2020 CVE Vulnerabilities

21,060 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-37256MEDIUM5.1Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security config...
CVE-2020-9713MEDIUM5.5Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3...
CVE-2020-9711MEDIUM5.5Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier are affected by an ou...
CVE-2020-37248MEDIUM6.5OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS...
CVE-2020-25900MEDIUM5.3HelloTalk through 3.4.1 stores full-precision GPS coordinates even when the user had intended to share only a country or...
CVE-2020-37246MEDIUM6.9Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and d...
CVE-2020-37241MEDIUM6.9bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative a...
CVE-2020-37240MEDIUM5.1Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrat...
CVE-2020-37238MEDIUM5.1CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content...
CVE-2020-37237MEDIUM5.1Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to...
CVE-2020-37236MEDIUM5.1NewsLister contains an authenticated persistent cross-site scripting vulnerability that allows authenticated administrat...
CVE-2020-37235MEDIUM5.1WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vulnerability in the Brand component that allows auth...
CVE-2020-37234MEDIUM6.9Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local ...
CVE-2020-37233MEDIUM5.1WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated att...
CVE-2020-37225MEDIUM5.1Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scripting vulnerability that allows authenticated att...
CVE-2020-37222MEDIUM5.1Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inje...
CVE-2020-37217MEDIUM5.1Easy2Pilot 7 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized user accounts...
CVE-2020-37174MEDIUM4.8WOOF Products Filter for WooCommerce 1.2.3 contains a persistent cross-site scripting vulnerability that allows authenti...
CVE-2020-37169MEDIUM6.8WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers...
CVE-2020-37215MEDIUM4.6MSN Password Recovery version 1.30 contains a denial of service vulnerability that allows attackers to crash the applica...
CVE-2020-37213MEDIUM6.7TextCrawler Pro 3.1.1 contains a denial of service vulnerability that allows attackers to crash the application by sendi...
CVE-2020-37212MEDIUM4.6SpotMSN 2.4.6 contains a denial of service vulnerability in the registration name input field that allows attackers to c...
CVE-2020-37211MEDIUM4.6SpotIM 2.2 contains a denial of service vulnerability that allows attackers to crash the application by inputting a larg...
CVE-2020-37210MEDIUM4.6SpotIE 2.9.5 contains a denial of service vulnerability in the registration key input that allows attackers to crash the...
CVE-2020-37209MEDIUM4.6SpotFTP 3.0.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now