2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-20523MEDIUM6.1Cross Site Scripting (XSS) vulnerability in adm_user parameter in Gila CMS version 1.11.3, allows remote attackers to ex...
CVE-2020-19952MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Rendering Engine in jbt Markdown Editor thru commit 2252418c27dffbb35147acd8...
CVE-2020-23564HIGH7.2File Upload vulnerability in SEMCMS 3.9 allows remote attackers to run arbitrary code via SEMCMS_Upfile.php.
CVE-2020-26082MEDIUM5.3A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could...
CVE-2020-26065MEDIUM6.5A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, rem...
CVE-2020-26064HIGH8.1A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain rea...
CVE-2020-20808MEDIUM6.1Cross Site Scripting vulnerability in Qibosoft qibosoft v.7 and before allows a remote attacker to execute arbitrary cod...
CVE-2020-10962HIGH7.8In PowerShell App Deployment Toolkit (aka PSAppDeployToolkit) through 3.8.0, an incorrect access control vulnerability i...
CVE-2020-36763MEDIUM5.4Cross Site Scripting (XSS) vulnerability in DuxCMS 2.1 allows remote attackers to run arbitrary code via the content, ti...
CVE-2020-21881MEDIUM6.5Cross Site Request Forgery (CSRF) vulnerability in admin.php in DuxCMS 2.1 allows remote attackers to modtify applicatio...
CVE-2020-21662CRITICAL9.8SQL injection vulnerability in yunyecms 2.0.2 allows remote attackers to run arbitrary SQL commands via XFF.
CVE-2020-4868MEDIUM5.3IBM TRIRIGA 3.0, 4.0, and 4.4 could allow a remote attacker to obtain sensitive information when a detailed technical er...
CVE-2020-22623HIGH7.5Directory traversal vulnerability in Jinfornet Jreport 15.6 allows unauthenticated attackers to gain sensitive informati...
CVE-2020-35698MEDIUM6.1Thinkific Thinkific Online Course Creation Platform 1.0 is affected by: Cross Site Scripting (XSS). The impact is: execu...
CVE-2020-24275MEDIUM6.5A HTTP response header injection vulnerability in Swoole v4.5.2 allows attackers to execute arbitrary code via supplying...
CVE-2020-22159HIGH8.8EVERTZ devices 3080IPX exe-guest-v1.2-r26125, 7801FC 1.3 Build 27, and 7890IXG V494 are vulnerable to Arbitrary File Upl...
CVE-2020-36762CRITICAL9.8A vulnerability was found in ONS Digital RAS Collection Instrument up to 2.0.27 and classified as critical. Affected by ...
CVE-2020-23911MEDIUM5.5An issue was discovered in asn1c through v0.9.28. A NULL pointer dereference exists in the function _default_error_logge...
CVE-2020-23910MEDIUM5.5Stack-based buffer overflow vulnerability in asn1c through v0.9.28 via function genhash_get in genhash.c.
CVE-2020-23909HIGH7.1Heap-based buffer over-read in function png_convert_4 in file pngex.cc in AdvanceMAME through 2.1.
CVE-2020-36695HIGH7.8Incorrect Default Permissions vulnerability in Hitachi Device Manager on Linux (Device Manager Server component), Hitach...
CVE-2020-20021HIGH7.5An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfigurati...
CVE-2020-36761MEDIUM4.3The Top 10 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.4. Th...
CVE-2020-36760MEDIUM4.3The Ocean Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5...
CVE-2020-36757MEDIUM4.3The WP Hotel Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now