2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-23362 | HIGH | 7.1 | 0.7% | May 9, 2023 | Insecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges... |
| CVE-2020-18280 | MEDIUM | 6.1 | 0.4% | May 9, 2023 | Cross Site Scripting vulnerability found in Phodal CMD v.1.0 allows a local attacker to execute arbitrary code via the E... |
| CVE-2020-36065 | HIGH | 8.8 | 0.3% | May 8, 2023 | Cross Site Request Forgery (CSRF) vulnerability in FlyCms 1.0 allows attackers to add arbitrary administrator accounts v... |
| CVE-2020-23966 | CRITICAL | 9.8 | 0.8% | May 8, 2023 | SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /... |
| CVE-2020-22755 | HIGH | 8.8 | 0.9% | May 8, 2023 | File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vu... |
| CVE-2020-22334 | MEDIUM | 6.5 | 0.4% | May 8, 2023 | Cross Site Request Forgery (CSRF) vulnerability in beescms v4 allows attackers to delete the administrator account via c... |
| CVE-2020-21038 | MEDIUM | 6.1 | 0.5% | May 8, 2023 | Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php. |
| CVE-2020-19660 | MEDIUM | 6.1 | 0.4% | May 8, 2023 | Cross Site Scripting (XSS) pandao editor.md 1.5.0 allows attackers to execute arbitrary code via crafted linked url valu... |
| CVE-2020-18282 | MEDIUM | 6.1 | 0.5% | May 8, 2023 | Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML... |
| CVE-2020-18132 | MEDIUM | 4.8 | 0.4% | May 8, 2023 | Cross Site Scripting (XSS) vulnerability in MIPCMS 3.6.0 allows attackers to execute arbitrary code via the category nam... |
| CVE-2020-18131 | HIGH | 8.8 | 0.4% | May 8, 2023 | Cross Site Request Forgery (CSRF) vulnerability in Bluethrust Clan Scripts v4 allows attackers to escilate privledges to... |
| CVE-2020-4914 | MEDIUM | 4.2 | 0.1% | May 5, 2023 | IBM Cloud Pak System Suite 2.3.3.0 through 2.3.3.5 does not invalidate session after logout which could allow a local us... |
| CVE-2020-22429 | HIGH | 7.8 | 0.3% | May 3, 2023 | redox-os v0.1.0 was discovered to contain a use-after-free bug via the gethostbyaddr() function at /src/header/netdb/mod... |
| CVE-2020-23647 | MEDIUM | 6.1 | 0.5% | Apr 28, 2023 | Cross Site Scripting (XSS) vulnerability in BoxBilling 4.19, 4.19.1, 4.20, and 4.21 allows remote attackers to run arbit... |
| CVE-2020-21643 | MEDIUM | 6.1 | 0.4% | Apr 28, 2023 | Cross Site Scripting (XSS) vulnerability in HongCMS 3.0 allows attackers to run arbitrary code via the callback paramete... |
| CVE-2020-4729 | MEDIUM | 5.3 | 0.6% | Apr 28, 2023 | IBM Counter Fraud Management for Safer Payments 5.7.0.00 through 5.7.0.10, 6.0.0.00 through 6.0.0.07, 6.1.0.00 through 6... |
| CVE-2020-36070 | CRITICAL | 9.8 | 1.1% | Apr 26, 2023 | Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code v... |
| CVE-2020-28163 | MEDIUM | 6.5 | 0.8% | Apr 16, 2023 | libdwarf before 20201201 allows a dwarf_print_lines.c NULL pointer dereference and application crash via a DWARF5 line-t... |
| CVE-2020-27545 | MEDIUM | 6.5 | 0.8% | Apr 16, 2023 | libdwarf before 20201017 has a one-byte out-of-bounds read because of an invalid pointer dereference via an invalid line... |
| CVE-2020-29007 | CRITICAL | 9.8 | 2.3% | Apr 15, 2023 | The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of ... |
| CVE-2020-17354 | HIGH | 8.6 | 0.4% | Apr 15, 2023 | LilyPond before 2.24 allows attackers to bypass the -dsafe protection mechanism via output-def-lookup or output-def-scop... |
| CVE-2020-9009 | LOW | 3.7 | 0.6% | Apr 11, 2023 | The ShipStation.com plugin 1.1 and earlier for CS-Cart allows remote attackers to insert arbitrary information into the ... |
| CVE-2020-24736 | MEDIUM | 5.5 | 0.3% | Apr 11, 2023 | Buffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allows a local attacker to cause a denial of service ... |
| CVE-2020-19803 | HIGH | 8.8 | 0.4% | Apr 11, 2023 | Cross Site Request Forgery vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary cod... |
| CVE-2020-19802 | CRITICAL | 9.8 | 1.1% | Apr 11, 2023 | File Upload vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the uploa... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now