Skip to main content

Year archive

CVEs published in 2020

Archive summary

18,322 CVEs published in 2020 — 2,625 Critical, 7,666 High, 7,546 Medium, 485 Low, 0 Unrated.

CVE-2020-27397

Published Dec 23, 2020

Marital - Online Matrimonial Project In PHP version 1.0 suffers from an authenticated file upload vulnerability allowing remote attackers to gain remote code execution (RCE) on th…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13969

Published Dec 23, 2020

CRK Business Platform <= 2019.1 allows reflected XSS via erro.aspx on 'CRK', 'IDContratante', 'Erro', or 'Mod' parameter. This is path-independent.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13968

Published Dec 23, 2020

CRK Business Platform <= 2019.1 allows can inject SQL statements against the DB on any path using the 'strSessao' parameter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-4642

Published Dec 23, 2020

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow local attacker to cause a denial of service inside the "DB2 Managemen…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11719

Published Dec 23, 2020

An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. It relies on broken encryption with a weak and guessable static encryption key.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000891

Published Dec 23, 2020

Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving messages with invalid checksums.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6159

Published Dec 23, 2020

URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scripting (XSS) attacks, but in certain circumstances this rem…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35650

Published Dec 23, 2020

Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Groups for LearnDash before v3.7 allow authenticated remote attackers to inject arbitrary JavaScript or HTML via the…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29552

Published Dec 23, 2020

An issue was discovered in URVE Build 24.03.2020. By using the _internal/pc/vpro.php?mac=0&ip=0&operation=0&usr=0&pass=0%3bpowershell+-c+" substring, it is possible to execute a P…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-29551

Published Dec 23, 2020

An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is possible to shutdown the system. Among others, the following files and scripts ar…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-29550

Published Dec 23, 2020

An issue was discovered in URVE Build 24.03.2020. The password of an integration user account (used for the connection of the MS Office 365 Integration Service) is stored in clear…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11720

Published Dec 23, 2020

An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. During the installation, it sets up administrative access by default with the accou…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-11718

Published Dec 23, 2020

An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and below. Its software-update packages are downloaded via cleartext HTTP.

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35136

Published Dec 23, 2020

Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup function by inserting a payload…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 426-450 of 18,322 CVEsPage 18 of 733