2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-26137MEDIUM6.5urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserti...
CVE-2020-26053Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-26043MEDIUM6.1An issue was discovered in Hoosk CMS v1.8.0. There is a XSS vulnerability in install/index.php
CVE-2020-26042CRITICAL9.8An issue was discovered in Hoosk CMS v1.8.0. There is a SQL injection vulnerability in install/index.php
CVE-2020-26041CRITICAL9.8An issue was discovered in Hoosk CmS v1.8.0. There is an Remote Code Execution vulnerability in install/index.php
CVE-2020-25763CRITICAL9.8Seat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers ...
CVE-2020-25762CRITICAL9.1An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input v...
CVE-2020-25761MEDIUM6.1Projectworlds Visitor Management System in PHP 1.0 allows XSS. The file myform.php does not perform input validation on ...
CVE-2020-25760HIGH8.8Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input valid...
CVE-2020-24721MEDIUM5.7An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-09-29, as used in CO...
CVE-2020-24570MEDIUM6.5An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resu...
CVE-2020-24569MEDIUM4.3An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection i...
CVE-2020-22842MEDIUM5.4CMS Made Simple before 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/mod...
CVE-2020-22481MEDIUM6.1An issue was discovered in HFish 0.5.1. When a payload is inserted where the password is entered, XSS code is triggered ...
CVE-2020-21564HIGH8.8An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remot...
CVE-2020-21527HIGH7.7There is an Arbitrary file deletion vulnerability in halo v1.1.3. A backup function in the background allows a user, whe...
CVE-2020-21526CRITICAL9.8An Arbitrary file writing vulnerability in halo v1.1.3. In an interface to write files in the background, a directory tr...
CVE-2020-21525HIGH7.5Halo V1.1.3 is affected by: Arbitrary File reading. In an interface that reads files in halo v1.1.3, a directory travers...
CVE-2020-21524CRITICAL9.1There is a XML external entity (XXE) vulnerability in halo v1.1.3, The function of importing other blogs in the backgrou...
CVE-2020-21523CRITICAL9.8A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl fi...
CVE-2020-21522CRITICAL9.8An issue was discovered in halo V1.1.3. A Zip Slip Directory Traversal Vulnerability in the backend,the attacker can ove...
CVE-2020-21244MEDIUM4.9An issue was discovered in FrontAccounting 2.4.7. There is a Directory Traversal vulnerability that can empty folder via...
CVE-2020-20800CRITICAL9.8An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the install/index.php?action=adminsetup&cndat...
CVE-2020-19676MEDIUM5.3Nacos 1.1.4 is affected by: Incorrect Access Control. An environment can be set up locally to get the service details in...
CVE-2020-19672CRITICAL9.8Niushop B2B2C Multi-business basic version V1.11, can bypass the administrator to obtain the background upload interface...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now