2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-36011MEDIUM4.8A cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote att...
CVE-2020-35854MEDIUM4.8Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.
CVE-2020-35853MEDIUM4.84images Image Gallery Management System 1.7.11 is affected by cross-site scripting (XSS) in the Image URL. This vulnerab...
CVE-2020-35845HIGH7.8FastStone Image Viewer 7.5 has an out-of-bounds write (via a crafted image file) at FSViewer.exe+0x96cf.
CVE-2020-35844HIGH7.8FastStone Image Viewer 7.5 has an out-of-bounds write (via a crafted image file) at FSViewer.exe+0xbe9c4.
CVE-2020-35843MEDIUM5.5FastStone Image Viewer 7.5 has an out-of-bounds write (via a crafted image file) at FSViewer.exe+0x956e.
CVE-2020-35753MEDIUM6.1The job posting recommendation form in Persis Human Resource Management Portal (Versions 17.2.00 through 17.2.35 and 19....
CVE-2020-35576HIGH8.8A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216...
CVE-2020-35513MEDIUM4.9A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality...
CVE-2020-35310Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none NOTE: This is disputed by the vendor; "We have no re...
CVE-2020-35309MEDIUM4.8Bakeshop Online Ordering System in PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attacker...
CVE-2020-35270CRITICAL9.1Student Result Management System In PHP With Source Code is affected by SQL injection. An attacker can able to access of...
CVE-2020-35263CRITICAL9.8EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbi...
CVE-2020-35239HIGH8.8A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method ove...
CVE-2020-29443LOW3.9ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not v...
CVE-2020-29241MEDIUM4.8Online News Portal using PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attackers to injec...
CVE-2020-29001HIGH7.2An issue was discovered on Geeni GNC-CW028 Camera 2.7.2, Geeni GNC-CW025 Doorbell 2.9.5, Merkury MI-CW024 Doorbell 2.9.6...
CVE-2020-29000HIGH7.2An issue was discovered on Geeni GNC-CW013 doorbell 1.8.1 devices. A vulnerability exists in the RTSP service that allow...
CVE-2020-28999HIGH7.2An issue was discovered in Apexis Streaming Video Web Application on Geeni GNC-CW013 doorbell 1.8.1 devices. A remote at...
CVE-2020-28998CRITICAL9.8An issue was discovered on Geeni GNC-CW013 doorbell 1.8.1 devices. A vulnerability exists in the Telnet service that all...
CVE-2020-28874HIGH7.5reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business...
CVE-2020-28326Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2020-28325Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2020-28324Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2020-28323Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now