2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-18116HIGH8.8A lack of filtering for searched keywords in the search bar of YouDianCMS 8.0 allows attackers to perform SQL injection.
CVE-2020-18477HIGH8.8SQL Injection vulnerability in Hucart CMS 5.7.4 via the purchase enquiry field found in the Message con_content field.
CVE-2020-18476HIGH8.8SQL Injection vulnerability in Hucart CMS 5.7.4 via the basic information field found in the avatar usd_image field.
CVE-2020-14160HIGH7.5An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote a...
CVE-2020-19822HIGH7.2A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbit...
CVE-2020-19821HIGH8.8A SQL injection vulnerability in admin.php of DOYOCMS 2.3 allows attackers to execute arbitrary SQL commands via the ord...
CVE-2020-18917HIGH8.8The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename ...
CVE-2020-18913HIGH7.5EARCLINK ESPCMS-P8 was discovered to contain a SQL injection vulnerability in the espcms_web/Search.php component via th...
CVE-2020-18771HIGH8.1Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which ...
CVE-2020-18735HIGH7.5A heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server t...
CVE-2020-18734HIGH7.5A stack buffer overflow in /ddsi/q_bitset.h of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server t...
CVE-2020-18731HIGH7.5A segmentation violation in the Iec104_Deal_FirmUpdate function of IEC104 v1.0 allows attackers to cause a denial of ser...
CVE-2020-18730HIGH7.5A segmentation violation in the Iec104_Deal_I function of IEC104 v1.0 allows attackers to cause a denial of service (DOS...
CVE-2020-36478HIGH7.5An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parame...
CVE-2020-36476HIGH7.5An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroiz...
CVE-2020-36475HIGH7.5An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations perfor...
CVE-2020-24130HIGH8.1A cross site request forgery (CSRF) vulnerability in the configure.html component of Ponzu 0.11.0 allows attackers to ch...
CVE-2020-27466HIGH7.8An arbitrary file write vulnerability in lib/AjaxHandlers/ajaxEditTemplate.php of rConfig 3.9.6 allows attackers to exec...
CVE-2020-27464HIGH7.8An insecure update feature in the /updater.php component of rConfig 3.9.6 and below allows attackers to execute arbitrar...
CVE-2020-27461HIGH8.8A remote code execution vulnerability in SEOPanel 4.6.0 has been fixed for 4.7.0. This vulnerability allowed for remote ...
CVE-2020-18886HIGH7.2Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/up...
CVE-2020-18885HIGH7.2Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the ...
CVE-2020-18877HIGH7.5SQL Injection in Wuzhi CMS v4.1.0 allows remote attackers to obtain sensitive information via the 'flag' parameter in th...
CVE-2020-18897HIGH7.8An use-after-free vulnerability in the libpff_item_tree_create_node function of libyal Libpff before 20180623 allows att...
CVE-2020-20642HIGH8.8Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now