2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-14072CRITICAL9.8An issue was discovered in MK-AUTH 19.01. It allows command execution as root via shell metacharacters to /auth admin sc...
CVE-2020-14071MEDIUM6.1An issue was discovered in MK-AUTH 19.01. XSS vulnerabilities in admin and client scripts allow an attacker to execute a...
CVE-2020-14070CRITICAL9.8An issue was discovered in MK-AUTH 19.01. There is authentication bypass in the web login functionality because guessabl...
CVE-2020-14069MEDIUM6.8An issue was discovered in MK-AUTH 19.01. There are SQL injection issues in mkt/ PHP scripts, as demonstrated by arp.php...
CVE-2020-14068CRITICAL9.8An issue was discovered in MK-AUTH 19.01. The web login functionality allows an attacker to bypass authentication and ga...
CVE-2020-15324CRITICAL9.8Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a world-readable axess/opt/axXMPPHandler/config/xmpp_config.py file that ...
CVE-2020-15323CRITICAL9.8Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account default credentials.
CVE-2020-15322CRITICAL9.8Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account.
CVE-2020-15321CRITICAL9.8Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account.
CVE-2020-15320CRITICAL9.8Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axiros password for the root account.
CVE-2020-15319MEDIUM5.9Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/mysql chroot...
CVE-2020-15318MEDIUM5.9Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/mysql chroot...
CVE-2020-15317MEDIUM5.9Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/axess chroot...
CVE-2020-15316MEDIUM5.9Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account within the /opt/axess chro...
CVE-2020-15315MEDIUM5.9Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/axess chroot...
CVE-2020-2021CRITICAL10When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate...
CVE-2020-15314MEDIUM5.9Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account.
CVE-2020-15313MEDIUM5.9Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account.
CVE-2020-15312MEDIUM5.9Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account.
CVE-2020-8573MEDIUM6.5The NetApp HCI H610C, H615C and H610S Baseboard Management Controllers (BMC) are shipped with a documented default accou...
CVE-2020-4557MEDIUM5.4IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cro...
CVE-2020-4452HIGH7.5IBM API Connect V2018.4.1.0 through 2018.4.1.11 uses weaker than expected cryptographic algorithms that could allow an a...
CVE-2020-13423MEDIUM4.8Form Builder 2.1.0 for Magento has multiple XSS issues that can be exploited against Magento 2 admin accounts via the Cu...
CVE-2020-12635MEDIUM6.1XSS exists in the WebForms Pro M2 extension before 2.9.17 for Magento 2 via the textarea field.
CVE-2020-12048HIGH7.5Phoenix Hemodialysis Delivery System SW 3.36 and 3.40, The Phoenix Hemodialysis device does not support data-in-transit ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now