2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6136 | HIGH | 8.8 | 1.8% | Sep 1, 2020 | An exploitable SQL injection vulnerability exists in the DownloadWindow.php functionality of OS4Ed openSIS 7.3. A specia... |
| CVE-2020-24034 | HIGH | 8.8 | 3.7% | Sep 1, 2020 | Sagemcom F@ST 5280 routers using firmware version 1.150.61 have insecure deserialization that allows any authenticated u... |
| CVE-2020-17405 | HIGH | 8.8 | 2.0% | Sep 1, 2020 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Senstar Symp... |
| CVE-2020-6135 | HIGH | 8.8 | 1.8% | Sep 1, 2020 | An exploitable SQL injection vulnerability exists in the Validator.php functionality of OS4Ed openSIS 7.3. A specially c... |
| CVE-2020-23839 | MEDIUM | 6.1 | 10.5% | Sep 1, 2020 | A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpa... |
| CVE-2020-23836 | HIGH | 8.8 | 0.6% | Sep 1, 2020 | A Cross-Site Request Forgery (CSRF) vulnerability in edit_user.php in OSWAPP Warehouse Inventory System (aka OSWA-INV) t... |
| CVE-2020-23835 | MEDIUM | 6.1 | 2.3% | Sep 1, 2020 | A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Mana... |
| CVE-2020-23831 | MEDIUM | 6.1 | 0.8% | Sep 1, 2020 | A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Stock Manag... |
| CVE-2020-23829 | HIGH | 8.8 | 2.5% | Sep 1, 2020 | interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerabilit... |
| CVE-2020-15150 | CRITICAL | 9.8 | 3.3% | Sep 1, 2020 | There is a vulnerability in Paginator (Elixir/Hex package) which makes it susceptible to Remote Code Execution (RCE) att... |
| CVE-2020-23971 | HIGH | 7.5 | 1.5% | Sep 1, 2020 | gmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions. An attacker can access the upload funct... |
| CVE-2020-23450 | MEDIUM | 5.4 | 0.8% | Sep 1, 2020 | Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is vulnerable to stored XSS... |
| CVE-2020-6134 | HIGH | 8.8 | 1.4% | Sep 1, 2020 | SQL injection vulnerabilities exist in the ID parameters of OS4Ed openSIS 7.3 pages. The id parameter in the page MassDr... |
| CVE-2020-6133 | HIGH | 8.8 | 1.4% | Sep 1, 2020 | SQL injection vulnerabilities exist in the ID parameters of OS4Ed openSIS 7.3 pages. The id parameter in the page Course... |
| CVE-2020-6132 | HIGH | 8.8 | 1.4% | Sep 1, 2020 | SQL injection vulnerability exists in the ID parameters of OS4Ed openSIS 7.3 pages. The id parameter in the page ChooseC... |
| CVE-2020-6128 | HIGH | 8.8 | 1.8% | Sep 1, 2020 | SQL injection vulnerability exists in the CoursePeriodModal.php page of OS4Ed openSIS 7.3. A specially crafted HTTP requ... |
| CVE-2020-6127 | HIGH | 8.8 | 1.4% | Sep 1, 2020 | SQL injection vulnerability exists in the CoursePeriodModal.php page of OS4Ed openSIS 7.3. The id parameter in the page ... |
| CVE-2020-6126 | HIGH | 8.8 | 1.4% | Sep 1, 2020 | SQL injection vulnerability exists in the CoursePeriodModal.php page of OS4Ed openSIS 7.3. The course_period_id paramete... |
| CVE-2020-6125 | HIGH | 8.8 | 1.8% | Sep 1, 2020 | An exploitable SQL injection vulnerability exists in the GetSchool.php functionality of OS4Ed openSIS 7.3. A specially c... |
| CVE-2020-6124 | HIGH | 8.8 | 1.4% | Sep 1, 2020 | An exploitable sql injection vulnerability exists in the email parameter functionality of OS4Ed openSIS 7.3. The email p... |
| CVE-2020-7669 | HIGH | 7.5 | 1.8% | Sep 1, 2020 | This affects all versions of package github.com/u-root/u-root/pkg/tarutil. It is vulnerable to both leading and non-lead... |
| CVE-2020-7666 | HIGH | 7.5 | 1.5% | Sep 1, 2020 | This affects all versions of package github.com/u-root/u-root/pkg/cpio. It is vulnerable to leading, non-leading relativ... |
| CVE-2020-7665 | HIGH | 7.5 | 1.8% | Sep 1, 2020 | This affects all versions of package github.com/u-root/u-root/pkg/uzip. It is vulnerable to both leading and non-leading... |
| CVE-2020-6131 | HIGH | 8.8 | 1.4% | Sep 1, 2020 | SQL injection vulnerabilities exist in the course_period_id parameters used in OS4Ed openSIS 7.3 pages. The course_perio... |
| CVE-2020-6130 | HIGH | 8.8 | 1.4% | Sep 1, 2020 | SQL injection vulnerabilities exist in the course_period_id parameters used in OS4Ed openSIS 7.3 pages. The course_perio... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now