2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-36739MEDIUM4.3The Feed Them Social – Page, Post, Video, and Photo Galleries plugin for WordPress is vulnerable to Cross-Site Request F...
CVE-2020-36738MEDIUM4.3The Cool Timeline (Horizontal & Vertical Timeline) plugin for WordPress is vulnerable to Cross-Site Request Forgery in v...
CVE-2020-36737MEDIUM4.3The Import / Export Customizer Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up ...
CVE-2020-36736MEDIUM4.3The WooCommerce Checkout & Funnel Builder by CartFlows plugin for WordPress is vulnerable to Cross-Site Request Forgery ...
CVE-2020-36735MEDIUM4.3The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is...
CVE-2020-18432CRITICAL9.8File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privile...
CVE-2020-26710HIGH7.5easy-parse v0.1.1 was discovered to contain a XML External Entity Injection (XXE) vulnerability which allows attackers t...
CVE-2020-26709HIGH7.5py-xml v1.0 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to exe...
CVE-2020-26708HIGH7.5requests-xml v0.2.3 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attacker...
CVE-2020-18414MEDIUM4.8Stored cross site scripting (XSS) vulnerability in Chaoji CMS v2.18 that allows attackers to execute arbitrary code via ...
CVE-2020-18409MEDIUM6.8Cross Site Request Forgery (CSRF) vulnerability was discovered in CatfishCMS 4.8.63 that would allow attackers to obtain...
CVE-2020-18404MEDIUM4.8An issue was discovered in espcms version P8.18101601. There is a cross site scripting (XSS) vulnerability that allows a...
CVE-2020-19902CRITICAL9.8Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code vi...
CVE-2020-18416MEDIUM6.8An cross site request forgery (CSRF) vulnerability discovered in Jymusic v2.0.0.,that allows attackers to execute arbitr...
CVE-2020-18413MEDIUM4.8Stored cross site scripting (XSS) vulnerability in /index.php?admin-master-navmenu-add of Chaoji CMS v2.18 that allows a...
CVE-2020-18410MEDIUM4.8A stored cross site scripting (XSS) vulnerability in /index.php?admin-master-article-edit of Chaoji CMS v2.18 that allow...
CVE-2020-18406HIGH7.5An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of ...
CVE-2020-18418HIGH8.8A Cross site request forgery (CSRF) vulnerability was discovered in FeiFeiCMS v4.1.190209, which allows attackers to cre...
CVE-2020-23066Rejected reason: DO NOT USE THIS CVE ID NUMBER. Consult IDs: CVE-2020-17480. Reason: This CVE Record is a duplicate of C...
CVE-2020-23065MEDIUM5.4Cross Site Scripting vulnerabiltiy in eZ Systems AS eZPublish Platform v.5.4 and eZ Publish Legacy v.5.4 allows a remote...
CVE-2020-23064Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-11023. Reason: This candidate is a duplicate of ...
CVE-2020-20210HIGH8.8Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.
CVE-2020-21489CRITICAL9.8File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.ph...
CVE-2020-21486HIGH7.5SQL injection vulnerability in PHPOK v.5.4. allows a remote attacker to obtain sensitive information via the _userlist f...
CVE-2020-21485MEDIUM6.1Cross Site Scripting vulnerability in Alluxio v.1.8.1 allows a remote attacker to executea arbitrary code via the path p...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now