2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-6111HIGH7.5An exploitable denial-of-service vulnerability exists in the IPv4 functionality of Allen-Bradley MicroLogix 1100 Program...
CVE-2020-5680HIGH7.5Improper input validation vulnerability in EC-CUBE versions from 3.0.5 to 3.0.18 allows a remote attacker to cause a den...
CVE-2020-5679MEDIUM6.1Improper restriction of rendered UI layers or frames in EC-CUBE versions from 3.0.0 to 3.0.18 leads to clickjacking atta...
CVE-2020-5678MEDIUM6.1Stored cross-site scripting vulnerability in GROWI v3.8.1 and earlier allows remote attackers to inject arbitrary script...
CVE-2020-5677MEDIUM6.1Reflected cross-site scripting vulnerability in GROWI v4.0.0 and earlier allows remote attackers to inject arbitrary scr...
CVE-2020-5676HIGH7.5GROWI v4.1.3 and earlier allow remote attackers to obtain information which is not allowed to access via unspecified vec...
CVE-2020-5638MEDIUM6.1Cross-site scripting vulnerability in desknet's NEO (desknet's NEO Small License V5.5 R1.5 and earlier, and desknet's NE...
CVE-2020-26246MEDIUM6.5Pimcore is an open source digital experience platform. In Pimcore before version 6.8.5 it is possible to modify & create...
CVE-2020-29288CRITICAL9.8An SQL injection vulnerability was discovered in Gym Management System In manage_user.php file, GET parameter 'id' is vu...
CVE-2020-29287CRITICAL9.8An SQL injection vulnerability was discovered in Car Rental Management System v1.0 can be exploited via the id parameter...
CVE-2020-29285CRITICAL9.8SQL injection vulnerability was discovered in Point of Sales in PHP/PDO 1.0, which can be exploited via the id parameter...
CVE-2020-29284CRITICAL9.8The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the t...
CVE-2020-29283CRITICAL9.8An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parame...
CVE-2020-29282CRITICAL9.8SQL injection vulnerability in BloodX 1.0 allows attackers to bypass authentication.
CVE-2020-29280CRITICAL9.8The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page.
CVE-2020-29279CRITICAL9.8PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 7...
CVE-2020-26244MEDIUM6.8Python oic is a Python OpenID Connect implementation. In Python oic before version 1.2.1, there are several related cryp...
CVE-2020-28206MEDIUM6.5An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An "User enumeration and Improper Restri...
CVE-2020-13498MEDIUM5.5An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially cra...
CVE-2020-13497MEDIUM5.5An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially cra...
CVE-2020-13496MEDIUM6.5An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially cra...
CVE-2020-13494MEDIUM5.5A heap overflow vulnerability exists in the Pixar OpenUSD 20.05 parsing of compressed string tokens in binary USD files....
CVE-2020-13493HIGH7.8A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD f...
CVE-2020-29389CRITICAL9.8The official Crux Linux Docker images 3.0 through 3.4 contain a blank password for a root user. System using the Crux Li...
CVE-2020-29240MEDIUM4.8Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of t...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now