2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-23981 | MEDIUM | 6.1 | 0.8% | Aug 27, 2020 | 13enforme CMS 1.0 has Cross Site Scripting via the "content.php" id parameter. |
| CVE-2020-23979 | CRITICAL | 9.8 | 1.9% | Aug 27, 2020 | 13enforme CMS 1.0 has SQL Injection via the 'content.php' id parameter. |
| CVE-2020-23978 | CRITICAL | 9.8 | 2.1% | Aug 27, 2020 | SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php" |
| CVE-2020-23977 | MEDIUM | 6.1 | 0.8% | Aug 27, 2020 | KandNconcepts Club CMS 1.1 and 1.2 has cross site scripting via the 'team.php,player.php,club.php' id parameter. |
| CVE-2020-23976 | CRITICAL | 9.8 | 2.2% | Aug 27, 2020 | Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter. |
| CVE-2020-23975 | MEDIUM | 6.1 | 0.9% | Aug 27, 2020 | Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has cross site scripting via the 'search.php' id parameter. |
| CVE-2020-23974 | MEDIUM | 5.4 | 0.6% | Aug 27, 2020 | Create-Project Manager 1.07 has Multi Persistent Cross-site Scripting and HTML injection in via Online chat, Social feed... |
| CVE-2020-23973 | CRITICAL | 9.8 | 1.6% | Aug 27, 2020 | KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter. |
| CVE-2020-23972 | HIGH | 7.5 | 31.4% | Aug 27, 2020 | In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating ... |
| CVE-2020-4603 | HIGH | 7.2 | 0.8% | Aug 27, 2020 | IBM Security Guardium Insights 2.0.1 performs an operation at a privilege level that is higher than the minimum level re... |
| CVE-2020-4575 | MEDIUM | 6.1 | 0.9% | Aug 27, 2020 | IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cros... |
| CVE-2020-4175 | MEDIUM | 5.9 | 1.6% | Aug 27, 2020 | IBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information, caused by the failur... |
| CVE-2020-4174 | HIGH | 7.5 | 1.0% | Aug 27, 2020 | IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to ... |
| CVE-2020-4172 | MEDIUM | 5.3 | 1.2% | Aug 27, 2020 | IBM Security Guardium Insights 2.0.1 stores sensitive information in URL parameters. This may lead to information disclo... |
| CVE-2020-4171 | MEDIUM | 4.3 | 1.0% | Aug 27, 2020 | IBM Security Guardium Insights 2.0.1 allows web pages to be stored locally which can be read by another user on the syst... |
| CVE-2020-4169 | HIGH | 7.5 | 1.0% | Aug 27, 2020 | IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to ... |
| CVE-2020-4167 | MEDIUM | 6.5 | 1.0% | Aug 27, 2020 | IBM Security Guardium Insights 2.0.1 could allow an attacker to obtain sensitive information or perform unauthorized act... |
| CVE-2020-4166 | MEDIUM | 5.3 | 1.3% | Aug 27, 2020 | IBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information when a detailed techn... |
| CVE-2020-23980 | CRITICAL | 9.8 | 2.2% | Aug 27, 2020 | DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login pa... |
| CVE-2020-14729 | MEDIUM | 5.4 | 0.6% | Aug 27, 2020 | Vulnerability in SuiteCommerce Advanced (SCA) Sites component of Oracle NetSuite service. Supported versions that are af... |
| CVE-2020-14728 | MEDIUM | 5.4 | 0.7% | Aug 27, 2020 | Vulnerability in the SuiteCommerce Advanced (SCA) component of Oracle NetSuite service. Supported versions that are affe... |
| CVE-2020-24599 | MEDIUM | 6.1 | 1.2% | Aug 26, 2020 | An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks. |
| CVE-2020-24598 | MEDIUM | 6.1 | 1.2% | Aug 26, 2020 | An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to a... |
| CVE-2020-15485 | MEDIUM | 5.5 | 0.2% | Aug 26, 2020 | An issue was discovered on Nescomed Multipara Monitor M1000 devices. The onboard Flash memory stores data in cleartext, ... |
| CVE-2020-24548 | MEDIUM | 5.3 | 1.7% | Aug 26, 2020 | Ericom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests o... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now