2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-37244HIGH8.8Supsystic Membership 1.4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbi...
CVE-2020-37243HIGH8.8Supsystic Pricing Table 1.8.7 contains an SQL injection vulnerability in the 'sidx' GET parameter that allows unauthenti...
CVE-2020-37242HIGH8.8Supsystic Ultimate Maps 1.1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute ...
CVE-2020-37241MEDIUM6.9bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative a...
CVE-2020-37240MEDIUM6.4Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrat...
CVE-2020-37239CRITICAL9.8libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety check...
CVE-2020-37238MEDIUM6.4CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content...
CVE-2020-37237MEDIUM6.4Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to...
CVE-2020-37236MEDIUM6.4NewsLister contains an authenticated persistent cross-site scripting vulnerability that allows authenticated administrat...
CVE-2020-37235MEDIUM6.4WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vulnerability in the Brand component that allows auth...
CVE-2020-37234MEDIUM6.9Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local ...
CVE-2020-37233MEDIUM6.4WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated att...
CVE-2020-37232HIGH8.5Advanced System Care Service 13.0.0.157 contains an unquoted service path vulnerability in the AdvancedSystemCareService...
CVE-2020-37231HIGH8.5Privacy Drive 3.17.0 contains an unquoted service path vulnerability in the pdsvc.exe service binary that allows local a...
CVE-2020-37230HIGH8.5Syncplify.me Server! 5.0.37 contains an unquoted service path vulnerability in the SMWebRestServicev5 service that allow...
CVE-2020-37229HIGH8.5OKI sPSV Port Manager 1.0.41 contains an unquoted service path vulnerability in the sPSVOpLclSrv service that allows loc...
CVE-2020-37228CRITICAL9.8iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass ...
CVE-2020-37227HIGH8.8HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerability that allows authenticated users to bypass cl...
CVE-2020-37226HIGH7.1Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipu...
CVE-2020-37225MEDIUM6.4Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scripting vulnerability that allows authenticated att...
CVE-2020-37224HIGH7.1Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipu...
CVE-2020-37223HIGH8.5IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local a...
CVE-2020-37222HIGH7.2Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inje...
CVE-2020-37221HIGH8.6Atomic Alarm Clock 6.3 contains a stack overflow vulnerability that allows local attackers to execute arbitrary code by ...
CVE-2020-37220HIGH8.7Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain a...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now