2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-19959HIGH7.5A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive da...
CVE-2020-19957HIGH7.5A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive da...
CVE-2020-19954HIGH7.5An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read...
CVE-2020-28145HIGH7.5Arbitrary file deletion vulnerability was discovered in wuzhicms v 4.0.1 via coreframe\app\attachment\admin\index.php, w...
CVE-2020-21654HIGH7.2emlog v6.0 contains a vulnerability in the component admin\template.php, which allows attackers to getshell via a crafte...
CVE-2020-21650HIGH8.8Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be...
CVE-2020-21649HIGH8.1Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploit...
CVE-2020-21503HIGH7.5waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing da...
CVE-2020-21386HIGH8.8A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gai...
CVE-2020-21013HIGH7.2emlog v6.0.0 contains a SQL injection via /admin/comment.php.
CVE-2020-20746HIGH7.2A stack-based buffer overflow in the httpd server on Tenda AC9 V15.03.06.60_EN allows remote attackers to execute arbitr...
CVE-2020-20665HIGH7.5rudp v0.6 was discovered to contain a memory leak in the component main.c.
CVE-2020-20128HIGH7.5LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers.
CVE-2020-20124HIGH8.8Wuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php.
CVE-2020-20693HIGH8.8A Cross-Site Request Forgery (CSRF) in GilaCMS v1.11.4 allows authenticated attackers to arbitrarily add administrator a...
CVE-2020-20692HIGH7.2GilaCMS v1.11.4 was discovered to contain a SQL injection vulnerability via the $_GET parameter in /src/core/controllers...
CVE-2020-24930HIGH8.1Beijing Wuzhi Internet Technology Co., Ltd. Wuzhi CMS 4.0.1 is an open source content management system. The five finger...
CVE-2020-20514HIGH8.1A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attac...
CVE-2020-19951HIGH8.8A cross-site request forgery (CSRF) in /controller/pay.class.php of YzmCMS v5.5 allows attackers to access sensitive com...
CVE-2020-23478HIGH7.5Leo Editor v6.2.1 was discovered to contain a regular expression denial of service (ReDoS) vulnerability in the componen...
CVE-2020-23469HIGH7.5gmate v0.12+bionic contains a regular expression denial of service (ReDoS) vulnerability in the gedit3 plugin.
CVE-2020-23267HIGH7.1An issue was discovered in gpac 0.8.0. The gf_hinter_track_process function in isom_hinter_track_process.c has a heap-ba...
CVE-2020-19551HIGH8.8Blacklist bypass issue exists in WUZHI CMS up to and including 4.1.0 in common.func.php, which when uploaded can cause r...
CVE-2020-21468HIGH7.5A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS). NOTE: the vendor c...
CVE-2020-20898HIGH8.8Integer Overflow vulnerability in function filter16_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows atta...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now