2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-36756MEDIUM4.3The 10WebAnalytics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1....
CVE-2020-36752MEDIUM4.3The Coming Soon & Maintenance Mode Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up ...
CVE-2020-36750MEDIUM4.3The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi...
CVE-2020-20118MEDIUM5.5Buffer Overflow vulnerability in Avast AntiVirus before v.19.7 allows a local attacker to cause a denial of service via ...
CVE-2020-8934MEDIUM4.3The Site Kit by Google plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and inc...
CVE-2020-22336CRITICAL9.8An issue was discovered in pdfcrack 0.17 thru 0.18, allows attackers to execute arbitrary code via a stack overflow in t...
CVE-2020-21862HIGH8.1Directory traversal vulnerability in DuxCMS 2.1 allows attackers to delete arbitrary files via /admin/AdminBackup/del.
CVE-2020-21861HIGH8.8File upload vulnerability in DuxCMS 2.1 allows attackers to execute arbitrary php code via duxcms/AdminUpload/upload.
CVE-2020-23452MEDIUM6.1A cross-site scripting (XSS) vulnerability in Selenium Grid v3.141.59 allows attackers to execute arbitrary web scripts ...
CVE-2020-25969CRITICAL9.8gnuplot v5.5 was discovered to contain a buffer overflow via the function plotrequest().
CVE-2020-22597CRITICAL9.8An issue in Jerrscript- project Jerryscrip v. 2.3.0 allows a remote attacker to execute arbitrary code via the ecma_buil...
CVE-2020-22153CRITICAL9.8File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file...
CVE-2020-22152MEDIUM5.4Cross Site Scripting vulnerability in daylight studio FUEL- CMS v.1.4.6 allows a remote attacker to execute arbitrary co...
CVE-2020-22151CRITICAL9.8Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file ...
CVE-2020-15730Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2020-36749MEDIUM4.3The Easy Testimonials plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,...
CVE-2020-36748MEDIUM4.3The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.8. This...
CVE-2020-36747MEDIUM4.3The Lightweight Sidebar Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and ...
CVE-2020-36746MEDIUM4.3The Menu Swapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1....
CVE-2020-36745HIGH8.8The WP Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including...
CVE-2020-36744MEDIUM4.3The NotificationX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8...
CVE-2020-36743MEDIUM4.3The Product Catalog Simple plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu...
CVE-2020-36742MEDIUM4.3The Custom Field Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ...
CVE-2020-36741MEDIUM4.3The MultiVendorX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5....
CVE-2020-36740HIGH8.8The Radio Buttons for Taxonomies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now