2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-22402MEDIUM6.1Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive informa...
CVE-2020-36732MEDIUM5.3The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer...
CVE-2020-36731MEDIUM6.1The Flexible Checkout Fields for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Plugin Set...
CVE-2020-36729MEDIUM4.3The 2J-SlideShow Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'tw...
CVE-2020-36723MEDIUM5.3The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions ...
CVE-2020-36722MEDIUM4.8The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 du...
CVE-2020-36721MEDIUM6.5The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Acti...
CVE-2020-36715MEDIUM4.6The Login/Signup Popup plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on se...
CVE-2020-36712MEDIUM5.3The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and incl...
CVE-2020-36711MEDIUM5.4The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the update_layout function in versions up...
CVE-2020-36709MEDIUM4.8The Page Builder: KingComposer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via via shortcode in ve...
CVE-2020-36704MEDIUM5.4The Fruitful Theme for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters stored via the frui...
CVE-2020-36703MEDIUM5.4The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in...
CVE-2020-36702MEDIUM4.3The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to,...
CVE-2020-36699MEDIUM4.3The Quick Page/Post Redirect Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks...
CVE-2020-36697MEDIUM6.5The WP GDPR plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up ...
CVE-2020-29547MEDIUM5.9An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 ...
CVE-2020-36694MEDIUM6.7An issue was discovered in netfilter in the Linux kernel before 5.10. There can be a use-after-free in the packet proces...
CVE-2020-18280MEDIUM6.1Cross Site Scripting vulnerability found in Phodal CMD v.1.0 allows a local attacker to execute arbitrary code via the E...
CVE-2020-22334MEDIUM6.5Cross Site Request Forgery (CSRF) vulnerability in beescms v4 allows attackers to delete the administrator account via c...
CVE-2020-21038MEDIUM6.1Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php.
CVE-2020-19660MEDIUM6.1Cross Site Scripting (XSS) pandao editor.md 1.5.0 allows attackers to execute arbitrary code via crafted linked url valu...
CVE-2020-18282MEDIUM6.1Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML...
CVE-2020-18132MEDIUM4.8Cross Site Scripting (XSS) vulnerability in MIPCMS 3.6.0 allows attackers to execute arbitrary code via the category nam...
CVE-2020-4914MEDIUM4.2IBM Cloud Pak System Suite 2.3.3.0 through 2.3.3.5 does not invalidate session after logout which could allow a local us...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now