2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-20919 | HIGH | 7.2 | 1.3% | Jun 20, 2023 | File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensi... |
| CVE-2020-20918 | HIGH | 7.2 | 1.1% | Jun 20, 2023 | An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden par... |
| CVE-2020-20726 | HIGH | 8.8 | 0.7% | Jun 20, 2023 | Cross Site Request Forgery vulnerability in Gila GilaCMS v.1.11.4 allows a remote attacker to execute arbitrary code via... |
| CVE-2020-20636 | HIGH | 7.5 | 0.7% | Jun 20, 2023 | SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via th... |
| CVE-2020-20491 | HIGH | 7.2 | 1.1% | Jun 20, 2023 | SQL injection vulnerability in OpenCart v.2.2.00 thru 3.0.3.2 allows a remote attacker to execute arbitrary code via the... |
| CVE-2020-20335 | HIGH | 7.5 | 1.0% | Jun 20, 2023 | Buffer Overflow vulnerability in Antirez Kilo before commit 7709a04ae8520c5b04d261616098cebf742f5a23 allows a remote att... |
| CVE-2020-20067 | HIGH | 8.8 | 1.3% | Jun 20, 2023 | File upload vulnerability in ebCMS v.1.1.0 allows a remote attacker to execute arbitrary code via the upload type parame... |
| CVE-2020-36725 | HIGH | 8.1 | 1.1% | Jun 7, 2023 | The TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vu... |
| CVE-2020-36720 | HIGH | 7.1 | 0.8% | Jun 7, 2023 | The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.... |
| CVE-2020-36717 | HIGH | 8.8 | 0.5% | Jun 7, 2023 | The Kali Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1.... |
| CVE-2020-36716 | HIGH | 7.3 | 0.8% | Jun 7, 2023 | The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ... |
| CVE-2020-36710 | HIGH | 7.5 | 0.8% | Jun 7, 2023 | The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are ... |
| CVE-2020-36707 | HIGH | 8.8 | 0.5% | Jun 7, 2023 | The Coming Soon & Maintenance Mode Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up ... |
| CVE-2020-36701 | HIGH | 8.8 | 1.5% | Jun 7, 2023 | The Page Builder: KingComposer plugin for WordPress is vulnerable to Arbitrary File Uploads in versions up to, and inclu... |
| CVE-2020-36700 | HIGH | 8.8 | 1.2% | Jun 7, 2023 | The Page Builder: KingComposer plugin for WordPress is vulnerable to authorization bypass in versions up to, and includi... |
| CVE-2020-36696 | HIGH | 7.5 | 1.1% | Jun 7, 2023 | The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing cap... |
| CVE-2020-19028 | HIGH | 7.5 | 1.1% | Jun 5, 2023 | *File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive informat... |
| CVE-2020-13377 | HIGH | 8.1 | 1.5% | May 12, 2023 | The web-services interface of Loadbalancer.org Enterprise VA MAX through 8.3.8 could allow an authenticated, remote, low... |
| CVE-2020-13378 | HIGH | 8.8 | 3.3% | May 12, 2023 | Loadbalancer.org Enterprise VA MAX through 8.3.8 has an OS Command Injection vulnerability that allows a remote authenti... |
| CVE-2020-23363 | HIGH | 8.8 | 0.4% | May 9, 2023 | Cross Site Request Forgery (CSRF) vulnerability found in Verytops Verydows all versions that allows an attacker to execu... |
| CVE-2020-23362 | HIGH | 7.1 | 0.7% | May 9, 2023 | Insecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges... |
| CVE-2020-36065 | HIGH | 8.8 | 0.3% | May 8, 2023 | Cross Site Request Forgery (CSRF) vulnerability in FlyCms 1.0 allows attackers to add arbitrary administrator accounts v... |
| CVE-2020-22755 | HIGH | 8.8 | 0.9% | May 8, 2023 | File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vu... |
| CVE-2020-18131 | HIGH | 8.8 | 0.4% | May 8, 2023 | Cross Site Request Forgery (CSRF) vulnerability in Bluethrust Clan Scripts v4 allows attackers to escilate privledges to... |
| CVE-2020-22429 | HIGH | 7.8 | 0.3% | May 3, 2023 | redox-os v0.1.0 was discovered to contain a use-after-free bug via the gethostbyaddr() function at /src/header/netdb/mod... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now