2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-37118MEDIUM5.1P5 FNIP-8x16A FNIP-4xSH 1.0.20 contains a cross-site request forgery vulnerability that allows attackers to perform admi...
CVE-2020-37087MEDIUM5.1Easy Transfer Wifi Transfer v1.7 for iOS contains a persistent cross-site scripting vulnerability that allows remote att...
CVE-2020-37096MEDIUM4.3Edimax EW-7438RPn 1.13 contains a cross-site request forgery vulnerability in the MAC filtering configuration interface....
CVE-2020-37091MEDIUM5.3Maian Support Helpdesk 4.3 contains a cross-site request forgery vulnerability that allows attackers to create administr...
CVE-2020-37086MEDIUM6.9Easy Transfer 1.7 iOS mobile application contains a directory traversal vulnerability that allows remote attackers to ac...
CVE-2020-37077MEDIUM6.9Booked Scheduler 2.7.7 contains a directory traversal vulnerability in the manage_email_templates.php script that allows...
CVE-2020-37072MEDIUM6.1Victor CMS 1.0 contains a stored cross-site scripting vulnerability in the 'comment_author' POST parameter that allows a...
CVE-2020-37115MEDIUM4.9GUnet OpenEclass 1.7.3 stores user credentials in plaintext, allowing administrators to view all registered users' usern...
CVE-2020-37114MEDIUM6.5GUnet OpenEclass 1.7.3 allows unauthenticated and authenticated users to access sensitive information, including system ...
CVE-2020-37112MEDIUM6.5GUnet OpenEclass 1.7.3 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate ...
CVE-2020-37111MEDIUM6.160CycleCMS 2.5.2 contains a cross-site scripting (XSS) vulnerability in news.php that allows attackers to inject malicio...
CVE-2020-37103MEDIUM5.4DotNetNuke 9.5 contains a persistent cross-site scripting vulnerability that allows normal users to upload malicious XML...
CVE-2020-37053MEDIUM6.5Navigate CMS 2.8.7 contains an authenticated SQL injection vulnerability that allows attackers to leak database informat...
CVE-2020-37051MEDIUM5.3Online-Exam-System 2015 contains a time-based blind SQL injection vulnerability in the feedback form that allows attacke...
CVE-2020-37046MEDIUM5.3Sistem Informasi Pengumuman Kelulusan Online 1.0 contains a cross-site request forgery vulnerability that allows attacke...
CVE-2020-37044MEDIUM6.1OpenCTI 3.3.1 is vulnerable to a reflected cross-site scripting (XSS) attack via the /graphql endpoint. An attacker can ...
CVE-2020-37026MEDIUM5.3Sickbeard alpha contains a cross-site request forgery vulnerability that allows attackers to disable authentication by s...
CVE-2020-37022MEDIUM6.4OpenZ ERP 3.6.60 contains a persistent cross-site scripting vulnerability in the Employee module's name and description ...
CVE-2020-37019MEDIUM6.4Orchard Core RC1 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicio...
CVE-2020-37014MEDIUM6.4Tryton 5.4 contains a persistent cross-site scripting vulnerability in the user profile name input that allows remote at...
CVE-2020-37003MEDIUM6.4Sellacious eCommerce 4.6 contains a persistent cross-site scripting vulnerability in the Manage Your Addresses module th...
CVE-2020-36998MEDIUM6.4Forma.lms The E-Learning Suite 2.3.0.2 contains a persistent cross-site scripting vulnerability in multiple course and p...
CVE-2020-36996MEDIUM6.4PHPFusion 9.03.50 contains a persistent cross-site scripting vulnerability in the print.php page that fails to properly ...
CVE-2020-36966MEDIUM6.4Dolibarr 11.0.3 contains a persistent cross-site scripting vulnerability in LDAP synchronization settings that allows at...
CVE-2020-37018MEDIUM6.4GOautodial 4.0 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malic...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now