2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-2504 | HIGH | 7.5 | 1.0% | Dec 24, 2020 | If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP h... |
| CVE-2020-2503 | MEDIUM | 5.4 | 0.8% | Dec 24, 2020 | If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in Fi... |
| CVE-2020-2499 | HIGH | 7.2 | 1.4% | Dec 24, 2020 | A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerabilit... |
| CVE-2020-35668 | HIGH | 7.5 | 1.6% | Dec 23, 2020 | RedisGraph 2.x through 2.2.11 has a NULL Pointer Dereference that leads to a server crash because it mishandles an unquo... |
| CVE-2020-35666 | HIGH | 8.8 | 1.1% | Dec 23, 2020 | Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/pac... |
| CVE-2020-35665 | CRITICAL | 9.8 | 78.1% | Dec 23, 2020 | An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in ... |
| CVE-2020-35598 | HIGH | 7.5 | 21.0% | Dec 23, 2020 | ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=.... |
| CVE-2020-35370 | HIGH | 8.8 | 7.5% | Dec 23, 2020 | A RCE vulnerability exists in Raysync below 3.3.3.8. An unauthenticated unauthorized attacker sending a specifically cra... |
| CVE-2020-35269 | HIGH | 8.8 | 2.3% | Dec 23, 2020 | Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, li... |
| CVE-2020-35252 | MEDIUM | 6.1 | 1.0% | Dec 23, 2020 | Cross Site Scripting (XSS) vulnerability via the 'Full Name' parameter in the User Registration section of User Registra... |
| CVE-2020-28074 | CRITICAL | 9.8 | 2.3% | Dec 23, 2020 | SourceCodester Online Health Care System 1.0 is affected by SQL Injection which allows a potential attacker to bypass th... |
| CVE-2020-28073 | CRITICAL | 9.8 | 2.8% | Dec 23, 2020 | SourceCodester Library Management System 1.0 is affected by SQL Injection allowing an attacker to bypass the user authen... |
| CVE-2020-28071 | MEDIUM | 4.8 | 0.6% | Dec 23, 2020 | SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the a... |
| CVE-2020-28070 | CRITICAL | 9.8 | 22.9% | Dec 23, 2020 | SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GE... |
| CVE-2020-27397 | HIGH | 8.8 | 2.6% | Dec 23, 2020 | Marital - Online Matrimonial Project In PHP version 1.0 suffers from an authenticated file upload vulnerability allowing... |
| CVE-2020-13969 | MEDIUM | 6.1 | 0.7% | Dec 23, 2020 | CRK Business Platform <= 2019.1 allows reflected XSS via erro.aspx on 'CRK', 'IDContratante', 'Erro', or 'Mod' parameter... |
| CVE-2020-13968 | CRITICAL | 9.8 | 1.3% | Dec 23, 2020 | CRK Business Platform <= 2019.1 allows can inject SQL statements against the DB on any path using the 'strSessao' parame... |
| CVE-2020-4642 | MEDIUM | 5.5 | 0.4% | Dec 23, 2020 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow local atta... |
| CVE-2020-11719 | HIGH | 7.5 | 1.0% | Dec 23, 2020 | An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. It relies on broken encr... |
| CVE-2020-9439 | MEDIUM | 6.1 | 0.8% | Dec 23, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Owl Tin Canny LearnDash Reporting before 3.4.4 allows aut... |
| CVE-2020-6159 | MEDIUM | 6.1 | 0.6% | Dec 23, 2020 | URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scr... |
| CVE-2020-35650 | MEDIUM | 6.1 | 0.8% | Dec 23, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Groups for LearnDash before v3.7 allow authenticated remo... |
| CVE-2020-35587 | HIGH | 7.5 | 1.5% | Dec 23, 2020 | In Solstice Pod before 3.0.3, the firmware can easily be decompiled/disassembled. The decompiled/disassembled files cont... |
| CVE-2020-29552 | CRITICAL | 9.8 | 4.8% | Dec 23, 2020 | An issue was discovered in URVE Build 24.03.2020. By using the _internal/pc/vpro.php?mac=0&ip=0&operation=0&usr=0&pass=0... |
| CVE-2020-29551 | CRITICAL | 9.1 | 2.8% | Dec 23, 2020 | An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is possible to shutdown t... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now