2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-17354HIGH8.6LilyPond before 2.24 allows attackers to bypass the -dsafe protection mechanism via output-def-lookup or output-def-scop...
CVE-2020-19803HIGH8.8Cross Site Request Forgery vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary cod...
CVE-2020-36077HIGH8.8SQL injection vulnerability found in Tailor Mangement System v.1 allows a remote attacker to execute arbitrary code via ...
CVE-2020-19678HIGH7.5Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote atta...
CVE-2020-36074HIGH8.8SQL injection vulnerability found in Tailor Mangement System v.1 allows a remote attacker to execute arbitrary code via ...
CVE-2020-36073HIGH8.8SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via...
CVE-2020-36072HIGH8.8SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via...
CVE-2020-36071HIGH8.8SQL injection vulnerability found in Tailor Management System v.1 allows a remote authenticated attacker to execute arbi...
CVE-2020-23260HIGH7.5An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the StringReplaceCmd fun...
CVE-2020-23259HIGH7.5An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the Jsi_Strlen function ...
CVE-2020-23258HIGH7.5An issue found in Jsish v.3.0.11 allows a remote attacker to cause a denial of service via the Jsi_ValueIsNumber functio...
CVE-2020-23257HIGH7.5Buffer Overflow vulnerability found in Espruino 2v05.41 allows an attacker to cause a denial of service via the function...
CVE-2020-21514HIGH8.8An issue was discovered in Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code du...
CVE-2020-21060HIGH8.8SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function...
CVE-2020-19278HIGH8.8Cross Site Request Forgery vulnerability found in Phachon mm-wiki v.0.1.2 allows a remote attacker to execute arbitrary ...
CVE-2020-14140HIGH7.5When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerabil...
CVE-2020-8889HIGH7.5The ShipStation.com plugin 1.0 for CS-Cart allows remote attackers to obtain sensitive information (via action=export) b...
CVE-2020-36666HIGH8.8The directory-pro WordPress plugin before 1.9.5, final-user-wp-frontend-user-profiles WordPress plugin before 1.2.2, pro...
CVE-2020-19786HIGH8.8File upload vulnerability in CSKaza CSZ CMS v.1.2.2 fixed in v1.2.4 allows attacker to execute aritrary commands and cod...
CVE-2020-4927HIGH8.2A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorized access to user dat...
CVE-2020-5002HIGH8.8IBM Financial Transaction Manager 3.2.0 through 3.2.10 could allow an authenticated user to perform unauthorized actions...
CVE-2020-36669HIGH8.8The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to Cross-Site Request Forgery in version...
CVE-2020-5026HIGH7.5IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.7 could allow a remote attac...
CVE-2020-5001HIGH7.5 IBM Financial Transaction Manager 3.2.0 through 3.2.7 could allow a remote attacker to traverse directories on the syst...
CVE-2020-36652HIGH7.1Incorrect Default Permissions vulnerability in Hitachi Automation Director on Linux, Hitachi Infrastructure Analytics Ad...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now