2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-24147CRITICAL9.1Server-side request forgery (SSR) vulnerability in the WP Smart Import (wp-smart-import) plugin 1.0.0 for WordPress via ...
CVE-2020-24146HIGH8.1Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized us...
CVE-2020-24145MEDIUM6.1Cross Site Scripting (XSS) vulnerability in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress...
CVE-2020-24144HIGH8.6Directory traversal in the Media File Organizer (aka media-file-organizer) plugin 1.0.1 for WordPress lets an attacker g...
CVE-2020-24143HIGH7.5Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker...
CVE-2020-24142CRITICAL9.8Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an ...
CVE-2020-24141MEDIUM5.3Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests...
CVE-2020-24038MEDIUM6.5myFax version 229 logs sensitive information in the export log module which allows any user to access critical informati...
CVE-2020-20225MEDIUM6.5Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /nova/bin/user proces...
CVE-2020-20216MEDIUM6.5Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/graphing proce...
CVE-2020-20215MEDIUM6.5Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/diskd process....
CVE-2020-20213MEDIUM6.5Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an stack exhaustion vulnerability in the /nova/bin/net process. A...
CVE-2020-20212MEDIUM6.5Mikrotik RouterOs 6.44.5 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/console proces...
CVE-2020-20211MEDIUM6.5Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an assertion failure vulnerability in the /nova/bin/console proce...
CVE-2020-23697MEDIUM5.4Cross Site Scripting vulnerabilty in Monstra CMS 3.0.4 via the page feature in admin/index.php.
CVE-2020-22251MEDIUM4.8Cross Site Scripting (XSS) vulnerability in phpList 3.5.3 via the login name field in Manage Administrators when adding ...
CVE-2020-22249CRITICAL9.8Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the p...
CVE-2020-26763HIGH7.5The Rocket.Chat desktop application 2.17.11 opens external links without user interaction.
CVE-2020-36416MEDIUM5.4A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitra...
CVE-2020-36415MEDIUM5.4A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitra...
CVE-2020-36414MEDIUM5.4A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitra...
CVE-2020-36413MEDIUM5.4A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitra...
CVE-2020-36412MEDIUM5.4A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitra...
CVE-2020-36411MEDIUM5.4A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitra...
CVE-2020-36410MEDIUM5.4A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitra...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now