2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15342 | MEDIUM | 5.3 | 0.6% | Sep 29, 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user API. |
| CVE-2020-15339 | MEDIUM | 6.1 | 0.7% | Sep 29, 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows live/CPEManager/AXCampaignManager/handle_campaign_script_link?script_n... |
| CVE-2020-15338 | MEDIUM | 5.3 | 0.8% | Sep 29, 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /cnr... |
| CVE-2020-15337 | MEDIUM | 5.3 | 0.8% | Sep 29, 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /reg... |
| CVE-2020-15334 | MEDIUM | 5.3 | 0.8% | Sep 29, 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows escape-sequence injection into the /var/log/axxmpp.log file. |
| CVE-2020-15333 | MEDIUM | 5.3 | 1.0% | Sep 29, 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows attackers to discover accounts via MySQL "select * from Administrator_... |
| CVE-2020-15330 | MEDIUM | 5.3 | 0.6% | Sep 29, 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded APP_KEY in /opt/axess/etc/default/axess. |
| CVE-2020-15329 | MEDIUM | 5.3 | 0.8% | Sep 29, 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak Data.fs permissions. |
| CVE-2020-15328 | MEDIUM | 5.3 | 0.8% | Sep 29, 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/var/blobstorage/ permissions. |
| CVE-2020-15326 | MEDIUM | 5.3 | 0.5% | Sep 29, 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded certificate for Ejabberd in ejabberd.pem. |
| CVE-2020-15325 | MEDIUM | 5.3 | 0.6% | Sep 29, 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded Erlang cookie for ejabberd replication. |
| CVE-2020-36602 | MEDIUM | 6.1 | 0.3% | Sep 20, 2022 | There is an out-of-bounds read and write vulnerability in some headset products. An unauthenticated attacker gets the de... |
| CVE-2020-25491 | MEDIUM | 6.1 | 0.5% | Sep 16, 2022 | 6Kare Emakin 5.0.341.0 is affected by Cross Site Scripting (XSS) via the /rpc/membership/setProfile DisplayName field, w... |
| CVE-2020-36603 | MEDIUM | 6.5 | 0.4% | Sep 14, 2022 | The HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unpri... |
| CVE-2020-19587 | MEDIUM | 5.4 | 0.7% | Sep 14, 2022 | Cross Site Scripting (XSS) vulnerability in configMap parameters in Yellowfin Business Intelligence 7.3 allows remote at... |
| CVE-2020-19914 | MEDIUM | 6.1 | 0.6% | Sep 7, 2022 | Cross Site Scripting (XSS) in xiunobbs 4.0.4 allows remote attackers to execute arbitrary web script or HTML via the att... |
| CVE-2020-4301 | MEDIUM | 6.5 | 0.3% | Sep 1, 2022 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacke... |
| CVE-2020-35535 | MEDIUM | 5.5 | 0.3% | Sep 1, 2022 | In LibRaw, there is an out-of-bounds read vulnerability within the "LibRaw::parseSonySRF()" function (libraw\src\metadat... |
| CVE-2020-35534 | MEDIUM | 5.5 | 0.2% | Sep 1, 2022 | In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\cr... |
| CVE-2020-35533 | MEDIUM | 5.5 | 0.3% | Sep 1, 2022 | In LibRaw, an out-of-bounds read vulnerability exists within the "LibRaw::adobe_copy_pixel()" function (libraw\src\decod... |
| CVE-2020-35532 | MEDIUM | 5.5 | 0.4% | Sep 1, 2022 | In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_util... |
| CVE-2020-35531 | MEDIUM | 5.5 | 0.3% | Sep 1, 2022 | In LibRaw, an out-of-bounds read vulnerability exists within the get_huffman_diff() function (libraw\src\x3f\x3f_utils_p... |
| CVE-2020-35530 | MEDIUM | 5.5 | 0.4% | Sep 1, 2022 | In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patc... |
| CVE-2020-27784 | MEDIUM | 5.5 | 0.2% | Sep 1, 2022 | A vulnerability was found in the Linux kernel, where accessing a deallocated instance in printer_ioctl() printer_ioctl()... |
| CVE-2020-35538 | MEDIUM | 5.5 | 0.3% | Aug 31, 2022 | A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now