2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-22210 | CRITICAL | 9.8 | 8.6% | Jun 16, 2021 | SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php. |
| CVE-2020-22209 | CRITICAL | 9.8 | 8.6% | Jun 16, 2021 | SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php. |
| CVE-2020-22208 | CRITICAL | 9.8 | 9.7% | Jun 16, 2021 | SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php. |
| CVE-2020-22206 | CRITICAL | 9.8 | 1.4% | Jun 16, 2021 | SQL Injection in ECShop 3.0 via the aid parameter to admin/affiliate_ck.php. |
| CVE-2020-22205 | CRITICAL | 9.8 | 1.4% | Jun 16, 2021 | SQL Injection in ECShop 3.0 via the id parameter to admin/shophelp.php. |
| CVE-2020-22204 | CRITICAL | 9.8 | 1.4% | Jun 16, 2021 | SQL Injection in ECShop 2.7.6 via the goods_number parameter to flow.php. . |
| CVE-2020-22203 | CRITICAL | 9.8 | 1.1% | Jun 16, 2021 | SQL Injection in phpCMS 2008 sp4 via the genre parameter to yp/job.php. |
| CVE-2020-22199 | CRITICAL | 9.8 | 1.2% | Jun 16, 2021 | SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php. |
| CVE-2020-35760 | CRITICAL | 9.8 | 1.9% | Jun 16, 2021 | bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php fi... |
| CVE-2020-22198 | CRITICAL | 9.8 | 1.7% | Jun 16, 2021 | SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php. |
| CVE-2020-9493 | CRITICAL | 9.8 | 4.6% | Jun 16, 2021 | A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution... |
| CVE-2020-7864 | CRITICAL | 9.8 | 1.0% | Jun 15, 2021 | Parameter manipulation can bypass authentication to cause file upload and execution. This will execute the remote code. ... |
| CVE-2020-29214 | CRITICAL | 9.8 | 4.5% | Jun 15, 2021 | SQL injection vulnerability in SourceCodester Alumni Management System 1.0 allows the user to inject SQL payload to bypa... |
| CVE-2020-5003 | CRITICAL | 9.1 | 1.8% | Jun 11, 2021 | IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing X... |
| CVE-2020-23323 | CRITICAL | 9.8 | 1.3% | Jun 10, 2021 | There is a heap-buffer-overflow at re-parser.c in re_parse_char_escape in JerryScript 2.2.0. |
| CVE-2020-23321 | CRITICAL | 9.8 | 1.3% | Jun 10, 2021 | There is a heap-buffer-overflow at lit-strings.c:431 in lit_read_code_unit_from_utf8 in JerryScript 2.2.0. |
| CVE-2020-23306 | CRITICAL | 9.8 | 1.3% | Jun 10, 2021 | There is a stack-overflow at ecma-regexp-object.c:535 in ecma_regexp_match in JerryScript 2.2.0. |
| CVE-2020-23303 | CRITICAL | 9.8 | 1.3% | Jun 10, 2021 | There is a heap-buffer-overflow at jmem-poolman.c:165 in jmem_pools_collect_empty in JerryScript 2.2.0. |
| CVE-2020-23302 | CRITICAL | 9.8 | 1.3% | Jun 10, 2021 | There is a heap-use-after-free at ecma-helpers-string.c:772 in ecma_ref_ecma_string in JerryScript 2.2.0 |
| CVE-2020-15377 | CRITICAL | 9.8 | 1.2% | Jun 9, 2021 | Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to ... |
| CVE-2020-11291 | CRITICAL | 9.8 | 0.9% | Jun 9, 2021 | Possible buffer overflow while updating ikev2 parameters for delete payloads received during informational exchange due ... |
| CVE-2020-11176 | CRITICAL | 9.8 | 0.7% | Jun 9, 2021 | While processing server certificate from IPSec server, certificate validation for subject alternative name API can cause... |
| CVE-2020-11182 | CRITICAL | 9.8 | 0.8% | Jun 9, 2021 | Possible heap overflow while parsing NAL header due to lack of check of length of data received from user in Snapdragon ... |
| CVE-2020-11159 | CRITICAL | 9.1 | 0.8% | Jun 9, 2021 | Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length o... |
| CVE-2020-11134 | CRITICAL | 9.8 | 0.8% | Jun 9, 2021 | Possible stack out of bound write might happen due to time bitmap length and bit duration fields of the attributes like ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now