2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-11916MEDIUM6.3An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. The password for the root user is hashed using an old...
CVE-2020-11859MEDIUM5.4Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iMana...
CVE-2020-26311HIGH7.5Useragent is a user agent parser for Node.js. All versions as of time of publication contain one or more regular express...
CVE-2020-26310HIGH8.7Validate.js provides a declarative way of validating javascript objects. All versions as of 30 November 2020 contain one...
CVE-2020-26309HIGH8.7Validate.js provides a declarative way of validating javascript objects. Versions 0.11.3 and prior contain one or more r...
CVE-2020-26308HIGH7.5Validate.js provides a declarative way of validating javascript objects. Versions 0.13.1 and prior contain one or more r...
CVE-2020-26307HIGH8.7HTML2Markdown is a Javascript implementation for converting HTML to Markdown text. All available versions contain one or...
CVE-2020-26306HIGH8.7Knwl.js is a Javascript library that parses through text for dates, times, phone numbers, emails, places, and more. Vers...
CVE-2020-26305HIGH7.5CommonRegexJS is a CommonRegex port for JavaScript. All available versions contain one or more regular expressions that ...
CVE-2020-26304HIGH7.5Foundation is a front-end framework. Versions 6.3.3 and prior contain one or more regular expressions that are vulnerabl...
CVE-2020-26303HIGH7.5insane is a whitelist-oriented HTML sanitizer. Versions 2.6.2 and prior contain one or more regular expressions that are...
CVE-2020-36841MEDIUM5.3The WooCommerce Smart Coupons plugin for WordPress is vulnerable to authorization bypass due to a missing capability che...
CVE-2020-36842HIGH8.8The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing c...
CVE-2020-36840CRITICAL9.8The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missin...
CVE-2020-36839HIGH8.3The WP Lead Plus X plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0....
CVE-2020-36838HIGH7.4The Facebook Chat Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp...
CVE-2020-36837CRITICAL9.9The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability che...
CVE-2020-36836HIGH8The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and i...
CVE-2020-36835MEDIUM6.5The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a Wor...
CVE-2020-36834MEDIUM6.3The Discount Rules for WooCommerce plugin for WordPress is vulnerable to missing authorization via several AJAX actions ...
CVE-2020-36833MEDIUM6.3The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on...
CVE-2020-36832CRITICAL9.8The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and includi...
CVE-2020-36831MEDIUM6.5The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing c...
CVE-2020-24061MEDIUM4.3Cross Site Scripting (XSS) Vulnerability in Firewall menu in Control Panel in KASDA KW5515 version 4.3.1.0, allows attac...
CVE-2020-36830HIGH7.5A vulnerability was found in nescalante urlregex up to 0.5.0 and classified as problematic. This issue affects some unkn...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now