2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15077MEDIUM5.3OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control c...
CVE-2020-36009HIGH7.5OBottle 2.0 in \c\g.php contains an arbitrary file download vulnerability.
CVE-2020-36008HIGH8.1OBottle 2.0 in \c\t.php contains an arbitrary file write vulnerability.
CVE-2020-36007MEDIUM6.1AppCMS 2.0.101 in /admin/template/tpl_app.php has a cross site scripting attack vulnerability which allows the attacker ...
CVE-2020-36006MEDIUM6.5AppCMS 2.0.101 in /admin/info.php has an arbitrary file deletion vulnerability which allows attackers to delete arbitrar...
CVE-2020-36005MEDIUM6.5AppCMS 2.0.101 in /admin/app.php has an arbitrary file deletion vulnerability which allows attackers to delete arbitrary...
CVE-2020-36004MEDIUM6.5AppCMS 2.0.101 in /admin/download_frame.php has a SQL injection vulnerability which allows attackers to obtain sensitive...
CVE-2020-35973MEDIUM5.4An issue was discovered in zzcms2020. There is a XSS vulnerability that can insert and execute JS code arbitrarily via /...
CVE-2020-35972MEDIUM4.3An issue was discovered in YzmCMS V5.8. There is a CSRF vulnerability that can add member user accounts via member/membe...
CVE-2020-35971MEDIUM5.4A storage XSS vulnerability is found in YzmCMS v5.8, which can be used by attackers to inject JS code and attack malicio...
CVE-2020-35970HIGH7.5An issue was discovered in YzmCMS 5.8. There is a SSRF vulnerability in the background collection management that allows...
CVE-2020-28469HIGH7.5This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure con...
CVE-2020-21005MEDIUM6.5WellCMS 2.0 beta3 is vulnerable to File Upload. A user can log in to the CMS background and upload a picture. Because th...
CVE-2020-21003MEDIUM4.8Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php.
CVE-2020-35442CRITICAL9.8FDCMS (also known as Fangfa Content Management System) 4.0 allows remote attackers to get a webshell in the background v...
CVE-2020-35441CRITICAL9.8FDCMS (aka Fangfa Content Management System) 4.0 contains a front-end SQL injection via Admin/Lib/Action/FloginAction.cl...
CVE-2020-5030MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2020-4977MEDIUM5.4IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability all...
CVE-2020-4732MEDIUM6.5IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due t...
CVE-2020-4495HIGH8.8IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused b...
CVE-2020-22056MEDIUM6.5A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the config_input function in af_acrossove...
CVE-2020-22054MEDIUM6.5A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_dict_set function in dict.c.
CVE-2020-25362HIGH7.5The id paramater in Online Shopping Alphaware 1.0 has been discovered to be vulnerable to an Error-Based blind SQL injec...
CVE-2020-24862HIGH7.5The catID parameter in Pharmacy Medical Store and Sale Point v1.0 has been found to be vulnerable to a Time-Based blind ...
CVE-2020-22051MEDIUM6.5A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the filter_frame function in vf_tile.c.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now