2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-23595HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in yzmcms version 5.6, allows remote attackers to escalate privileges an...
CVE-2020-23564HIGH7.2File Upload vulnerability in SEMCMS 3.9 allows remote attackers to run arbitrary code via SEMCMS_Upfile.php.
CVE-2020-26064HIGH8.1A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain rea...
CVE-2020-10962HIGH7.8In PowerShell App Deployment Toolkit (aka PSAppDeployToolkit) through 3.8.0, an incorrect access control vulnerability i...
CVE-2020-22623HIGH7.5Directory traversal vulnerability in Jinfornet Jreport 15.6 allows unauthenticated attackers to gain sensitive informati...
CVE-2020-22159HIGH8.8EVERTZ devices 3080IPX exe-guest-v1.2-r26125, 7801FC 1.3 Build 27, and 7890IXG V494 are vulnerable to Arbitrary File Upl...
CVE-2020-23909HIGH7.1Heap-based buffer over-read in function png_convert_4 in file pngex.cc in AdvanceMAME through 2.1.
CVE-2020-36695HIGH7.8Incorrect Default Permissions vulnerability in Hitachi Device Manager on Linux (Device Manager Server component), Hitach...
CVE-2020-20021HIGH7.5An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfigurati...
CVE-2020-21862HIGH8.1Directory traversal vulnerability in DuxCMS 2.1 allows attackers to delete arbitrary files via /admin/AdminBackup/del.
CVE-2020-21861HIGH8.8File upload vulnerability in DuxCMS 2.1 allows attackers to execute arbitrary php code via duxcms/AdminUpload/upload.
CVE-2020-36745HIGH8.8The WP Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including...
CVE-2020-36740HIGH8.8The Radio Buttons for Taxonomies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and...
CVE-2020-26710HIGH7.5easy-parse v0.1.1 was discovered to contain a XML External Entity Injection (XXE) vulnerability which allows attackers t...
CVE-2020-26709HIGH7.5py-xml v1.0 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to exe...
CVE-2020-26708HIGH7.5requests-xml v0.2.3 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attacker...
CVE-2020-18406HIGH7.5An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of ...
CVE-2020-18418HIGH8.8A Cross site request forgery (CSRF) vulnerability was discovered in FeiFeiCMS v4.1.190209, which allows attackers to cre...
CVE-2020-20210HIGH8.8Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.
CVE-2020-21486HIGH7.5SQL injection vulnerability in PHPOK v.5.4. allows a remote attacker to obtain sensitive information via the _userlist f...
CVE-2020-21400HIGH7.2SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id ...
CVE-2020-21366HIGH8Cross Site Request Forgery vulnerability in GreenCMS v.2.3 allows an attacker to gain privileges via the adduser functio...
CVE-2020-21325HIGH8.8An issue in WUZHI CMS v.4.1.0 allows a remote attacker to execute arbitrary code via the set_chache method of the functi...
CVE-2020-21252HIGH8.8Cross Site Request Forgery vulnerability in Neeke HongCMS 3.0.0 allows a remote attacker to execute arbitrary code and e...
CVE-2020-20969HIGH7.2File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_resto...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now