Search Results (43212 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-15364 1 Nexos Project 1 Nexos 2024-11-21 6.1 Medium
The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.
CVE-2020-15339 1 Zyxel 1 Cloudcnm Secumanager 2024-11-21 6.1 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows live/CPEManager/AXCampaignManager/handle_campaign_script_link?script_name= XSS.
CVE-2020-15327 1 Zyxel 1 Cloudcnm Secumanager 2024-11-21 7.5 High
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication.
CVE-2020-15326 1 Zyxel 1 Cloudcnm Secumanager 2024-11-21 5.3 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded certificate for Ejabberd in ejabberd.pem.
CVE-2020-15324 1 Zyxel 1 Cloud Cnm Secumanager 2024-11-21 9.8 Critical
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a world-readable axess/opt/axXMPPHandler/config/xmpp_config.py file that stores hardcoded credentials.
CVE-2020-15323 1 Zyxel 1 Cloudcnm Secumanager 2024-11-21 9.8 Critical
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account default credentials.
CVE-2020-15322 1 Zyxel 1 Cloudcnm Secumanager 2024-11-21 9.8 Critical
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account.
CVE-2020-15321 1 Zyxel 1 Cloudcnm Secumanager 2024-11-21 9.8 Critical
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account.
CVE-2020-15320 1 Zyxel 1 Cloudcnm Secumanager 2024-11-21 9.8 Critical
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axiros password for the root account.
CVE-2020-15319 1 Zyxel 1 Cloudcnm Secumanager 2024-11-21 5.9 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/mysql chroot directory tree.
CVE-2020-15318 1 Zyxel 1 Cloudcnm Secumanager 2024-11-21 5.9 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/mysql chroot directory tree.
CVE-2020-15317 1 Zyxel 1 Cloudcnm Secumanager 2024-11-21 5.9 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/axess chroot directory tree.
CVE-2020-15316 1 Zyxel 1 Cloudcnm Secumanager 2024-11-21 5.9 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account within the /opt/axess chroot directory tree.
CVE-2020-15315 1 Zyxel 1 Cloudcnm Secumanager 2024-11-21 5.9 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/axess chroot directory tree.
CVE-2020-15314 1 Zyxel 1 Cloudcnm Secumanager 2024-11-21 5.9 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account.
CVE-2020-15313 1 Zyxel 1 Cloudcnm Secumanager 2024-11-21 5.9 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account.
CVE-2020-15312 1 Zyxel 1 Cloudcnm Secumanager 2024-11-21 5.9 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account.
CVE-2020-15307 1 Nozominetworks 1 Guardian 2024-11-21 6.1 Medium
Nozomi Guardian before 19.0.4 allows attackers to achieve stored XSS (in the web front end) by leveraging the ability to create a custom field with a crafted field name.
CVE-2020-15299 1 King-theme 1 Kingcomposer 2024-11-21 6.1 Medium
A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST parameter) that is executed in the victim's browser.
CVE-2020-15276 1 Basercms 1 Basercms 2024-11-21 7.7 High
baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. Arbitrary JavaScript may be executed by entering a crafted nickname in blog comments. The issue affects the blog comment component. It is fixed in version 4.4.1.