2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-19959 | HIGH | 7.5 | 1.5% | Oct 14, 2021 | A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive da... |
| CVE-2020-19957 | HIGH | 7.5 | 1.5% | Oct 14, 2021 | A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive da... |
| CVE-2020-19954 | HIGH | 7.5 | 1.2% | Oct 14, 2021 | An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read... |
| CVE-2020-28145 | HIGH | 7.5 | 1.2% | Oct 12, 2021 | Arbitrary file deletion vulnerability was discovered in wuzhicms v 4.0.1 via coreframe\app\attachment\admin\index.php, w... |
| CVE-2020-21654 | HIGH | 7.2 | 1.1% | Oct 6, 2021 | emlog v6.0 contains a vulnerability in the component admin\template.php, which allows attackers to getshell via a crafte... |
| CVE-2020-21650 | HIGH | 8.8 | 3.1% | Oct 6, 2021 | Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be... |
| CVE-2020-21649 | HIGH | 8.1 | 0.8% | Oct 6, 2021 | Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploit... |
| CVE-2020-21503 | HIGH | 7.5 | 1.0% | Oct 5, 2021 | waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing da... |
| CVE-2020-21386 | HIGH | 8.8 | 0.4% | Oct 4, 2021 | A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gai... |
| CVE-2020-21013 | HIGH | 7.2 | 1.0% | Oct 1, 2021 | emlog v6.0.0 contains a SQL injection via /admin/comment.php. |
| CVE-2020-20746 | HIGH | 7.2 | 2.8% | Sep 30, 2021 | A stack-based buffer overflow in the httpd server on Tenda AC9 V15.03.06.60_EN allows remote attackers to execute arbitr... |
| CVE-2020-20665 | HIGH | 7.5 | 1.1% | Sep 30, 2021 | rudp v0.6 was discovered to contain a memory leak in the component main.c. |
| CVE-2020-20128 | HIGH | 7.5 | 0.8% | Sep 29, 2021 | LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers. |
| CVE-2020-20124 | HIGH | 8.8 | 2.8% | Sep 28, 2021 | Wuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php. |
| CVE-2020-20693 | HIGH | 8.8 | 0.7% | Sep 27, 2021 | A Cross-Site Request Forgery (CSRF) in GilaCMS v1.11.4 allows authenticated attackers to arbitrarily add administrator a... |
| CVE-2020-20692 | HIGH | 7.2 | 1.2% | Sep 27, 2021 | GilaCMS v1.11.4 was discovered to contain a SQL injection vulnerability via the $_GET parameter in /src/core/controllers... |
| CVE-2020-24930 | HIGH | 8.1 | 1.1% | Sep 27, 2021 | Beijing Wuzhi Internet Technology Co., Ltd. Wuzhi CMS 4.0.1 is an open source content management system. The five finger... |
| CVE-2020-20514 | HIGH | 8.1 | 0.4% | Sep 24, 2021 | A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attac... |
| CVE-2020-19951 | HIGH | 8.8 | 0.5% | Sep 23, 2021 | A cross-site request forgery (CSRF) in /controller/pay.class.php of YzmCMS v5.5 allows attackers to access sensitive com... |
| CVE-2020-23478 | HIGH | 7.5 | 1.2% | Sep 22, 2021 | Leo Editor v6.2.1 was discovered to contain a regular expression denial of service (ReDoS) vulnerability in the componen... |
| CVE-2020-23469 | HIGH | 7.5 | 1.2% | Sep 22, 2021 | gmate v0.12+bionic contains a regular expression denial of service (ReDoS) vulnerability in the gedit3 plugin. |
| CVE-2020-23267 | HIGH | 7.1 | 0.7% | Sep 22, 2021 | An issue was discovered in gpac 0.8.0. The gf_hinter_track_process function in isom_hinter_track_process.c has a heap-ba... |
| CVE-2020-19551 | HIGH | 8.8 | 1.7% | Sep 21, 2021 | Blacklist bypass issue exists in WUZHI CMS up to and including 4.1.0 in common.func.php, which when uploaded can cause r... |
| CVE-2020-21468 | HIGH | 7.5 | 1.2% | Sep 20, 2021 | A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS). NOTE: the vendor c... |
| CVE-2020-20898 | HIGH | 8.8 | 1.2% | Sep 20, 2021 | Integer Overflow vulnerability in function filter16_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows atta... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now