2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-18980 | CRITICAL | 9.8 | 1.5% | Jul 12, 2021 | Remote Code Executon vulnerability in Halo 0.4.3 via the remoteAddr and themeName parameters. |
| CVE-2020-21133 | CRITICAL | 9.8 | 1.7% | Jul 12, 2021 | SQL Injection vulnerability in Metinfo 7.0.0 beta in member/getpassword.php?lang=cn&a=dovalid. |
| CVE-2020-21132 | CRITICAL | 9.8 | 1.7% | Jul 12, 2021 | SQL Injection vulnerability in Metinfo 7.0.0beta in index.php. |
| CVE-2020-23580 | CRITICAL | 9.8 | 2.5% | Jul 8, 2021 | Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board. |
| CVE-2020-24148 | CRITICAL | 9.1 | 14.7% | Jul 7, 2021 | Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the ... |
| CVE-2020-24147 | CRITICAL | 9.1 | 1.6% | Jul 7, 2021 | Server-side request forgery (SSR) vulnerability in the WP Smart Import (wp-smart-import) plugin 1.0.0 for WordPress via ... |
| CVE-2020-24142 | CRITICAL | 9.8 | 1.7% | Jul 7, 2021 | Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an ... |
| CVE-2020-22249 | CRITICAL | 9.8 | 2.9% | Jul 6, 2021 | Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the p... |
| CVE-2020-36400 | CRITICAL | 9.8 | 1.8% | Jul 1, 2021 | ZeroMQ libzmq 4.3.3 has a heap-based buffer overflow in zmq::tcp_read, a different vulnerability than CVE-2021-20235. |
| CVE-2020-7868 | CRITICAL | 9.8 | 2.7% | Jun 29, 2021 | A remote code execution vulnerability exists in helpUS(remote administration tool) due to improper validation of paramet... |
| CVE-2020-7871 | CRITICAL | 9.8 | 0.9% | Jun 29, 2021 | A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exis... |
| CVE-2020-23711 | CRITICAL | 9.8 | 1.5% | Jun 28, 2021 | SQL Injection vulnerability in NavigateCMS 2.9 via the URL encoded GET input category in navigate.php. |
| CVE-2020-17752 | CRITICAL | 9.8 | 1.6% | Jun 24, 2021 | Integer overflow vulnerability in payable function of a smart contract implementation for an Ethereum token, as demonstr... |
| CVE-2020-18667 | CRITICAL | 9.8 | 1.4% | Jun 24, 2021 | SQL Injection vulnerability in WebPort <=1.19.1 via the new connection, parameter name in type-conn. |
| CVE-2020-21786 | CRITICAL | 9.8 | 1.1% | Jun 24, 2021 | In IBOS 4.5.4 Open, Arbitrary File Inclusion causes getshell via /system/modules/dashboard/controllers/CronController.ph... |
| CVE-2020-21784 | CRITICAL | 9.8 | 1.4% | Jun 24, 2021 | phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php. |
| CVE-2020-18662 | CRITICAL | 9.8 | 5.4% | Jun 24, 2021 | SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php. |
| CVE-2020-21787 | CRITICAL | 9.8 | 1.8% | Jun 24, 2021 | CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php. |
| CVE-2020-20392 | CRITICAL | 9.8 | 1.4% | Jun 23, 2021 | SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php. |
| CVE-2020-19510 | CRITICAL | 9.8 | 1.5% | Jun 21, 2021 | Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php. |
| CVE-2020-20466 | CRITICAL | 9.8 | 1.8% | Jun 21, 2021 | White Shark System (WSS) 1.3.2 is vulnerable to unauthorized access via user_edit_password.php, remote attackers can mod... |
| CVE-2020-25414 | CRITICAL | 9.8 | 2.0% | Jun 17, 2021 | A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attacke... |
| CVE-2020-25753 | CRITICAL | 9.8 | 2.2% | Jun 16, 2021 | An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software. The default admin password is set to th... |
| CVE-2020-22212 | CRITICAL | 9.8 | 1.4% | Jun 16, 2021 | SQL Injection in 74cms 3.2.0 via the id parameter to wap/wap-company-show.php. |
| CVE-2020-22211 | CRITICAL | 9.8 | 7.9% | Jun 16, 2021 | SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now