2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-24159HIGH7.8NetEase Youdao Dictionary has a DLL hijacking vulnerability, which can be exploited by attackers to gain server permissi...
CVE-2020-24158HIGH7.8360 Speed Browser 12.0.1247.0 has a DLL hijacking vulnerability, which can be exploited by attackers to execute maliciou...
CVE-2020-23814MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in xxl-job v2.2.0 allow remote attackers to inject arbitrary web scr...
CVE-2020-23811HIGH7.5xxl-job 2.2.0 allows Information Disclosure of username, model, and password via job/admin/controller/UserController.jav...
CVE-2020-25105CRITICAL9.8eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilit...
CVE-2020-25104MEDIUM5.4eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object. For exam...
CVE-2020-25068HIGH7.5Setelsa Conacwin v3.7.1.2 is vulnerable to a local file inclusion vulnerability. This vulnerability allows a remote unau...
CVE-2020-25042HIGH7.2An arbitrary file upload issue exists in Mara CMS 7.5. In order to exploit this, an attacker must have a valid authentic...
CVE-2020-24948HIGH7.2The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimat...
CVE-2020-24863MEDIUM5.5A memory corruption vulnerability was found in the kernel function kern_getfsstat in MidnightBSD before 1.2.7 and 1.3 th...
CVE-2020-24385MEDIUM5.5In MidnightBSD before 1.2.6 and 1.3 before August 2020, and FreeBSD before 7, a NULL pointer dereference was found in th...
CVE-2020-16149Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its request...
CVE-2020-13972MEDIUM6.1Enghouse Web Chat 6.2.284.34 allows XSS. When one enters their own domain name in the WebServiceLocation parameter, the ...
CVE-2020-7382MEDIUM6.5Rapid7 Nexpose installer version prior to 6.6.40 contains an Unquoted Search Path which may allow an attacker on the loc...
CVE-2020-7381HIGH7.8In Rapid7 Nexpose installer versions prior to 6.6.40, the Nexpose installer calls an executable which can be placed in t...
CVE-2020-4638HIGH7.2IBM API Connect's API Manager 2018.4.1.0 through 2018.4.1.12 is vulnerable to privilege escalation. An invitee to an API...
CVE-2020-4337MEDIUM6.5IBM API Connect 2018.4.1.0 through 2018.4.1.12 could allow an attacker to launch phishing attacks by tricking the server...
CVE-2020-24949HIGH8.8Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a cr...
CVE-2020-12058MEDIUM6.1Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary Ja...
CVE-2020-7729HIGH7.1The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load(...
CVE-2020-25093MEDIUM6.1Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop...
CVE-2020-25092MEDIUM6.1Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in _parts/header.php, within application/views/templates/cl...
CVE-2020-25091MEDIUM6.1Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/vendor/views/add_product.php.
CVE-2020-25090MEDIUM6.1Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/publish.php.
CVE-2020-25089MEDIUM6.1Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/discounts.php.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now