2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-35987MEDIUM5.4A stored cross site scripting (XSS) vulnerability in the 'Entities List' feature of Rukovoditel 2.7.2 allows authenticat...
CVE-2020-35986MEDIUM5.4A stored cross site scripting (XSS) vulnerability in the 'Users Access Groups' feature of Rukovoditel 2.7.2 allows authe...
CVE-2020-35985MEDIUM5.4A stored cross site scripting (XSS) vulnerability in the 'Global Lists" feature of Rukovoditel 2.7.2 allows authenticate...
CVE-2020-35984MEDIUM5.4A stored cross site scripting (XSS) vulnerability in the 'Users Alerts' feature of Rukovoditel 2.7.2 allows authenticate...
CVE-2020-25879MEDIUM5.4A stored cross site scripting (XSS) vulnerability in the 'Manage Users' feature of Codoforum v5.0.2 allows authenticated...
CVE-2020-25878MEDIUM4.8A stored cross site scripting (XSS) vulnerability in the 'Admin-Tools' feature of BlackCat CMS 1.3.6 allows authenticate...
CVE-2020-25877MEDIUM5.4A stored cross site scripting (XSS) vulnerability in the 'Add Page' feature of BlackCat CMS 1.3.6 allows authenticated a...
CVE-2020-25876MEDIUM5.4A stored cross site scripting (XSS) vulnerability in the 'Pages' feature of Codoforum v5.0.2 allows authenticated attack...
CVE-2020-25875MEDIUM5.4A stored cross site scripting (XSS) vulnerability in the 'Smileys' feature of Codoforum v5.0.2 allows authenticated atta...
CVE-2020-25394MEDIUM5.4A stored cross site scripting (XSS) vulnerability in moziloCMS 2.0 allows authenticated attackers to execute arbitrary w...
CVE-2020-25392MEDIUM5.4A cross site scripting (XSS) vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML vi...
CVE-2020-25391MEDIUM5.4A cross site scripting vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML via a cr...
CVE-2020-29014MEDIUM5.3A concurrent execution using shared resource with improper synchronization ('race condition') in the command shell of Fo...
CVE-2020-21333MEDIUM5.4Cross Site Scripting (XSS) vulnerability in PublicCMS 4.0 to get an admin cookie when the Administrator reviews submit c...
CVE-2020-22535MEDIUM6.5Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontrol...
CVE-2020-20363MEDIUM4.8Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php.
CVE-2020-18741MEDIUM5.3Improper Authorization in ThinkSAAS v2.7 allows remote attackers to modify the description of any user's photo via the "...
CVE-2020-20586MEDIUM4.5A cross site request forgery (CSRF) vulnerability in the /xyhai.php?s=/Auth/editUser URI of XYHCMS V3.6 allows attackers...
CVE-2020-20584MEDIUM6.1A cross site scripting vulnerability in baigo CMS v4.0-beta-1 allows attackers to execute arbitrary web scripts or HTML ...
CVE-2020-20217MEDIUM6.5Mikrotik RouterOs before 6.47 (stable tree) suffers from an uncontrolled resource consumption vulnerability in the /nova...
CVE-2020-23702MEDIUM4.8Cross Site Scripting (XSS) vulnerability in PHP-Fusion 9.03.60 via 'New Shout' in /infusions/shoutbox_panel/shoutbox_adm...
CVE-2020-23700MEDIUM4.8Cross Site Scripting (XSS) vulnerability in LavaLite-CMS 5.8.0 via the Menu Links feature.
CVE-2020-25925MEDIUM6.1Cross Site Scripting (XSS) in Webmail Calender in IceWarp WebClient 10.3.5 allows remote attackers to inject arbitrary w...
CVE-2020-24145MEDIUM6.1Cross Site Scripting (XSS) vulnerability in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress...
CVE-2020-24141MEDIUM5.3Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now