2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35717 | CRITICAL | 9 | 3.8% | Jan 1, 2021 | zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in web... |
| CVE-2020-35391 | MEDIUM | 6.5 | 35.0% | Jan 1, 2021 | Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas... |
| CVE-2020-35951 | CRITICAL | 9.9 | 76.3% | Jan 1, 2021 | An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbit... |
| CVE-2020-35950 | HIGH | 8.8 | 0.9% | Jan 1, 2021 | An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almos... |
| CVE-2020-35949 | CRITICAL | 9.8 | 4.9% | Jan 1, 2021 | An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthe... |
| CVE-2020-35948 | HIGH | 8.8 | 24.9% | Jan 1, 2021 | An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated atta... |
| CVE-2020-35947 | HIGH | 7.4 | 1.1% | Jan 1, 2021 | An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lack... |
| CVE-2020-35946 | MEDIUM | 5.4 | 0.8% | Jan 1, 2021 | An issue was discovered in the All in One SEO Pack plugin before 3.6.2 for WordPress. The SEO Description and Title fiel... |
| CVE-2020-35945 | HIGH | 8.8 | 2.4% | Jan 1, 2021 | An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authent... |
| CVE-2020-35944 | HIGH | 8.8 | 0.8% | Jan 1, 2021 | An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vuln... |
| CVE-2020-35939 | HIGH | 8.8 | 2.1% | Jan 1, 2021 | PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated... |
| CVE-2020-35938 | HIGH | 8.8 | 2.1% | Jan 1, 2021 | PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated atta... |
| CVE-2020-35937 | HIGH | 8 | 1.7% | Jan 1, 2021 | Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote ... |
| CVE-2020-35936 | HIGH | 8 | 1.7% | Jan 1, 2021 | Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authe... |
| CVE-2020-35935 | HIGH | 8.8 | 1.5% | Jan 1, 2021 | The Advanced Access Manager plugin before 6.6.2 for WordPress allows privilege escalation on profile updates via the aam... |
| CVE-2020-35934 | MEDIUM | 4.3 | 1.1% | Jan 1, 2021 | The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadat... |
| CVE-2020-35933 | MEDIUM | 6.5 | 0.9% | Jan 1, 2021 | A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress a... |
| CVE-2020-35932 | HIGH | 8.8 | 2.1% | Jan 1, 2021 | Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with ... |
| CVE-2020-35931 | HIGH | 7.8 | 2.3% | Dec 31, 2020 | An issue was discovered in Foxit Reader before 10.1.1 (and before 4.1.1 on macOS) and PhantomPDF before 9.7.5 and 10.x b... |
| CVE-2020-26165 | HIGH | 8.8 | 2.5% | Dec 31, 2020 | qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/a... |
| CVE-2020-35930 | MEDIUM | 5.4 | 0.5% | Dec 31, 2020 | Seo Panel 4.8.0 allows stored XSS by an Authenticated User via the url parameter, as demonstrated by the seo/seopanel/we... |
| CVE-2020-25799 | MEDIUM | 5.4 | 0.7% | Dec 31, 2020 | LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Quota component of the Survey page. When the survey q... |
| CVE-2020-25797 | MEDIUM | 5.4 | 0.7% | Dec 31, 2020 | LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Add Participants Function (First and last name parame... |
| CVE-2020-11835 | MEDIUM | 5.5 | 0.3% | Dec 31, 2020 | In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_da9313.c, failure to check the parameter buf in the... |
| CVE-2020-11834 | MEDIUM | 5.5 | 0.3% | Dec 31, 2020 | In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_vooc.c, the function proc_fastchg_fw_update_write in proc_fast... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now