2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-19110 | CRITICAL | 9.8 | 1.6% | May 6, 2021 | SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to book.php parameter, which could let ... |
| CVE-2020-19109 | CRITICAL | 9.8 | 1.9% | May 6, 2021 | SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_edit.php, which could let a re... |
| CVE-2020-19108 | CRITICAL | 9.8 | 1.9% | May 6, 2021 | SQL Injection vulnerability in Online Book Store v1.0 via the pubid parameter to bookPerPub.php, which could let a remot... |
| CVE-2020-19107 | CRITICAL | 9.8 | 1.9% | May 6, 2021 | SQL Injection vulnerability in Online Book Store v1.0 via the isbn parameter to edit_book.php, which could let a remote ... |
| CVE-2020-5013 | HIGH | 8.1 | 1.5% | May 5, 2021 | IBM QRadar SIEM 7.3 and 7.4 may vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A r... |
| CVE-2020-4993 | MEDIUM | 4.9 | 1.3% | May 5, 2021 | IBM QRadar SIEM 7.3 and 7.4 when decompressing or verifying signature of zip files processes data in a way that may be v... |
| CVE-2020-4979 | CRITICAL | 9.8 | 1.6% | May 5, 2021 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker that is able to compri... |
| CVE-2020-4932 | HIGH | 7.8 | 0.2% | May 5, 2021 | IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for ... |
| CVE-2020-4929 | MEDIUM | 5.4 | 0.5% | May 5, 2021 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja... |
| CVE-2020-4883 | MEDIUM | 6.5 | 0.8% | May 5, 2021 | IBM QRadar SIEM 7.3 and 7.4 could disclose sensitive information about other domains which could be used in further atta... |
| CVE-2020-13665 | CRITICAL | 9.8 | 1.3% | May 5, 2021 | Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode. Only sites that have the... |
| CVE-2020-13664 | HIGH | 8.8 | 3.0% | May 5, 2021 | Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an admini... |
| CVE-2020-13662 | MEDIUM | 6.1 | 0.9% | May 5, 2021 | Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which woul... |
| CVE-2020-13666 | MEDIUM | 6.1 | 2.9% | May 5, 2021 | Cross-site scripting vulnerability in Drupal Core. Drupal AJAX API does not disable JSONP by default, allowing for an XS... |
| CVE-2020-36334 | HIGH | 8.8 | 0.6% | May 5, 2021 | themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database. |
| CVE-2020-36333 | CRITICAL | 9.1 | 3.4% | May 5, 2021 | themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard... |
| CVE-2020-22428 | MEDIUM | 4.8 | 1.2% | May 5, 2021 | SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an a... |
| CVE-2020-4987 | MEDIUM | 5.4 | 0.5% | May 4, 2021 | The IBM FlashSystem 900 user management GUI is vulnerable to stored cross-site scripting in code versions 1.5.2.8 and pr... |
| CVE-2020-21999 | HIGH | 8.8 | 5.2% | May 4, 2021 | iWT Ltd FaceSentry Access Control System 6.4.8 suffers from an authenticated OS command injection vulnerability using de... |
| CVE-2020-27518 | HIGH | 7.8 | 0.5% | May 4, 2021 | All versions of Windscribe VPN for Mac and Windows <= v2.02.10 contain a local privilege escalation vulnerability in the... |
| CVE-2020-23083 | CRITICAL | 9.8 | 3.7% | May 3, 2021 | Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges ... |
| CVE-2020-23015 | MEDIUM | 6.1 | 2.7% | May 3, 2021 | An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not fil... |
| CVE-2020-35758 | CRITICAL | 9.8 | 1.6% | May 3, 2021 | An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a Authentication Bypass in the Web Interface... |
| CVE-2020-35757 | CRITICAL | 9.8 | 1.8% | May 3, 2021 | An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is Unauthenticated Root ADB Access Over TCP. Th... |
| CVE-2020-35756 | HIGH | 7.5 | 1.2% | May 3, 2021 | An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service GETPASS Configuration Passwor... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now