2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-23362HIGH7.1Insecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges...
CVE-2020-18280MEDIUM6.1Cross Site Scripting vulnerability found in Phodal CMD v.1.0 allows a local attacker to execute arbitrary code via the E...
CVE-2020-36065HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in FlyCms 1.0 allows attackers to add arbitrary administrator accounts v...
CVE-2020-23966CRITICAL9.8SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /...
CVE-2020-22755HIGH8.8File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vu...
CVE-2020-22334MEDIUM6.5Cross Site Request Forgery (CSRF) vulnerability in beescms v4 allows attackers to delete the administrator account via c...
CVE-2020-21038MEDIUM6.1Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php.
CVE-2020-19660MEDIUM6.1Cross Site Scripting (XSS) pandao editor.md 1.5.0 allows attackers to execute arbitrary code via crafted linked url valu...
CVE-2020-18282MEDIUM6.1Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML...
CVE-2020-18132MEDIUM4.8Cross Site Scripting (XSS) vulnerability in MIPCMS 3.6.0 allows attackers to execute arbitrary code via the category nam...
CVE-2020-18131HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in Bluethrust Clan Scripts v4 allows attackers to escilate privledges to...
CVE-2020-4914MEDIUM4.2IBM Cloud Pak System Suite 2.3.3.0 through 2.3.3.5 does not invalidate session after logout which could allow a local us...
CVE-2020-22429HIGH7.8redox-os v0.1.0 was discovered to contain a use-after-free bug via the gethostbyaddr() function at /src/header/netdb/mod...
CVE-2020-23647MEDIUM6.1Cross Site Scripting (XSS) vulnerability in BoxBilling 4.19, 4.19.1, 4.20, and 4.21 allows remote attackers to run arbit...
CVE-2020-21643MEDIUM6.1Cross Site Scripting (XSS) vulnerability in HongCMS 3.0 allows attackers to run arbitrary code via the callback paramete...
CVE-2020-4729MEDIUM5.3IBM Counter Fraud Management for Safer Payments 5.7.0.00 through 5.7.0.10, 6.0.0.00 through 6.0.0.07, 6.1.0.00 through 6...
CVE-2020-36070CRITICAL9.8Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code v...
CVE-2020-28163MEDIUM6.5libdwarf before 20201201 allows a dwarf_print_lines.c NULL pointer dereference and application crash via a DWARF5 line-t...
CVE-2020-27545MEDIUM6.5libdwarf before 20201017 has a one-byte out-of-bounds read because of an invalid pointer dereference via an invalid line...
CVE-2020-29007CRITICAL9.8The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of ...
CVE-2020-17354HIGH8.6LilyPond before 2.24 allows attackers to bypass the -dsafe protection mechanism via output-def-lookup or output-def-scop...
CVE-2020-9009LOW3.7The ShipStation.com plugin 1.1 and earlier for CS-Cart allows remote attackers to insert arbitrary information into the ...
CVE-2020-24736MEDIUM5.5Buffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allows a local attacker to cause a denial of service ...
CVE-2020-19803HIGH8.8Cross Site Request Forgery vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary cod...
CVE-2020-19802CRITICAL9.8File Upload vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the uploa...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now