stored XSS (Cross-site Scripting) exists in the "captive.cgi" Captive Portal via the "Title of Login Pa... |
| CVE-2020-25414 | CRITICAL | 9.8 | 2.0% | Jun 17, 2021 | A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attacke... |
| CVE-2020-25755 | HIGH | 8.8 | 3.1% | Jun 16, 2021 | An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /insta... |
| CVE-2020-25754 | HIGH | 7.5 | 1.3% | Jun 16, 2021 | An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication tha... |
| CVE-2020-25753 | CRITICAL | 9.8 | 2.2% | Jun 16, 2021 | An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software. The default admin password is set to th... |
| CVE-2020-25752 | MEDIUM | 5.3 | 1.6% | Jun 16, 2021 | An issue was discovered on Enphase Envoy R3.x and D4.x devices. There are hardcoded web-panel login passwords for the in... |
| CVE-2020-22212 | CRITICAL | 9.8 | 1.4% | Jun 16, 2021 | SQL Injection in 74cms 3.2.0 via the id parameter to wap/wap-company-show.php. |
| CVE-2020-22211 | CRITICAL | 9.8 | 7.9% | Jun 16, 2021 | SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php. |
| CVE-2020-22210 | CRITICAL | 9.8 | 8.6% | Jun 16, 2021 | SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php. |
| CVE-2020-22209 | CRITICAL | 9.8 | 8.6% | Jun 16, 2021 | SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php. |
| CVE-2020-22208 | CRITICAL | 9.8 | 9.7% | Jun 16, 2021 | SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php. |
| CVE-2020-22206 | CRITICAL | 9.8 | 1.4% | Jun 16, 2021 | SQL Injection in ECShop 3.0 via the aid parameter to admin/affiliate_ck.php. |
| CVE-2020-22205 | CRITICAL | 9.8 | 1.4% | Jun 16, 2021 | SQL Injection in ECShop 3.0 via the id parameter to admin/shophelp.php. |
| CVE-2020-22204 | CRITICAL | 9.8 | 1.4% | Jun 16, 2021 | SQL Injection in ECShop 2.7.6 via the goods_number parameter to flow.php. . |
| CVE-2020-22203 | CRITICAL | 9.8 | 1.1% | Jun 16, 2021 | SQL Injection in phpCMS 2008 sp4 via the genre parameter to yp/job.php. |
| CVE-2020-22201 | HIGH | 8.8 | 1.5% | Jun 16, 2021 | phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/produc... |
| CVE-2020-22200 | MEDIUM | 5.3 | 1.4% | Jun 16, 2021 | Directory Traversal vulnerability in phpCMS 9.1.13 via the q parameter to public_get_suggest_keyword. |
| CVE-2020-22199 | CRITICAL | 9.8 | 1.2% | Jun 16, 2021 | SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php. |
| CVE-2020-35762 | LOW | 2.7 | 1.0% | Jun 16, 2021 | bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files. |
| CVE-2020-35761 | MEDIUM | 5.4 | 0.8% | Jun 16, 2021 | bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code. |
| CVE-2020-35760 | CRITICAL | 9.8 | 1.9% | Jun 16, 2021 | bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php fi... |
| CVE-2020-35759 | MEDIUM | 6.5 | 0.8% | Jun 16, 2021 | bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely). |
| CVE-2020-27339 | MEDIUM | 6.7 | 0.3% | Jun 16, 2021 | In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now