2020 CVE Vulnerabilities

21,060 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-37235MEDIUM5.1WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vulnerability in the Brand component that allows auth...
CVE-2020-37234MEDIUM6.9Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local ...
CVE-2020-37233MEDIUM5.1WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated att...
CVE-2020-37232HIGH8.5Advanced System Care Service 13.0.0.157 contains an unquoted service path vulnerability in the AdvancedSystemCareService...
CVE-2020-37231HIGH8.5Privacy Drive 3.17.0 contains an unquoted service path vulnerability in the pdsvc.exe service binary that allows local a...
CVE-2020-37230HIGH8.5Syncplify.me Server! 5.0.37 contains an unquoted service path vulnerability in the SMWebRestServicev5 service that allow...
CVE-2020-37229HIGH8.5OKI sPSV Port Manager 1.0.41 contains an unquoted service path vulnerability in the sPSVOpLclSrv service that allows loc...
CVE-2020-37228CRITICAL9.3iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass ...
CVE-2020-37227HIGH8.7HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerability that allows authenticated users to bypass cl...
CVE-2020-37226HIGH7.1Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipu...
CVE-2020-37225MEDIUM5.1Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scripting vulnerability that allows authenticated att...
CVE-2020-37224HIGH7.1Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipu...
CVE-2020-37223HIGH8.5IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local a...
CVE-2020-37222MEDIUM5.1Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inje...
CVE-2020-37221HIGH8.6Atomic Alarm Clock 6.3 contains a stack overflow vulnerability that allows local attackers to execute arbitrary code by ...
CVE-2020-37220HIGH8.7Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain a...
CVE-2020-37219HIGH8.7Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbi...
CVE-2020-37218HIGH8.8Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated atta...
CVE-2020-37217MEDIUM5.1Easy2Pilot 7 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized user accounts...
CVE-2020-37174MEDIUM4.8WOOF Products Filter for WooCommerce 1.2.3 contains a persistent cross-site scripting vulnerability that allows authenti...
CVE-2020-37169MEDIUM6.8WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers...
CVE-2020-37168CRITICAL9.3Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute force ...
CVE-2020-37216HIGH8.7Hirschmann HiOS devices versions prior to 08.1.00 and 07.1.01 contain a denial of service vulnerability in the EtherNet...
CVE-2020-37167HIGH8.6ClamAV versions prior to 0.103.0-rc contain a vulnerability in function name processing through the ClamBC bytecode inte...
CVE-2020-37215MEDIUM4.6MSN Password Recovery version 1.30 contains a denial of service vulnerability that allows attackers to crash the applica...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now