2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-35717CRITICAL9zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in web...
CVE-2020-35391MEDIUM6.5Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas...
CVE-2020-35951CRITICAL9.9An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbit...
CVE-2020-35950HIGH8.8An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almos...
CVE-2020-35949CRITICAL9.8An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthe...
CVE-2020-35948HIGH8.8An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated atta...
CVE-2020-35947HIGH7.4An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lack...
CVE-2020-35946MEDIUM5.4An issue was discovered in the All in One SEO Pack plugin before 3.6.2 for WordPress. The SEO Description and Title fiel...
CVE-2020-35945HIGH8.8An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authent...
CVE-2020-35944HIGH8.8An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vuln...
CVE-2020-35939HIGH8.8PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated...
CVE-2020-35938HIGH8.8PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated atta...
CVE-2020-35937HIGH8Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote ...
CVE-2020-35936HIGH8Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authe...
CVE-2020-35935HIGH8.8The Advanced Access Manager plugin before 6.6.2 for WordPress allows privilege escalation on profile updates via the aam...
CVE-2020-35934MEDIUM4.3The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadat...
CVE-2020-35933MEDIUM6.5A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress a...
CVE-2020-35932HIGH8.8Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with ...
CVE-2020-35931HIGH7.8An issue was discovered in Foxit Reader before 10.1.1 (and before 4.1.1 on macOS) and PhantomPDF before 9.7.5 and 10.x b...
CVE-2020-26165HIGH8.8qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/a...
CVE-2020-35930MEDIUM5.4Seo Panel 4.8.0 allows stored XSS by an Authenticated User via the url parameter, as demonstrated by the seo/seopanel/we...
CVE-2020-25799MEDIUM5.4LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Quota component of the Survey page. When the survey q...
CVE-2020-25797MEDIUM5.4LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Add Participants Function (First and last name parame...
CVE-2020-11835MEDIUM5.5In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_da9313.c, failure to check the parameter buf in the...
CVE-2020-11834MEDIUM5.5In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_vooc.c, the function proc_fastchg_fw_update_write in proc_fast...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now