2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-23981MEDIUM6.113enforme CMS 1.0 has Cross Site Scripting via the "content.php" id parameter.
CVE-2020-23979CRITICAL9.813enforme CMS 1.0 has SQL Injection via the 'content.php' id parameter.
CVE-2020-23978CRITICAL9.8SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php"
CVE-2020-23977MEDIUM6.1KandNconcepts Club CMS 1.1 and 1.2 has cross site scripting via the 'team.php,player.php,club.php' id parameter.
CVE-2020-23976CRITICAL9.8Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter.
CVE-2020-23975MEDIUM6.1Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has cross site scripting via the 'search.php' id parameter.
CVE-2020-23974MEDIUM5.4Create-Project Manager 1.07 has Multi Persistent Cross-site Scripting and HTML injection in via Online chat, Social feed...
CVE-2020-23973CRITICAL9.8KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter.
CVE-2020-23972HIGH7.5In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating ...
CVE-2020-4603HIGH7.2IBM Security Guardium Insights 2.0.1 performs an operation at a privilege level that is higher than the minimum level re...
CVE-2020-4575MEDIUM6.1IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cros...
CVE-2020-4175MEDIUM5.9IBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information, caused by the failur...
CVE-2020-4174HIGH7.5IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to ...
CVE-2020-4172MEDIUM5.3IBM Security Guardium Insights 2.0.1 stores sensitive information in URL parameters. This may lead to information disclo...
CVE-2020-4171MEDIUM4.3IBM Security Guardium Insights 2.0.1 allows web pages to be stored locally which can be read by another user on the syst...
CVE-2020-4169HIGH7.5IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to ...
CVE-2020-4167MEDIUM6.5IBM Security Guardium Insights 2.0.1 could allow an attacker to obtain sensitive information or perform unauthorized act...
CVE-2020-4166MEDIUM5.3IBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information when a detailed techn...
CVE-2020-23980CRITICAL9.8DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login pa...
CVE-2020-14729MEDIUM5.4Vulnerability in SuiteCommerce Advanced (SCA) Sites component of Oracle NetSuite service. Supported versions that are af...
CVE-2020-14728MEDIUM5.4Vulnerability in the SuiteCommerce Advanced (SCA) component of Oracle NetSuite service. Supported versions that are affe...
CVE-2020-24599MEDIUM6.1An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks.
CVE-2020-24598MEDIUM6.1An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to a...
CVE-2020-15485MEDIUM5.5An issue was discovered on Nescomed Multipara Monitor M1000 devices. The onboard Flash memory stores data in cleartext, ...
CVE-2020-24548MEDIUM5.3Ericom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests o...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now