2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-20979 | CRITICAL | 9.8 | 1.6% | Aug 12, 2021 | An arbitrary file upload vulnerability in the move_uploaded_file() function of LJCMS v4.3 allows attackers to execute ar... |
| CVE-2020-20975 | CRITICAL | 9.8 | 1.3% | Aug 12, 2021 | In \lib\admin\action\dataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter. |
| CVE-2020-28165 | CRITICAL | 9.8 | 1.1% | Aug 12, 2021 | The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload a... |
| CVE-2020-25566 | CRITICAL | 9.8 | 1.6% | Aug 11, 2021 | In SapphireIMS 5.0, it is possible to take over an account by sending a request to the Save_Password form as shown in PO... |
| CVE-2020-25565 | CRITICAL | 9.8 | 2.1% | Aug 11, 2021 | In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and ga... |
| CVE-2020-25563 | CRITICAL | 9.8 | 1.6% | Aug 11, 2021 | In SapphireIMS 5.0, it is possible to create local administrator on any client without requiring any credentials by dire... |
| CVE-2020-25560 | CRITICAL | 9.8 | 2.1% | Aug 11, 2021 | In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and ga... |
| CVE-2020-21359 | CRITICAL | 9.8 | 1.7% | Aug 11, 2021 | An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix wh... |
| CVE-2020-23151 | CRITICAL | 9.8 | 5.7% | Aug 9, 2021 | rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since t... |
| CVE-2020-36452 | CRITICAL | 9.8 | 1.1% | Aug 8, 2021 | An issue was discovered in the array-tools crate before 0.3.2 for Rust. FixedCapacityDequeLike::clone() has a drop of un... |
| CVE-2020-36443 | CRITICAL | 9.8 | 1.2% | Aug 8, 2021 | An issue was discovered in the libp2p-deflate crate before 0.27.1 for Rust. An uninitialized buffer is passed to AsyncRe... |
| CVE-2020-36434 | CRITICAL | 9.8 | 1.2% | Aug 8, 2021 | An issue was discovered in the sys-info crate before 0.8.0 for Rust. sys_info::disk_info calls can trigger a double free... |
| CVE-2020-36432 | CRITICAL | 9.8 | 1.2% | Aug 8, 2021 | An issue was discovered in the alg_ds crate through 2020-08-25 for Rust. There is a drop of uninitialized memory in Matr... |
| CVE-2020-28088 | CRITICAL | 9.8 | 2.3% | Aug 6, 2021 | An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execut... |
| CVE-2020-19305 | CRITICAL | 9.8 | 2.1% | Aug 3, 2021 | An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when ... |
| CVE-2020-19302 | CRITICAL | 9.8 | 1.7% | Aug 3, 2021 | An arbitrary file upload vulnerability in the avatar upload function of vaeThink v1.0.1 allows attackers to open a websh... |
| CVE-2020-19301 | CRITICAL | 9.8 | 2.5% | Aug 3, 2021 | A vulnerability in the vae_admin_rule database table of vaeThink v1.0.1 allows attackers to execute arbitrary code via a... |
| CVE-2020-21809 | CRITICAL | 9.8 | 1.6% | Jul 30, 2021 | SQL Injection vulnerability in NukeViet CMS module Shops 4.0.29 and 4.3 via the (1) listid parameter in detail.php and t... |
| CVE-2020-21808 | CRITICAL | 9.8 | 1.6% | Jul 30, 2021 | SQL Injection vulnerability in NukeViet CMS 4.0.10 - 4.3.07 via:the topicsid parameter in modules/news/admin/addtotopics... |
| CVE-2020-21806 | CRITICAL | 9.8 | 1.2% | Jul 30, 2021 | SQL Injection Vulnerability in ECTouch v2 via the shop page in index.php.. |
| CVE-2020-18175 | CRITICAL | 9.8 | 1.5% | Jul 30, 2021 | SQL Injection vulnerability in Metinfo 6.1.3 via a dosafety_emailadd action in basic.php. |
| CVE-2020-18013 | CRITICAL | 9.8 | 1.4% | Jul 30, 2021 | SQL Injextion vulnerability exists in Whatsns 4.0 via the ip parameter in index.php?admin_banned/add.htm. |
| CVE-2020-36239 | CRITICAL | 9.8 | 48.9% | Jul 29, 2021 | Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8... |
| CVE-2020-5341 | CRITICAL | 9.8 | 4.3% | Jul 28, 2021 | Deserialization of Untrusted Data Vulnerability Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2, 19.1 and 19.2... |
| CVE-2020-18174 | CRITICAL | 9.8 | 1.3% | Jul 26, 2021 | A process injection vulnerability in setup.exe of AutoHotkey 1.1.32.00 allows attackers to escalate privileges. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now