Skip to main content

Year archive

CVEs published in 2020

Archive summary

18,322 CVEs published in 2020 — 2,625 Critical, 7,666 High, 7,546 Medium, 485 Low, 0 Unrated.

CVE-2020-5841

Published Jan 7, 2020

An issue was discovered in OpServices OpMon 9.3.1-1. Using password change parameters, an attacker could perform SQL injection without authentication.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-5842

Published Jan 7, 2020

Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI. The payload is, for example, executed on the admin/index.ph…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5307

Published Jan 7, 2020

PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category and CategoryCode parameters i…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-9465

Published Jan 7, 2020

In the Titan M handling of cryptographic operations, there is a possible information disclosure due to an unusual root cause. This could lead to local information disclosure with…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6700

Published Jan 7, 2020

An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker to retrieve the external authe…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18386

Published Jan 7, 2020

Systems management on Unisys ClearPath Forward Libra and ClearPath MCP Software Series can fault and have other unspecified impact when receiving specifically crafted message payl…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16154

Published Jan 7, 2020

An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS)…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10776

Published Jan 7, 2020

In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. This affects git-diff-apply all versions prior to 0.22.2.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-10465

Published Jan 7, 2020

Jamf Pro 10.x before 10.3.0 has Incorrect Access Control. Jamf Pro user accounts and groups with access to log in to Jamf Pro had full access to endpoints in the Universal API (UA…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8673

Published Jan 7, 2020

Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online Planning (SOPPlanning)before 1.33.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-14879

Published Jan 7, 2020

A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14866

Published Jan 7, 2020

In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14834

Published Jan 7, 2020

A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHC…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-5657

Published Jan 7, 2020

AultWare pwStore 2010.8.30.0 has DoS via an empty HTTP request

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 18,101-18,125 of 18,322 CVEsPage 725 of 733