2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-20703 | CRITICAL | 9.8 | 1.5% | Jun 20, 2023 | Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand param... |
| CVE-2020-20413 | CRITICAL | 9.8 | 1.3% | Jun 20, 2023 | SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checkti... |
| CVE-2020-36728 | CRITICAL | 9.8 | 3.2% | Jun 7, 2023 | The Adning Advertising plugin for WordPress is vulnerable to file deletion via path traversal in versions up to, and inc... |
| CVE-2020-36705 | CRITICAL | 9.8 | 6.9% | Jun 7, 2023 | The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation ... |
| CVE-2020-36730 | CRITICAL | 9.3 | 2.3% | Jun 7, 2023 | The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail... |
| CVE-2020-36727 | CRITICAL | 9.8 | 1.6% | Jun 7, 2023 | The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, ... |
| CVE-2020-36726 | CRITICAL | 9.8 | 1.6% | Jun 7, 2023 | The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32... |
| CVE-2020-36724 | CRITICAL | 9.8 | 1.5% | Jun 7, 2023 | The Wordable plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.1. This i... |
| CVE-2020-36719 | CRITICAL | 9.8 | 4.3% | Jun 7, 2023 | The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activ... |
| CVE-2020-36718 | CRITICAL | 9.8 | 1.7% | Jun 7, 2023 | The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inclu... |
| CVE-2020-36713 | CRITICAL | 9.8 | 1.6% | Jun 7, 2023 | The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This... |
| CVE-2020-36708 | CRITICAL | 9.8 | 65.3% | Jun 7, 2023 | The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.... |
| CVE-2020-20012 | CRITICAL | 9.8 | 1.1% | May 23, 2023 | WebPlus Pro v1.4.7.8.4-01 is vulnerable to Incorrect Access Control. |
| CVE-2020-23966 | CRITICAL | 9.8 | 0.8% | May 8, 2023 | SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /... |
| CVE-2020-36070 | CRITICAL | 9.8 | 1.1% | Apr 26, 2023 | Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code v... |
| CVE-2020-29007 | CRITICAL | 9.8 | 2.3% | Apr 15, 2023 | The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of ... |
| CVE-2020-19802 | CRITICAL | 9.8 | 1.1% | Apr 11, 2023 | File Upload vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the uploa... |
| CVE-2020-29312 | CRITICAL | 9.8 | 1.5% | Apr 4, 2023 | An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserializ... |
| CVE-2020-21487 | CRITICAL | 9.6 | 0.7% | Apr 4, 2023 | Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute a... |
| CVE-2020-20915 | CRITICAL | 9.8 | 1.1% | Apr 4, 2023 | SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql paramete... |
| CVE-2020-20914 | CRITICAL | 9.8 | 1.1% | Apr 4, 2023 | SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the... |
| CVE-2020-20913 | CRITICAL | 9.8 | 1.4% | Apr 4, 2023 | SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic... |
| CVE-2020-19695 | CRITICAL | 9.8 | 1.3% | Apr 4, 2023 | Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parame... |
| CVE-2020-19693 | CRITICAL | 9.8 | 0.8% | Apr 4, 2023 | An issue found in Espruino Espruino 6ea4c0a allows an attacker to execute arbitrrary code via oldFunc parameter of the j... |
| CVE-2020-19692 | CRITICAL | 9.8 | 1.3% | Apr 4, 2023 | Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now