2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14072 | CRITICAL | 9.8 | 3.4% | Jun 29, 2020 | An issue was discovered in MK-AUTH 19.01. It allows command execution as root via shell metacharacters to /auth admin sc... |
| CVE-2020-14071 | MEDIUM | 6.1 | 0.7% | Jun 29, 2020 | An issue was discovered in MK-AUTH 19.01. XSS vulnerabilities in admin and client scripts allow an attacker to execute a... |
| CVE-2020-14070 | CRITICAL | 9.8 | 1.8% | Jun 29, 2020 | An issue was discovered in MK-AUTH 19.01. There is authentication bypass in the web login functionality because guessabl... |
| CVE-2020-14069 | MEDIUM | 6.8 | 0.4% | Jun 29, 2020 | An issue was discovered in MK-AUTH 19.01. There are SQL injection issues in mkt/ PHP scripts, as demonstrated by arp.php... |
| CVE-2020-14068 | CRITICAL | 9.8 | 1.1% | Jun 29, 2020 | An issue was discovered in MK-AUTH 19.01. The web login functionality allows an attacker to bypass authentication and ga... |
| CVE-2020-15324 | CRITICAL | 9.8 | 1.2% | Jun 29, 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a world-readable axess/opt/axXMPPHandler/config/xmpp_config.py file that ... |
| CVE-2020-15323 | CRITICAL | 9.8 | 1.2% | Jun 29, 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account default credentials. |
| CVE-2020-15322 | CRITICAL | 9.8 | 1.2% | Jun 29, 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account. |
| CVE-2020-15321 | CRITICAL | 9.8 | 1.2% | Jun 29, 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account. |
| CVE-2020-15320 | CRITICAL | 9.8 | 1.2% | Jun 29, 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axiros password for the root account. |
| CVE-2020-15319 | MEDIUM | 5.9 | 1.0% | Jun 29, 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/mysql chroot... |
| CVE-2020-15318 | MEDIUM | 5.9 | 1.0% | Jun 29, 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/mysql chroot... |
| CVE-2020-15317 | MEDIUM | 5.9 | 1.0% | Jun 29, 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/axess chroot... |
| CVE-2020-15316 | MEDIUM | 5.9 | 1.0% | Jun 29, 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account within the /opt/axess chro... |
| CVE-2020-15315 | MEDIUM | 5.9 | 1.0% | Jun 29, 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/axess chroot... |
| CVE-2020-2021 | CRITICAL | 10 | 4.4% | Jun 29, 2020 | When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate... |
| CVE-2020-15314 | MEDIUM | 5.9 | 1.0% | Jun 29, 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account. |
| CVE-2020-15313 | MEDIUM | 5.9 | 1.0% | Jun 29, 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account. |
| CVE-2020-15312 | MEDIUM | 5.9 | 1.0% | Jun 29, 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account. |
| CVE-2020-8573 | MEDIUM | 6.5 | 1.3% | Jun 29, 2020 | The NetApp HCI H610C, H615C and H610S Baseboard Management Controllers (BMC) are shipped with a documented default accou... |
| CVE-2020-4557 | MEDIUM | 5.4 | 0.6% | Jun 29, 2020 | IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cro... |
| CVE-2020-4452 | HIGH | 7.5 | 0.8% | Jun 29, 2020 | IBM API Connect V2018.4.1.0 through 2018.4.1.11 uses weaker than expected cryptographic algorithms that could allow an a... |
| CVE-2020-13423 | MEDIUM | 4.8 | 1.4% | Jun 29, 2020 | Form Builder 2.1.0 for Magento has multiple XSS issues that can be exploited against Magento 2 admin accounts via the Cu... |
| CVE-2020-12635 | MEDIUM | 6.1 | 0.7% | Jun 29, 2020 | XSS exists in the WebForms Pro M2 extension before 2.9.17 for Magento 2 via the textarea field. |
| CVE-2020-12048 | HIGH | 7.5 | 0.5% | Jun 29, 2020 | Phoenix Hemodialysis Delivery System SW 3.36 and 3.40, The Phoenix Hemodialysis device does not support data-in-transit ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now