2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-19049MEDIUM5.4Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Descr...
CVE-2020-19048MEDIUM5.4Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Title...
CVE-2020-19046MEDIUM5.4Cross Site Scripting (XSS) in S-CMS v1.0 allows remote attackers to execute arbitrary code via the component '/admin/tpl...
CVE-2020-13639MEDIUM6.1A stored XSS vulnerability was discovered in the ECT Provider in OutSystems before 2020-09-04, affecting generated appli...
CVE-2020-18127MEDIUM6.5An issue in the /config/config.php component of Indexhibit 2.1.5 allows attackers to arbitrarily view files.
CVE-2020-18126MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in the Sections module of Indexhibit 2.1.5 allows attackers t...
CVE-2020-18125MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the /plugin/ajax.php component of Indexhibit 2.1.5 allows attack...
CVE-2020-18124MEDIUM5.7A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily reset account pass...
CVE-2020-18123MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily delete admin accou...
CVE-2020-19002MEDIUM6.1Cross Site Scripting (XSS) in Mezzanine v4.3.1 allows remote attackers to execute arbitrary code via the 'Description' f...
CVE-2020-19000MEDIUM6.1Cross Site Scripting (XSS) in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary code via line 54 of...
CVE-2020-18999MEDIUM6.1Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin...
CVE-2020-18998MEDIUM6.1Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin...
CVE-2020-23226MEDIUM6.1Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1.2.12 in (1) reports_admin.php, (2) data_queries.ph...
CVE-2020-18475MEDIUM5.4Cross Site Scripting (XSS) vulnerabilty exists in Hucart CMS 5.7.4 is via the mes_title field. The first user inserts a ...
CVE-2020-18470MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in the Name of application field found in the General Configuration page...
CVE-2020-18469MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in the Copyright Text field found in the Application page under the Conf...
CVE-2020-18468MEDIUM5.4Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the ...
CVE-2020-18467MEDIUM5.4Cross Site Scripting (XSS) vulnerabilty exists in BigTree-CMS 4.4.3 in the tag name field found in the Tags page under t...
CVE-2020-14161MEDIUM6.1It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /conver...
CVE-2020-19709MEDIUM6.1Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a c...
CVE-2020-19704MEDIUM5.4A stored cross-site scripting (XSS) vulnerability via ResourceController.java in spring-boot-admin as of 20190710 allows...
CVE-2020-19703MEDIUM6.1A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitr...
CVE-2020-19547MEDIUM6.5Directory Traversal vulnerability exists in PopojiCMS 2.0.1 via the id parameter in admin.php.
CVE-2020-18065MEDIUM5.4Cross Site Scripting (XSS) vulnerability exists in PopojiCMS 2.0.1 in admin.php?mod=menumanager--------- edit menu.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now