2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6111 | HIGH | 7.5 | 4.6% | Dec 3, 2020 | An exploitable denial-of-service vulnerability exists in the IPv4 functionality of Allen-Bradley MicroLogix 1100 Program... |
| CVE-2020-5680 | HIGH | 7.5 | 1.4% | Dec 3, 2020 | Improper input validation vulnerability in EC-CUBE versions from 3.0.5 to 3.0.18 allows a remote attacker to cause a den... |
| CVE-2020-5679 | MEDIUM | 6.1 | 0.7% | Dec 3, 2020 | Improper restriction of rendered UI layers or frames in EC-CUBE versions from 3.0.0 to 3.0.18 leads to clickjacking atta... |
| CVE-2020-5678 | MEDIUM | 6.1 | 1.2% | Dec 3, 2020 | Stored cross-site scripting vulnerability in GROWI v3.8.1 and earlier allows remote attackers to inject arbitrary script... |
| CVE-2020-5677 | MEDIUM | 6.1 | 1.1% | Dec 3, 2020 | Reflected cross-site scripting vulnerability in GROWI v4.0.0 and earlier allows remote attackers to inject arbitrary scr... |
| CVE-2020-5676 | HIGH | 7.5 | 1.8% | Dec 3, 2020 | GROWI v4.1.3 and earlier allow remote attackers to obtain information which is not allowed to access via unspecified vec... |
| CVE-2020-5638 | MEDIUM | 6.1 | 0.8% | Dec 3, 2020 | Cross-site scripting vulnerability in desknet's NEO (desknet's NEO Small License V5.5 R1.5 and earlier, and desknet's NE... |
| CVE-2020-26246 | MEDIUM | 6.5 | 0.8% | Dec 3, 2020 | Pimcore is an open source digital experience platform. In Pimcore before version 6.8.5 it is possible to modify & create... |
| CVE-2020-29288 | CRITICAL | 9.8 | 2.6% | Dec 2, 2020 | An SQL injection vulnerability was discovered in Gym Management System In manage_user.php file, GET parameter 'id' is vu... |
| CVE-2020-29287 | CRITICAL | 9.8 | 2.7% | Dec 2, 2020 | An SQL injection vulnerability was discovered in Car Rental Management System v1.0 can be exploited via the id parameter... |
| CVE-2020-29285 | CRITICAL | 9.8 | 1.3% | Dec 2, 2020 | SQL injection vulnerability was discovered in Point of Sales in PHP/PDO 1.0, which can be exploited via the id parameter... |
| CVE-2020-29284 | CRITICAL | 9.8 | 6.1% | Dec 2, 2020 | The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the t... |
| CVE-2020-29283 | CRITICAL | 9.8 | 1.3% | Dec 2, 2020 | An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parame... |
| CVE-2020-29282 | CRITICAL | 9.8 | 2.7% | Dec 2, 2020 | SQL injection vulnerability in BloodX 1.0 allows attackers to bypass authentication. |
| CVE-2020-29280 | CRITICAL | 9.8 | 1.9% | Dec 2, 2020 | The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page. |
| CVE-2020-29279 | CRITICAL | 9.8 | 52.9% | Dec 2, 2020 | PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 7... |
| CVE-2020-26244 | MEDIUM | 6.8 | 0.8% | Dec 2, 2020 | Python oic is a Python OpenID Connect implementation. In Python oic before version 1.2.1, there are several related cryp... |
| CVE-2020-28206 | MEDIUM | 6.5 | 1.1% | Dec 2, 2020 | An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An "User enumeration and Improper Restri... |
| CVE-2020-13498 | MEDIUM | 5.5 | 0.9% | Dec 2, 2020 | An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially cra... |
| CVE-2020-13497 | MEDIUM | 5.5 | 1.2% | Dec 2, 2020 | An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially cra... |
| CVE-2020-13496 | MEDIUM | 6.5 | 1.7% | Dec 2, 2020 | An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially cra... |
| CVE-2020-13494 | MEDIUM | 5.5 | 1.2% | Dec 2, 2020 | A heap overflow vulnerability exists in the Pixar OpenUSD 20.05 parsing of compressed string tokens in binary USD files.... |
| CVE-2020-13493 | HIGH | 7.8 | 1.3% | Dec 2, 2020 | A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD f... |
| CVE-2020-29389 | CRITICAL | 9.8 | 1.7% | Dec 2, 2020 | The official Crux Linux Docker images 3.0 through 3.4 contain a blank password for a root user. System using the Crux Li... |
| CVE-2020-29240 | MEDIUM | 4.8 | 1.7% | Dec 2, 2020 | Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of t... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now