2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-20703CRITICAL9.8Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand param...
CVE-2020-20413CRITICAL9.8SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checkti...
CVE-2020-36728CRITICAL9.8The Adning Advertising plugin for WordPress is vulnerable to file deletion via path traversal in versions up to, and inc...
CVE-2020-36705CRITICAL9.8The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation ...
CVE-2020-36730CRITICAL9.3The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail...
CVE-2020-36727CRITICAL9.8The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, ...
CVE-2020-36726CRITICAL9.8The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32...
CVE-2020-36724CRITICAL9.8The Wordable plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.1. This i...
CVE-2020-36719CRITICAL9.8The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activ...
CVE-2020-36718CRITICAL9.8The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inclu...
CVE-2020-36713CRITICAL9.8The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This...
CVE-2020-36708CRITICAL9.8The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2....
CVE-2020-20012CRITICAL9.8WebPlus Pro v1.4.7.8.4-01 is vulnerable to Incorrect Access Control.
CVE-2020-23966CRITICAL9.8SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /...
CVE-2020-36070CRITICAL9.8Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code v...
CVE-2020-29007CRITICAL9.8The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of ...
CVE-2020-19802CRITICAL9.8File Upload vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the uploa...
CVE-2020-29312CRITICAL9.8An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserializ...
CVE-2020-21487CRITICAL9.6Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute a...
CVE-2020-20915CRITICAL9.8SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql paramete...
CVE-2020-20914CRITICAL9.8SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the...
CVE-2020-20913CRITICAL9.8SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic...
CVE-2020-19695CRITICAL9.8Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parame...
CVE-2020-19693CRITICAL9.8An issue found in Espruino Espruino 6ea4c0a allows an attacker to execute arbitrrary code via oldFunc parameter of the j...
CVE-2020-19692CRITICAL9.8Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now