2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-20919HIGH7.2File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensi...
CVE-2020-20918HIGH7.2An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden par...
CVE-2020-20726HIGH8.8Cross Site Request Forgery vulnerability in Gila GilaCMS v.1.11.4 allows a remote attacker to execute arbitrary code via...
CVE-2020-20636HIGH7.5SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via th...
CVE-2020-20491HIGH7.2SQL injection vulnerability in OpenCart v.2.2.00 thru 3.0.3.2 allows a remote attacker to execute arbitrary code via the...
CVE-2020-20335HIGH7.5Buffer Overflow vulnerability in Antirez Kilo before commit 7709a04ae8520c5b04d261616098cebf742f5a23 allows a remote att...
CVE-2020-20067HIGH8.8File upload vulnerability in ebCMS v.1.1.0 allows a remote attacker to execute arbitrary code via the upload type parame...
CVE-2020-36725HIGH8.1The TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vu...
CVE-2020-36720HIGH7.1The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1....
CVE-2020-36717HIGH8.8The Kali Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1....
CVE-2020-36716HIGH7.3The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ...
CVE-2020-36710HIGH7.5The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are ...
CVE-2020-36707HIGH8.8The Coming Soon & Maintenance Mode Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up ...
CVE-2020-36701HIGH8.8The Page Builder: KingComposer plugin for WordPress is vulnerable to Arbitrary File Uploads in versions up to, and inclu...
CVE-2020-36700HIGH8.8The Page Builder: KingComposer plugin for WordPress is vulnerable to authorization bypass in versions up to, and includi...
CVE-2020-36696HIGH7.5The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing cap...
CVE-2020-19028HIGH7.5*File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive informat...
CVE-2020-13377HIGH8.1The web-services interface of Loadbalancer.org Enterprise VA MAX through 8.3.8 could allow an authenticated, remote, low...
CVE-2020-13378HIGH8.8Loadbalancer.org Enterprise VA MAX through 8.3.8 has an OS Command Injection vulnerability that allows a remote authenti...
CVE-2020-23363HIGH8.8Cross Site Request Forgery (CSRF) vulnerability found in Verytops Verydows all versions that allows an attacker to execu...
CVE-2020-23362HIGH7.1Insecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges...
CVE-2020-36065HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in FlyCms 1.0 allows attackers to add arbitrary administrator accounts v...
CVE-2020-22755HIGH8.8File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vu...
CVE-2020-18131HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in Bluethrust Clan Scripts v4 allows attackers to escilate privledges to...
CVE-2020-22429HIGH7.8redox-os v0.1.0 was discovered to contain a use-after-free bug via the gethostbyaddr() function at /src/header/netdb/mod...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now