2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-20067 | HIGH | 8.8 | 1.3% | Jun 20, 2023 | File upload vulnerability in ebCMS v.1.1.0 allows a remote attacker to execute arbitrary code via the upload type parame... |
| CVE-2020-22402 | MEDIUM | 6.1 | 0.4% | Jun 14, 2023 | Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive informa... |
| CVE-2020-36732 | MEDIUM | 5.3 | 1.1% | Jun 12, 2023 | The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer... |
| CVE-2020-36728 | CRITICAL | 9.8 | 3.2% | Jun 7, 2023 | The Adning Advertising plugin for WordPress is vulnerable to file deletion via path traversal in versions up to, and inc... |
| CVE-2020-36705 | CRITICAL | 9.8 | 6.9% | Jun 7, 2023 | The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation ... |
| CVE-2020-36731 | MEDIUM | 6.1 | 1.3% | Jun 7, 2023 | The Flexible Checkout Fields for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Plugin Set... |
| CVE-2020-36730 | CRITICAL | 9.3 | 2.3% | Jun 7, 2023 | The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail... |
| CVE-2020-36729 | MEDIUM | 4.3 | 0.7% | Jun 7, 2023 | The 2J-SlideShow Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'tw... |
| CVE-2020-36727 | CRITICAL | 9.8 | 1.6% | Jun 7, 2023 | The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, ... |
| CVE-2020-36726 | CRITICAL | 9.8 | 1.6% | Jun 7, 2023 | The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32... |
| CVE-2020-36725 | HIGH | 8.1 | 1.1% | Jun 7, 2023 | The TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vu... |
| CVE-2020-36724 | CRITICAL | 9.8 | 1.5% | Jun 7, 2023 | The Wordable plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.1. This i... |
| CVE-2020-36723 | MEDIUM | 5.3 | 1.6% | Jun 7, 2023 | The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions ... |
| CVE-2020-36722 | MEDIUM | 4.8 | 0.7% | Jun 7, 2023 | The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 du... |
| CVE-2020-36721 | MEDIUM | 6.5 | 1.0% | Jun 7, 2023 | The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Acti... |
| CVE-2020-36720 | HIGH | 7.1 | 0.8% | Jun 7, 2023 | The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.... |
| CVE-2020-36719 | CRITICAL | 9.8 | 4.3% | Jun 7, 2023 | The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activ... |
| CVE-2020-36718 | CRITICAL | 9.8 | 1.7% | Jun 7, 2023 | The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inclu... |
| CVE-2020-36717 | HIGH | 8.8 | 0.5% | Jun 7, 2023 | The Kali Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1.... |
| CVE-2020-36716 | HIGH | 7.3 | 0.8% | Jun 7, 2023 | The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ... |
| CVE-2020-36715 | MEDIUM | 4.6 | 0.7% | Jun 7, 2023 | The Login/Signup Popup plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on se... |
| CVE-2020-36713 | CRITICAL | 9.8 | 1.6% | Jun 7, 2023 | The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This... |
| CVE-2020-36712 | MEDIUM | 5.3 | 0.7% | Jun 7, 2023 | The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and incl... |
| CVE-2020-36711 | MEDIUM | 5.4 | 0.6% | Jun 7, 2023 | The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the update_layout function in versions up... |
| CVE-2020-36710 | HIGH | 7.5 | 0.8% | Jun 7, 2023 | The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now