2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13566HIGH8.8SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An a...
CVE-2020-15390CRITICAL9.8pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerabi...
CVE-2020-4965HIGH7.5IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker to decrypt ...
CVE-2020-4964MEDIUM4.3IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a c...
CVE-2020-4920MEDIUM5.4IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed ar...
CVE-2020-7924MEDIUM6.5Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, ma...
CVE-2020-15734MEDIUM5.5An Origin Validation Error vulnerability in Bitdefender Safepay allows an attacker to manipulate the browser's file uplo...
CVE-2020-15942MEDIUM6.5An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.2...
CVE-2020-28872CRITICAL9.8An authorization bypass vulnerability in Monitorr v1.7.6m in Monitorr/assets/config/_installation/_register.php allows a...
CVE-2020-24285HIGH7.5INTELBRAS TELEFONE IP TIP200 version 60.61.75.22 allows an attacker to obtain sensitive information through /cgi-bin/cgi...
CVE-2020-36318CRITICAL9.8In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than ...
CVE-2020-36317HIGH7.5In the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem. It allows creation ...
CVE-2020-23763CRITICAL9.8SQL injection in admin.php in Online Book Store 1.0 allows remote attackers to execute arbitrary SQL commands and bypass...
CVE-2020-23762MEDIUM5.4Cross Site Scripting (XSS) vulnerability in the Larsens Calender plugin Version <= 1.2 for WordPress allows remote attac...
CVE-2020-23761MEDIUM6.1Cross Site Scripting (XSS) vulnerability in subrion CMS Version <= 4.2.1 allows remote attackers to execute arbitrary we...
CVE-2020-13592HIGH8.8An exploitable SQL injection vulnerability exists in "global_lists/choices" page of the Rukovoditel Project Management A...
CVE-2020-13591HIGH8.8An exploitable SQL injection vulnerability exists in the "access_rules/rules_form" page of the Rukovoditel Project Manag...
CVE-2020-13587HIGH8.8An exploitable SQL injection vulnerability exists in the "forms_fields_rules/rules" page of the Rukovoditel Project Mana...
CVE-2020-13534HIGH7.8A privilege escalation vulnerability exists in Dream Report 5 R20-2. COM Class Identifiers (CLSID), installed by Dream R...
CVE-2020-13533HIGH7.8A privilege escalation vulnerability exists in Dream Report 5 R20-2. IIn the default configuration, the following regist...
CVE-2020-13532HIGH7.8A privilege escalation vulnerability exists in Dream Report 5 R20-2. In the default configuration, the Syncfusion Dashbo...
CVE-2020-21884HIGH8.8Unibox SMB 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a cross-site request forgery (CSRF)...
CVE-2020-21883HIGH8.8Unibox U-50 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a OS command injection vulnerabili...
CVE-2020-36287MEDIUM5.3The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center befor...
CVE-2020-6590HIGH7.5Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information dis...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now