2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-2504HIGH7.5If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP h...
CVE-2020-2503MEDIUM5.4If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in Fi...
CVE-2020-2499HIGH7.2A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerabilit...
CVE-2020-35668HIGH7.5RedisGraph 2.x through 2.2.11 has a NULL Pointer Dereference that leads to a server crash because it mishandles an unquo...
CVE-2020-35666HIGH8.8Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/pac...
CVE-2020-35665CRITICAL9.8An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in ...
CVE-2020-35598HIGH7.5ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=....
CVE-2020-35370HIGH8.8A RCE vulnerability exists in Raysync below 3.3.3.8. An unauthenticated unauthorized attacker sending a specifically cra...
CVE-2020-35269HIGH8.8Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, li...
CVE-2020-35252MEDIUM6.1Cross Site Scripting (XSS) vulnerability via the 'Full Name' parameter in the User Registration section of User Registra...
CVE-2020-28074CRITICAL9.8SourceCodester Online Health Care System 1.0 is affected by SQL Injection which allows a potential attacker to bypass th...
CVE-2020-28073CRITICAL9.8SourceCodester Library Management System 1.0 is affected by SQL Injection allowing an attacker to bypass the user authen...
CVE-2020-28071MEDIUM4.8SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the a...
CVE-2020-28070CRITICAL9.8SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GE...
CVE-2020-27397HIGH8.8Marital - Online Matrimonial Project In PHP version 1.0 suffers from an authenticated file upload vulnerability allowing...
CVE-2020-13969MEDIUM6.1CRK Business Platform <= 2019.1 allows reflected XSS via erro.aspx on 'CRK', 'IDContratante', 'Erro', or 'Mod' parameter...
CVE-2020-13968CRITICAL9.8CRK Business Platform <= 2019.1 allows can inject SQL statements against the DB on any path using the 'strSessao' parame...
CVE-2020-4642MEDIUM5.5IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow local atta...
CVE-2020-11719HIGH7.5An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. It relies on broken encr...
CVE-2020-9439MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Owl Tin Canny LearnDash Reporting before 3.4.4 allows aut...
CVE-2020-6159MEDIUM6.1URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scr...
CVE-2020-35650MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Groups for LearnDash before v3.7 allow authenticated remo...
CVE-2020-35587HIGH7.5In Solstice Pod before 3.0.3, the firmware can easily be decompiled/disassembled. The decompiled/disassembled files cont...
CVE-2020-29552CRITICAL9.8An issue was discovered in URVE Build 24.03.2020. By using the _internal/pc/vpro.php?mac=0&ip=0&operation=0&usr=0&pass=0...
CVE-2020-29551CRITICAL9.1An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is possible to shutdown t...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now