2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-24147 | CRITICAL | 9.1 | 1.6% | Jul 7, 2021 | Server-side request forgery (SSR) vulnerability in the WP Smart Import (wp-smart-import) plugin 1.0.0 for WordPress via ... |
| CVE-2020-24146 | HIGH | 8.1 | 1.7% | Jul 7, 2021 | Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized us... |
| CVE-2020-24145 | MEDIUM | 6.1 | 1.0% | Jul 7, 2021 | Cross Site Scripting (XSS) vulnerability in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress... |
| CVE-2020-24144 | HIGH | 8.6 | 2.0% | Jul 7, 2021 | Directory traversal in the Media File Organizer (aka media-file-organizer) plugin 1.0.1 for WordPress lets an attacker g... |
| CVE-2020-24143 | HIGH | 7.5 | 2.0% | Jul 7, 2021 | Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker... |
| CVE-2020-24142 | CRITICAL | 9.8 | 1.7% | Jul 7, 2021 | Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an ... |
| CVE-2020-24141 | MEDIUM | 5.3 | 0.9% | Jul 7, 2021 | Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests... |
| CVE-2020-24038 | MEDIUM | 6.5 | 1.1% | Jul 7, 2021 | myFax version 229 logs sensitive information in the export log module which allows any user to access critical informati... |
| CVE-2020-20225 | MEDIUM | 6.5 | 2.0% | Jul 7, 2021 | Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /nova/bin/user proces... |
| CVE-2020-20216 | MEDIUM | 6.5 | 1.6% | Jul 7, 2021 | Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/graphing proce... |
| CVE-2020-20215 | MEDIUM | 6.5 | 1.5% | Jul 7, 2021 | Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/diskd process.... |
| CVE-2020-20213 | MEDIUM | 6.5 | 2.1% | Jul 7, 2021 | Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an stack exhaustion vulnerability in the /nova/bin/net process. A... |
| CVE-2020-20212 | MEDIUM | 6.5 | 1.9% | Jul 7, 2021 | Mikrotik RouterOs 6.44.5 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/console proces... |
| CVE-2020-20211 | MEDIUM | 6.5 | 2.1% | Jul 7, 2021 | Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an assertion failure vulnerability in the /nova/bin/console proce... |
| CVE-2020-23697 | MEDIUM | 5.4 | 1.9% | Jul 6, 2021 | Cross Site Scripting vulnerabilty in Monstra CMS 3.0.4 via the page feature in admin/index.php. |
| CVE-2020-22251 | MEDIUM | 4.8 | 0.6% | Jul 6, 2021 | Cross Site Scripting (XSS) vulnerability in phpList 3.5.3 via the login name field in Manage Administrators when adding ... |
| CVE-2020-22249 | CRITICAL | 9.8 | 2.9% | Jul 6, 2021 | Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the p... |
| CVE-2020-26763 | HIGH | 7.5 | 0.8% | Jul 5, 2021 | The Rocket.Chat desktop application 2.17.11 opens external links without user interaction. |
| CVE-2020-36416 | MEDIUM | 5.4 | 0.5% | Jul 2, 2021 | A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitra... |
| CVE-2020-36415 | MEDIUM | 5.4 | 0.5% | Jul 2, 2021 | A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitra... |
| CVE-2020-36414 | MEDIUM | 5.4 | 0.5% | Jul 2, 2021 | A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitra... |
| CVE-2020-36413 | MEDIUM | 5.4 | 0.5% | Jul 2, 2021 | A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitra... |
| CVE-2020-36412 | MEDIUM | 5.4 | 0.5% | Jul 2, 2021 | A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitra... |
| CVE-2020-36411 | MEDIUM | 5.4 | 0.5% | Jul 2, 2021 | A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitra... |
| CVE-2020-36410 | MEDIUM | 5.4 | 0.5% | Jul 2, 2021 | A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitra... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now