2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-37080CRITICAL9.8webTareas 2.0.p8 contains a file deletion vulnerability in the print_layout.php administration component that allows aut...
CVE-2020-37078HIGH8.8i-doit Open Source CMDB 1.14.1 contains a file deletion vulnerability in the import module that allows authenticated att...
CVE-2020-37077MEDIUM6.9Booked Scheduler 2.7.7 contains a directory traversal vulnerability in the manage_email_templates.php script that allows...
CVE-2020-37076HIGH8.2Victor CMS version 1.0 contains a SQL injection vulnerability in the 'post' parameter on post.php that allows remote att...
CVE-2020-37075CRITICAL9.8LanSend 3.2 contains a buffer overflow vulnerability in the Add Computers Wizard file import functionality that allows r...
CVE-2020-37074CRITICAL9.8Remote Desktop Audit 2.3.0.157 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code ...
CVE-2020-37073HIGH8.8Victor CMS 1.0 contains an authenticated file upload vulnerability that allows administrators to upload PHP files with a...
CVE-2020-37072MEDIUM6.1Victor CMS 1.0 contains a stored cross-site scripting vulnerability in the 'comment_author' POST parameter that allows a...
CVE-2020-37071CRITICAL9.8CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute ...
CVE-2020-37070CRITICAL9.8CloudMe 1.11.2 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code through c...
CVE-2020-37069CRITICAL9.8Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the NLST command that allows attackers to ove...
CVE-2020-37068CRITICAL9.8Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the LIST command that allows attackers to ove...
CVE-2020-37067CRITICAL9.8Filetto 1.0 FTP server contains a denial of service vulnerability in the FEAT command processing that allows attackers t...
CVE-2020-37066CRITICAL9.8GoldWave 5.70 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting malic...
CVE-2020-37065CRITICAL9.8StreamRipper32 version 2.6 contains a buffer overflow vulnerability in the Station/Song Section that allows attackers to...
CVE-2020-37116HIGH8.8GUnet OpenEclass 1.7.3 includes phpMyAdmin 2.10.0.2 by default, which allows remote logins. Attackers with access to the...
CVE-2020-37115MEDIUM4.9GUnet OpenEclass 1.7.3 stores user credentials in plaintext, allowing administrators to view all registered users' usern...
CVE-2020-37114MEDIUM6.5GUnet OpenEclass 1.7.3 allows unauthenticated and authenticated users to access sensitive information, including system ...
CVE-2020-37113HIGH8.8GUnet OpenEclass 1.7.3 allows authenticated users to bypass file extension restrictions when uploading files. By renamin...
CVE-2020-37112MEDIUM6.5GUnet OpenEclass 1.7.3 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate ...
CVE-2020-37111MEDIUM6.160CycleCMS 2.5.2 contains a cross-site scripting (XSS) vulnerability in news.php that allows attackers to inject malicio...
CVE-2020-37110CRITICAL9.860CycleCMS 2.5.2 contains an SQL injection vulnerability in news.php and common/lib.php that allows attackers to manipul...
CVE-2020-37108HIGH7.1PhpIX 2012 Professional contains a SQL injection vulnerability in the 'id' parameter of product_detail.php that allows r...
CVE-2020-37105HIGH7.1PMB 5.6 contains a SQL injection vulnerability in the administration download script that allows authenticated attackers...
CVE-2020-37103MEDIUM5.4DotNetNuke 9.5 contains a persistent cross-site scripting vulnerability that allows normal users to upload malicious XML...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now