2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-20067HIGH8.8File upload vulnerability in ebCMS v.1.1.0 allows a remote attacker to execute arbitrary code via the upload type parame...
CVE-2020-22402MEDIUM6.1Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive informa...
CVE-2020-36732MEDIUM5.3The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer...
CVE-2020-36728CRITICAL9.8The Adning Advertising plugin for WordPress is vulnerable to file deletion via path traversal in versions up to, and inc...
CVE-2020-36705CRITICAL9.8The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation ...
CVE-2020-36731MEDIUM6.1The Flexible Checkout Fields for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Plugin Set...
CVE-2020-36730CRITICAL9.3The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail...
CVE-2020-36729MEDIUM4.3The 2J-SlideShow Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'tw...
CVE-2020-36727CRITICAL9.8The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, ...
CVE-2020-36726CRITICAL9.8The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32...
CVE-2020-36725HIGH8.1The TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vu...
CVE-2020-36724CRITICAL9.8The Wordable plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.1. This i...
CVE-2020-36723MEDIUM5.3The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions ...
CVE-2020-36722MEDIUM4.8The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 du...
CVE-2020-36721MEDIUM6.5The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Acti...
CVE-2020-36720HIGH7.1The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1....
CVE-2020-36719CRITICAL9.8The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activ...
CVE-2020-36718CRITICAL9.8The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inclu...
CVE-2020-36717HIGH8.8The Kali Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1....
CVE-2020-36716HIGH7.3The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ...
CVE-2020-36715MEDIUM4.6The Login/Signup Popup plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on se...
CVE-2020-36713CRITICAL9.8The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This...
CVE-2020-36712MEDIUM5.3The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and incl...
CVE-2020-36711MEDIUM5.4The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the update_layout function in versions up...
CVE-2020-36710HIGH7.5The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now