2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26137 | MEDIUM | 6.5 | 2.2% | Sep 30, 2020 | urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserti... |
| CVE-2020-26053 | — | — | — | Sep 30, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-26043 | MEDIUM | 6.1 | 0.7% | Sep 30, 2020 | An issue was discovered in Hoosk CMS v1.8.0. There is a XSS vulnerability in install/index.php |
| CVE-2020-26042 | CRITICAL | 9.8 | 1.2% | Sep 30, 2020 | An issue was discovered in Hoosk CMS v1.8.0. There is a SQL injection vulnerability in install/index.php |
| CVE-2020-26041 | CRITICAL | 9.8 | 2.8% | Sep 30, 2020 | An issue was discovered in Hoosk CmS v1.8.0. There is an Remote Code Execution vulnerability in install/index.php |
| CVE-2020-25763 | CRITICAL | 9.8 | 5.0% | Sep 30, 2020 | Seat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers ... |
| CVE-2020-25762 | CRITICAL | 9.1 | 11.3% | Sep 30, 2020 | An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input v... |
| CVE-2020-25761 | MEDIUM | 6.1 | 1.8% | Sep 30, 2020 | Projectworlds Visitor Management System in PHP 1.0 allows XSS. The file myform.php does not perform input validation on ... |
| CVE-2020-25760 | HIGH | 8.8 | 2.2% | Sep 30, 2020 | Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input valid... |
| CVE-2020-24721 | MEDIUM | 5.7 | 0.3% | Sep 30, 2020 | An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-09-29, as used in CO... |
| CVE-2020-24570 | MEDIUM | 6.5 | 0.5% | Sep 30, 2020 | An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resu... |
| CVE-2020-24569 | MEDIUM | 4.3 | 0.7% | Sep 30, 2020 | An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection i... |
| CVE-2020-22842 | MEDIUM | 5.4 | 0.5% | Sep 30, 2020 | CMS Made Simple before 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/mod... |
| CVE-2020-22481 | MEDIUM | 6.1 | 0.6% | Sep 30, 2020 | An issue was discovered in HFish 0.5.1. When a payload is inserted where the password is entered, XSS code is triggered ... |
| CVE-2020-21564 | HIGH | 8.8 | 3.5% | Sep 30, 2020 | An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remot... |
| CVE-2020-21527 | HIGH | 7.7 | 1.1% | Sep 30, 2020 | There is an Arbitrary file deletion vulnerability in halo v1.1.3. A backup function in the background allows a user, whe... |
| CVE-2020-21526 | CRITICAL | 9.8 | 1.9% | Sep 30, 2020 | An Arbitrary file writing vulnerability in halo v1.1.3. In an interface to write files in the background, a directory tr... |
| CVE-2020-21525 | HIGH | 7.5 | 1.9% | Sep 30, 2020 | Halo V1.1.3 is affected by: Arbitrary File reading. In an interface that reads files in halo v1.1.3, a directory travers... |
| CVE-2020-21524 | CRITICAL | 9.1 | 1.5% | Sep 30, 2020 | There is a XML external entity (XXE) vulnerability in halo v1.1.3, The function of importing other blogs in the backgrou... |
| CVE-2020-21523 | CRITICAL | 9.8 | 2.6% | Sep 30, 2020 | A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl fi... |
| CVE-2020-21522 | CRITICAL | 9.8 | 1.5% | Sep 30, 2020 | An issue was discovered in halo V1.1.3. A Zip Slip Directory Traversal Vulnerability in the backend,the attacker can ove... |
| CVE-2020-21244 | MEDIUM | 4.9 | 1.0% | Sep 30, 2020 | An issue was discovered in FrontAccounting 2.4.7. There is a Directory Traversal vulnerability that can empty folder via... |
| CVE-2020-20800 | CRITICAL | 9.8 | 1.5% | Sep 30, 2020 | An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the install/index.php?action=adminsetup&cndat... |
| CVE-2020-19676 | MEDIUM | 5.3 | 1.4% | Sep 30, 2020 | Nacos 1.1.4 is affected by: Incorrect Access Control. An environment can be set up locally to get the service details in... |
| CVE-2020-19672 | CRITICAL | 9.8 | 1.3% | Sep 30, 2020 | Niushop B2B2C Multi-business basic version V1.11, can bypass the administrator to obtain the background upload interface... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now