2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-22210CRITICAL9.8SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.
CVE-2020-22209CRITICAL9.8SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.
CVE-2020-22208CRITICAL9.8SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.
CVE-2020-22206CRITICAL9.8SQL Injection in ECShop 3.0 via the aid parameter to admin/affiliate_ck.php.
CVE-2020-22205CRITICAL9.8SQL Injection in ECShop 3.0 via the id parameter to admin/shophelp.php.
CVE-2020-22204CRITICAL9.8SQL Injection in ECShop 2.7.6 via the goods_number parameter to flow.php. .
CVE-2020-22203CRITICAL9.8SQL Injection in phpCMS 2008 sp4 via the genre parameter to yp/job.php.
CVE-2020-22199CRITICAL9.8SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php.
CVE-2020-35760CRITICAL9.8bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php fi...
CVE-2020-22198CRITICAL9.8SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.
CVE-2020-9493CRITICAL9.8A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution...
CVE-2020-7864CRITICAL9.8Parameter manipulation can bypass authentication to cause file upload and execution. This will execute the remote code. ...
CVE-2020-29214CRITICAL9.8SQL injection vulnerability in SourceCodester Alumni Management System 1.0 allows the user to inject SQL payload to bypa...
CVE-2020-5003CRITICAL9.1IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing X...
CVE-2020-23323CRITICAL9.8There is a heap-buffer-overflow at re-parser.c in re_parse_char_escape in JerryScript 2.2.0.
CVE-2020-23321CRITICAL9.8There is a heap-buffer-overflow at lit-strings.c:431 in lit_read_code_unit_from_utf8 in JerryScript 2.2.0.
CVE-2020-23306CRITICAL9.8There is a stack-overflow at ecma-regexp-object.c:535 in ecma_regexp_match in JerryScript 2.2.0.
CVE-2020-23303CRITICAL9.8There is a heap-buffer-overflow at jmem-poolman.c:165 in jmem_pools_collect_empty in JerryScript 2.2.0.
CVE-2020-23302CRITICAL9.8There is a heap-use-after-free at ecma-helpers-string.c:772 in ecma_ref_ecma_string in JerryScript 2.2.0
CVE-2020-15377CRITICAL9.8Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to ...
CVE-2020-11291CRITICAL9.8Possible buffer overflow while updating ikev2 parameters for delete payloads received during informational exchange due ...
CVE-2020-11176CRITICAL9.8While processing server certificate from IPSec server, certificate validation for subject alternative name API can cause...
CVE-2020-11182CRITICAL9.8Possible heap overflow while parsing NAL header due to lack of check of length of data received from user in Snapdragon ...
CVE-2020-11159CRITICAL9.1Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length o...
CVE-2020-11134CRITICAL9.8Possible stack out of bound write might happen due to time bitmap length and bit duration fields of the attributes like ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now