2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-36011 | MEDIUM | 4.8 | 0.7% | Jan 26, 2021 | A cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote att... |
| CVE-2020-35854 | MEDIUM | 4.8 | 0.7% | Jan 26, 2021 | Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter. |
| CVE-2020-35853 | MEDIUM | 4.8 | 0.6% | Jan 26, 2021 | 4images Image Gallery Management System 1.7.11 is affected by cross-site scripting (XSS) in the Image URL. This vulnerab... |
| CVE-2020-35845 | HIGH | 7.8 | 0.9% | Jan 26, 2021 | FastStone Image Viewer 7.5 has an out-of-bounds write (via a crafted image file) at FSViewer.exe+0x96cf. |
| CVE-2020-35844 | HIGH | 7.8 | 0.9% | Jan 26, 2021 | FastStone Image Viewer 7.5 has an out-of-bounds write (via a crafted image file) at FSViewer.exe+0xbe9c4. |
| CVE-2020-35843 | MEDIUM | 5.5 | 0.7% | Jan 26, 2021 | FastStone Image Viewer 7.5 has an out-of-bounds write (via a crafted image file) at FSViewer.exe+0x956e. |
| CVE-2020-35753 | MEDIUM | 6.1 | 0.9% | Jan 26, 2021 | The job posting recommendation form in Persis Human Resource Management Portal (Versions 17.2.00 through 17.2.35 and 19.... |
| CVE-2020-35576 | HIGH | 8.8 | 42.3% | Jan 26, 2021 | A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216... |
| CVE-2020-35513 | MEDIUM | 4.9 | 1.3% | Jan 26, 2021 | A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality... |
| CVE-2020-35310 | — | — | — | Jan 26, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none NOTE: This is disputed by the vendor; "We have no re... |
| CVE-2020-35309 | MEDIUM | 4.8 | 0.7% | Jan 26, 2021 | Bakeshop Online Ordering System in PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attacker... |
| CVE-2020-35270 | CRITICAL | 9.1 | 1.8% | Jan 26, 2021 | Student Result Management System In PHP With Source Code is affected by SQL injection. An attacker can able to access of... |
| CVE-2020-35263 | CRITICAL | 9.8 | 2.5% | Jan 26, 2021 | EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbi... |
| CVE-2020-35239 | HIGH | 8.8 | 0.6% | Jan 26, 2021 | A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method ove... |
| CVE-2020-29443 | LOW | 3.9 | 0.4% | Jan 26, 2021 | ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not v... |
| CVE-2020-29241 | MEDIUM | 4.8 | 0.6% | Jan 26, 2021 | Online News Portal using PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attackers to injec... |
| CVE-2020-29001 | HIGH | 7.2 | 1.3% | Jan 26, 2021 | An issue was discovered on Geeni GNC-CW028 Camera 2.7.2, Geeni GNC-CW025 Doorbell 2.9.5, Merkury MI-CW024 Doorbell 2.9.6... |
| CVE-2020-29000 | HIGH | 7.2 | 2.5% | Jan 26, 2021 | An issue was discovered on Geeni GNC-CW013 doorbell 1.8.1 devices. A vulnerability exists in the RTSP service that allow... |
| CVE-2020-28999 | HIGH | 7.2 | 1.7% | Jan 26, 2021 | An issue was discovered in Apexis Streaming Video Web Application on Geeni GNC-CW013 doorbell 1.8.1 devices. A remote at... |
| CVE-2020-28998 | CRITICAL | 9.8 | 2.8% | Jan 26, 2021 | An issue was discovered on Geeni GNC-CW013 doorbell 1.8.1 devices. A vulnerability exists in the Telnet service that all... |
| CVE-2020-28874 | HIGH | 7.5 | 2.4% | Jan 26, 2021 | reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business... |
| CVE-2020-28326 | — | — | — | Jan 26, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2020-28325 | — | — | — | Jan 26, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2020-28324 | — | — | — | Jan 26, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2020-28323 | — | — | — | Jan 26, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now