2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-37007 | MEDIUM | 4.3 | 0.2% | Jan 29, 2026 | Liman 0.7 contains a cross-site request forgery vulnerability that allows attackers to manipulate user account settings ... |
| CVE-2020-36994 | MEDIUM | 6.2 | 0.2% | Jan 29, 2026 | QlikView 12.50.20000.0 contains a denial of service vulnerability in the FTP server address input field that allows loca... |
| CVE-2020-36993 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | LimeSurvey 4.3.10 contains a stored cross-site scripting vulnerability in the Survey Menu functionality of the administr... |
| CVE-2020-36988 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | PDW File Browser version 1.3 contains stored and reflected cross-site scripting vulnerabilities that allow authenticated... |
| CVE-2020-36978 | MEDIUM | 6.4 | 0.3% | Jan 27, 2026 | Froxlor Server Management Panel 0.10.16 contains a persistent cross-site scripting vulnerability in customer registratio... |
| CVE-2020-36947 | MEDIUM | 6.5 | 0.4% | Jan 27, 2026 | LibreNMS 1.46 contains an authenticated SQL injection vulnerability in the MAC accounting graph endpoint that allows rem... |
| CVE-2020-36960 | MEDIUM | 6.4 | 0.2% | Jan 26, 2026 | Forma LMS 2.3 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts int... |
| CVE-2020-36956 | MEDIUM | 6.4 | 0.3% | Jan 26, 2026 | Openfire 4.6.0 contains a stored cross-site scripting vulnerability in the nodejs plugin that allows attackers to inject... |
| CVE-2020-36955 | MEDIUM | 6.4 | 0.6% | Jan 26, 2026 | Grav CMS 1.6.30 with Admin Plugin 1.9.18 contains a persistent cross-site scripting vulnerability that allows authentica... |
| CVE-2020-36954 | MEDIUM | 6.4 | 0.3% | Jan 26, 2026 | Xeroneit Library Management System 3.1 contains a stored cross-site scripting vulnerability in the Book Category feature... |
| CVE-2020-36932 | MEDIUM | 6.1 | 0.2% | Jan 25, 2026 | SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. ... |
| CVE-2020-36931 | MEDIUM | 6.4 | 0.3% | Jan 25, 2026 | Click2Magic 1.1.5 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts... |
| CVE-2020-36926 | MEDIUM | 5.3 | 0.4% | Jan 16, 2026 | SmarterTrack 7922 contains an information disclosure vulnerability in the Chat Management search form that reveals agent... |
| CVE-2020-36919 | MEDIUM | 6.1 | 0.3% | Jan 13, 2026 | WPForms 1.7.8 contains a cross-site scripting vulnerability in the slider import search feature and tab parameter. Attac... |
| CVE-2020-36924 | MEDIUM | 6.1 | 0.5% | Jan 6, 2026 | Sony BRAVIA Digital Signage 1.7.8 contains a remote file inclusion vulnerability that allows attackers to inject arbitra... |
| CVE-2020-36918 | MEDIUM | 5.1 | 0.1% | Jan 6, 2026 | iDS6 DSSPro Digital Signage System 6.2 contains a cross-site request forgery vulnerability that allows attackers to perf... |
| CVE-2020-36906 | MEDIUM | 5.3 | 0.1% | Jan 6, 2026 | P5 FNIP-8x16A FNIP-4xSH 1.0.20 contains a cross-site request forgery vulnerability that allows attackers to perform admi... |
| CVE-2020-36891 | MEDIUM | 5.4 | 0.2% | Dec 18, 2025 | A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to upload files with spoofed Content-T... |
| CVE-2020-36889 | MEDIUM | 5.4 | 0.2% | Dec 18, 2025 | A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via error ... |
| CVE-2020-36888 | MEDIUM | 5.3 | 0.3% | Dec 10, 2025 | SpinetiX Fusion Digital Signage 3.4.8 contains a username enumeration vulnerability in its login script that allows atta... |
| CVE-2020-36884 | MEDIUM | 6.9 | 0.8% | Dec 10, 2025 | BrightSign Digital Signage Diagnostic Web Server 8.2.26 and less contains an unauthenticated server-side request forgery... |
| CVE-2020-36866 | MEDIUM | 5.4 | 0.4% | Oct 30, 2025 | Nagios XI versions prior to 5.7.3 are vulnerable to cross-site scripting (XSS) via the Manage Users page of the Admin in... |
| CVE-2020-36865 | MEDIUM | 5.4 | 0.4% | Oct 30, 2025 | Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the BPI (Business Process Intelligenc... |
| CVE-2020-36864 | MEDIUM | 5.4 | 0.4% | Oct 30, 2025 | Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the background color settings in Dash... |
| CVE-2020-36862 | MEDIUM | 6.1 | 0.6% | Oct 30, 2025 | Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local exporting tool. Craft... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now