2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-36077HIGH8.8SQL injection vulnerability found in Tailor Mangement System v.1 allows a remote attacker to execute arbitrary code via ...
CVE-2020-11935MEDIUM5.5It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacke...
CVE-2020-19678HIGH7.5Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote atta...
CVE-2020-36074HIGH8.8SQL injection vulnerability found in Tailor Mangement System v.1 allows a remote attacker to execute arbitrary code via ...
CVE-2020-36073HIGH8.8SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via...
CVE-2020-36072HIGH8.8SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via...
CVE-2020-36071HIGH8.8SQL injection vulnerability found in Tailor Management System v.1 allows a remote authenticated attacker to execute arbi...
CVE-2020-29312CRITICAL9.8An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserializ...
CVE-2020-23327MEDIUM6.1Cross Site Scripting vulnerability found in ZblogCN ZblogPHP v.1.0 allows a local attacker to execute arbitrary code via...
CVE-2020-23260HIGH7.5An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the StringReplaceCmd fun...
CVE-2020-23259HIGH7.5An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the Jsi_Strlen function ...
CVE-2020-23258HIGH7.5An issue found in Jsish v.3.0.11 allows a remote attacker to cause a denial of service via the Jsi_ValueIsNumber functio...
CVE-2020-23257HIGH7.5Buffer Overflow vulnerability found in Espruino 2v05.41 allows an attacker to cause a denial of service via the function...
CVE-2020-22533MEDIUM6.1Cross Site Scripting vulnerability found in Zentao allows a remote attacker to execute arbitrary code via the lang param...
CVE-2020-21514HIGH8.8An issue was discovered in Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code du...
CVE-2020-21487CRITICAL9.6Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute a...
CVE-2020-21060HIGH8.8SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function...
CVE-2020-20915CRITICAL9.8SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql paramete...
CVE-2020-20914CRITICAL9.8SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the...
CVE-2020-20913CRITICAL9.8SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic...
CVE-2020-20522MEDIUM6.1Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the reg...
CVE-2020-20521MEDIUM6.1Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the com...
CVE-2020-19850MEDIUM6.5An issue found in Directus API v.2.2.0 allows a remote attacker to cause a denial of service via a great amount of HTTP ...
CVE-2020-19699MEDIUM6.1Cross Site Scripting vulnerability found in KOHGYLW Kiftd v.1.0.18 allows a remote attacker to execute arbitrary code vi...
CVE-2020-19698MEDIUM6.1Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now