2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-19110CRITICAL9.8SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to book.php parameter, which could let ...
CVE-2020-19109CRITICAL9.8SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_edit.php, which could let a re...
CVE-2020-19108CRITICAL9.8SQL Injection vulnerability in Online Book Store v1.0 via the pubid parameter to bookPerPub.php, which could let a remot...
CVE-2020-19107CRITICAL9.8SQL Injection vulnerability in Online Book Store v1.0 via the isbn parameter to edit_book.php, which could let a remote ...
CVE-2020-5013HIGH8.1IBM QRadar SIEM 7.3 and 7.4 may vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A r...
CVE-2020-4993MEDIUM4.9IBM QRadar SIEM 7.3 and 7.4 when decompressing or verifying signature of zip files processes data in a way that may be v...
CVE-2020-4979CRITICAL9.8IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker that is able to compri...
CVE-2020-4932HIGH7.8IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for ...
CVE-2020-4929MEDIUM5.4IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja...
CVE-2020-4883MEDIUM6.5IBM QRadar SIEM 7.3 and 7.4 could disclose sensitive information about other domains which could be used in further atta...
CVE-2020-13665CRITICAL9.8Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode. Only sites that have the...
CVE-2020-13664HIGH8.8Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an admini...
CVE-2020-13662MEDIUM6.1Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which woul...
CVE-2020-13666MEDIUM6.1Cross-site scripting vulnerability in Drupal Core. Drupal AJAX API does not disable JSONP by default, allowing for an XS...
CVE-2020-36334HIGH8.8themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database.
CVE-2020-36333CRITICAL9.1themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard...
CVE-2020-22428MEDIUM4.8SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an a...
CVE-2020-4987MEDIUM5.4The IBM FlashSystem 900 user management GUI is vulnerable to stored cross-site scripting in code versions 1.5.2.8 and pr...
CVE-2020-21999HIGH8.8iWT Ltd FaceSentry Access Control System 6.4.8 suffers from an authenticated OS command injection vulnerability using de...
CVE-2020-27518HIGH7.8All versions of Windscribe VPN for Mac and Windows <= v2.02.10 contain a local privilege escalation vulnerability in the...
CVE-2020-23083CRITICAL9.8Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges ...
CVE-2020-23015MEDIUM6.1An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not fil...
CVE-2020-35758CRITICAL9.8An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a Authentication Bypass in the Web Interface...
CVE-2020-35757CRITICAL9.8An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is Unauthenticated Root ADB Access Over TCP. Th...
CVE-2020-35756HIGH7.5An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service GETPASS Configuration Passwor...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now