2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-36739 | MEDIUM | 4.3 | 0.4% | Jul 1, 2023 | The Feed Them Social – Page, Post, Video, and Photo Galleries plugin for WordPress is vulnerable to Cross-Site Request F... |
| CVE-2020-36738 | MEDIUM | 4.3 | 0.4% | Jul 1, 2023 | The Cool Timeline (Horizontal & Vertical Timeline) plugin for WordPress is vulnerable to Cross-Site Request Forgery in v... |
| CVE-2020-36737 | MEDIUM | 4.3 | 0.4% | Jul 1, 2023 | The Import / Export Customizer Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up ... |
| CVE-2020-36736 | MEDIUM | 4.3 | 0.4% | Jul 1, 2023 | The WooCommerce Checkout & Funnel Builder by CartFlows plugin for WordPress is vulnerable to Cross-Site Request Forgery ... |
| CVE-2020-36735 | MEDIUM | 4.3 | 0.4% | Jul 1, 2023 | The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is... |
| CVE-2020-18432 | CRITICAL | 9.8 | 0.7% | Jun 30, 2023 | File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privile... |
| CVE-2020-26710 | HIGH | 7.5 | 0.7% | Jun 29, 2023 | easy-parse v0.1.1 was discovered to contain a XML External Entity Injection (XXE) vulnerability which allows attackers t... |
| CVE-2020-26709 | HIGH | 7.5 | 0.7% | Jun 29, 2023 | py-xml v1.0 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to exe... |
| CVE-2020-26708 | HIGH | 7.5 | 0.7% | Jun 29, 2023 | requests-xml v0.2.3 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attacker... |
| CVE-2020-18414 | MEDIUM | 4.8 | 0.4% | Jun 27, 2023 | Stored cross site scripting (XSS) vulnerability in Chaoji CMS v2.18 that allows attackers to execute arbitrary code via ... |
| CVE-2020-18409 | MEDIUM | 6.8 | 0.3% | Jun 27, 2023 | Cross Site Request Forgery (CSRF) vulnerability was discovered in CatfishCMS 4.8.63 that would allow attackers to obtain... |
| CVE-2020-18404 | MEDIUM | 4.8 | 0.3% | Jun 27, 2023 | An issue was discovered in espcms version P8.18101601. There is a cross site scripting (XSS) vulnerability that allows a... |
| CVE-2020-19902 | CRITICAL | 9.8 | 1.6% | Jun 27, 2023 | Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code vi... |
| CVE-2020-18416 | MEDIUM | 6.8 | 0.3% | Jun 27, 2023 | An cross site request forgery (CSRF) vulnerability discovered in Jymusic v2.0.0.,that allows attackers to execute arbitr... |
| CVE-2020-18413 | MEDIUM | 4.8 | 0.4% | Jun 27, 2023 | Stored cross site scripting (XSS) vulnerability in /index.php?admin-master-navmenu-add of Chaoji CMS v2.18 that allows a... |
| CVE-2020-18410 | MEDIUM | 4.8 | 0.3% | Jun 27, 2023 | A stored cross site scripting (XSS) vulnerability in /index.php?admin-master-article-edit of Chaoji CMS v2.18 that allow... |
| CVE-2020-18406 | HIGH | 7.5 | 0.3% | Jun 27, 2023 | An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of ... |
| CVE-2020-18418 | HIGH | 8.8 | 0.3% | Jun 27, 2023 | A Cross site request forgery (CSRF) vulnerability was discovered in FeiFeiCMS v4.1.190209, which allows attackers to cre... |
| CVE-2020-23066 | — | — | — | Jun 26, 2023 | Rejected reason: DO NOT USE THIS CVE ID NUMBER. Consult IDs: CVE-2020-17480. Reason: This CVE Record is a duplicate of C... |
| CVE-2020-23065 | MEDIUM | 5.4 | 0.4% | Jun 26, 2023 | Cross Site Scripting vulnerabiltiy in eZ Systems AS eZPublish Platform v.5.4 and eZ Publish Legacy v.5.4 allows a remote... |
| CVE-2020-23064 | — | — | — | Jun 26, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-11023. Reason: This candidate is a duplicate of ... |
| CVE-2020-20210 | HIGH | 8.8 | 1.0% | Jun 26, 2023 | Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images. |
| CVE-2020-21489 | CRITICAL | 9.8 | 1.3% | Jun 20, 2023 | File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.ph... |
| CVE-2020-21486 | HIGH | 7.5 | 0.9% | Jun 20, 2023 | SQL injection vulnerability in PHPOK v.5.4. allows a remote attacker to obtain sensitive information via the _userlist f... |
| CVE-2020-21485 | MEDIUM | 6.1 | 0.5% | Jun 20, 2023 | Cross Site Scripting vulnerability in Alluxio v.1.8.1 allows a remote attacker to executea arbitrary code via the path p... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now