2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7831 | HIGH | 8.8 | 0.9% | Aug 24, 2020 | A vulnerability in the web-based contract management service interface Ebiz4u of INOGARD could allow an victim user to d... |
| CVE-2020-19891 | HIGH | 7.2 | 1.4% | Aug 24, 2020 | DBHcms v1.2.0 has an Arbitrary file write vulnerability in dbhcms\mod\mod.editor.php $_POST['updatefile'] is filename an... |
| CVE-2020-19890 | MEDIUM | 4.9 | 0.9% | Aug 24, 2020 | DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as the... |
| CVE-2020-19889 | HIGH | 8.8 | 0.5% | Aug 24, 2020 | DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user. |
| CVE-2020-19888 | MEDIUM | 5.9 | 0.7% | Aug 24, 2020 | DBHcms v1.2.0 has an unauthorized operation vulnerability because there's no access control at line 175 of dbhcms\page.p... |
| CVE-2020-19887 | MEDIUM | 4.8 | 0.9% | Aug 24, 2020 | DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_desc... |
| CVE-2020-19886 | HIGH | 8.1 | 0.4% | Aug 24, 2020 | DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for an /index.php?dbhcms_pid=-80&deletemenu=9 can... |
| CVE-2020-19885 | MEDIUM | 4.8 | 0.9% | Aug 24, 2020 | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_name... |
| CVE-2020-19884 | MEDIUM | 4.8 | 0.6% | Aug 24, 2020 | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function in dbhcms\mod\mod.domain.edit.php ... |
| CVE-2020-19883 | MEDIUM | 4.8 | 0.7% | Aug 24, 2020 | DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter in dbhcms\mod\mod.users.view.php line 57 for... |
| CVE-2020-19882 | MEDIUM | 4.8 | 0.7% | Aug 24, 2020 | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for 'menu_description' variable in... |
| CVE-2020-19881 | MEDIUM | 4.8 | 0.9% | Aug 24, 2020 | DBHcms v1.2.0 has a reflected xss vulnerability as there is no security filter in dbhcms\mod\mod.selector.php line 108 f... |
| CVE-2020-19880 | MEDIUM | 6.1 | 0.9% | Aug 24, 2020 | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function form 'Name' in dbhcms\types.php, A... |
| CVE-2020-19879 | MEDIUM | 6.1 | 0.7% | Aug 24, 2020 | DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter of $_GET['dbhcms_pid'] variable in dbhcms\pa... |
| CVE-2020-19878 | HIGH | 7.5 | 1.5% | Aug 24, 2020 | DBHcms v1.2.0 has a sensitive information leaks vulnerability as there is no security access control in /dbhcms/ext/news... |
| CVE-2020-14367 | MEDIUM | 6 | 0.5% | Aug 24, 2020 | A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file i... |
| CVE-2020-24186 | CRITICAL | 10 | 94.6% | Aug 24, 2020 | A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo... |
| CVE-2020-19877 | MEDIUM | 5.3 | 1.7% | Aug 24, 2020 | DBHcms v1.2.0 has a directory traversal vulnerability as there is no directory control function in directory /dbhcms/. A... |
| CVE-2020-14350 | HIGH | 7.3 | 0.5% | Aug 24, 2020 | It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker wi... |
| CVE-2020-14349 | HIGH | 7.1 | 2.2% | Aug 24, 2020 | It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_pat... |
| CVE-2020-13101 | HIGH | 7.5 | 0.7% | Aug 24, 2020 | In OASIS Digital Signature Services (DSS) 1.0, an attacker can control the validation outcome (i.e., trigger either a va... |
| CVE-2020-7711 | HIGH | 7.5 | 1.8% | Aug 23, 2020 | This affects all versions of package github.com/russellhaering/goxmldsig. There is a crash on nil-pointer dereference ca... |
| CVE-2020-5417 | HIGH | 8.8 | 1.0% | Aug 21, 2020 | Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where an app domain is also t... |
| CVE-2020-5416 | MEDIUM | 6.5 | 1.2% | Aug 21, 2020 | Cloud Foundry Routing (Gorouter), versions prior to 0.204.0, when used in a deployment with NGINX reverse proxies in fro... |
| CVE-2020-9063 | HIGH | 7.6 | 0.7% | Aug 21, 2020 | NCR SelfServ ATMs running APTRA XFS 05.01.00 or earlier do not authenticate or protect the integrity of USB HID communic... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now