2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-7831HIGH8.8A vulnerability in the web-based contract management service interface Ebiz4u of INOGARD could allow an victim user to d...
CVE-2020-19891HIGH7.2DBHcms v1.2.0 has an Arbitrary file write vulnerability in dbhcms\mod\mod.editor.php $_POST['updatefile'] is filename an...
CVE-2020-19890MEDIUM4.9DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as the...
CVE-2020-19889HIGH8.8DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user.
CVE-2020-19888MEDIUM5.9DBHcms v1.2.0 has an unauthorized operation vulnerability because there's no access control at line 175 of dbhcms\page.p...
CVE-2020-19887MEDIUM4.8DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_desc...
CVE-2020-19886HIGH8.1DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for an /index.php?dbhcms_pid=-80&deletemenu=9 can...
CVE-2020-19885MEDIUM4.8DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_name...
CVE-2020-19884MEDIUM4.8DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function in dbhcms\mod\mod.domain.edit.php ...
CVE-2020-19883MEDIUM4.8DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter in dbhcms\mod\mod.users.view.php line 57 for...
CVE-2020-19882MEDIUM4.8DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for 'menu_description' variable in...
CVE-2020-19881MEDIUM4.8DBHcms v1.2.0 has a reflected xss vulnerability as there is no security filter in dbhcms\mod\mod.selector.php line 108 f...
CVE-2020-19880MEDIUM6.1DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function form 'Name' in dbhcms\types.php, A...
CVE-2020-19879MEDIUM6.1DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter of $_GET['dbhcms_pid'] variable in dbhcms\pa...
CVE-2020-19878HIGH7.5DBHcms v1.2.0 has a sensitive information leaks vulnerability as there is no security access control in /dbhcms/ext/news...
CVE-2020-14367MEDIUM6A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file i...
CVE-2020-24186CRITICAL10A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo...
CVE-2020-19877MEDIUM5.3DBHcms v1.2.0 has a directory traversal vulnerability as there is no directory control function in directory /dbhcms/. A...
CVE-2020-14350HIGH7.3It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker wi...
CVE-2020-14349HIGH7.1It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_pat...
CVE-2020-13101HIGH7.5In OASIS Digital Signature Services (DSS) 1.0, an attacker can control the validation outcome (i.e., trigger either a va...
CVE-2020-7711HIGH7.5This affects all versions of package github.com/russellhaering/goxmldsig. There is a crash on nil-pointer dereference ca...
CVE-2020-5417HIGH8.8Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where an app domain is also t...
CVE-2020-5416MEDIUM6.5Cloud Foundry Routing (Gorouter), versions prior to 0.204.0, when used in a deployment with NGINX reverse proxies in fro...
CVE-2020-9063HIGH7.6NCR SelfServ ATMs running APTRA XFS 05.01.00 or earlier do not authenticate or protect the integrity of USB HID communic...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now