2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-36388HIGH8.8In CiviCRM before 5.21.3 and 5.22.x through 5.24.x before 5.24.3, users may be able to upload and execute a crafted PHAR...
CVE-2020-35373MEDIUM6.1In Fiyo CMS 2.0.6.1, the 'tag' parameter results in an unauthenticated XSS attack.
CVE-2020-19202MEDIUM5.4An authenticated Stored XSS (Cross-site Scripting) exists in the "captive.cgi" Captive Portal via the "Title of Login Pa...
CVE-2020-25414CRITICAL9.8A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attacke...
CVE-2020-25755HIGH8.8An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /insta...
CVE-2020-25754HIGH7.5An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication tha...
CVE-2020-25753CRITICAL9.8An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software. The default admin password is set to th...
CVE-2020-25752MEDIUM5.3An issue was discovered on Enphase Envoy R3.x and D4.x devices. There are hardcoded web-panel login passwords for the in...
CVE-2020-22212CRITICAL9.8SQL Injection in 74cms 3.2.0 via the id parameter to wap/wap-company-show.php.
CVE-2020-22211CRITICAL9.8SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.
CVE-2020-22210CRITICAL9.8SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.
CVE-2020-22209CRITICAL9.8SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.
CVE-2020-22208CRITICAL9.8SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.
CVE-2020-22206CRITICAL9.8SQL Injection in ECShop 3.0 via the aid parameter to admin/affiliate_ck.php.
CVE-2020-22205CRITICAL9.8SQL Injection in ECShop 3.0 via the id parameter to admin/shophelp.php.
CVE-2020-22204CRITICAL9.8SQL Injection in ECShop 2.7.6 via the goods_number parameter to flow.php. .
CVE-2020-22203CRITICAL9.8SQL Injection in phpCMS 2008 sp4 via the genre parameter to yp/job.php.
CVE-2020-22201HIGH8.8phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/produc...
CVE-2020-22200MEDIUM5.3Directory Traversal vulnerability in phpCMS 9.1.13 via the q parameter to public_get_suggest_keyword.
CVE-2020-22199CRITICAL9.8SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php.
CVE-2020-35762LOW2.7bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files.
CVE-2020-35761MEDIUM5.4bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code.
CVE-2020-35760CRITICAL9.8bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php fi...
CVE-2020-35759MEDIUM6.5bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).
CVE-2020-27339MEDIUM6.7In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now