High · CVSS 7.4
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim's traffic to view or modify a victim's data in transit.
Published Jun 23, 2020 · Updated Sep 16, 2024
Medium · CVSS 5.1
In the Zephyr project Bluetooth subsystem, certain duplicate and back-to-back packets can cause incorrect behavior, resulting in a denial of service. This issue affects: zephyrproject-rtos zephyr version 2.2.0 and later versions, and version 1.14.0 and later versions.
Published Jun 5, 2020 · Updated Sep 16, 2024
Medium · CVSS 5.4
IBM Workload Scheduler 9.3.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 179160.
Published Jun 11, 2020 · Updated Sep 16, 2024
High · CVSS 7.5
Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability.
Published Jun 1, 2022 · Updated Sep 16, 2024
Medium · CVSS 5.3
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 discloses highly sensitive information in plain text in the virgo log file which could be used in further attacks against the system. IBM X-Force ID: 181779.
Published Jun 15, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.4
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
Published Jun 9, 2020 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who control a Confluence Server instance that the Companion App is connected to, execute arbitrary .exe files via a Protection Mechanism Failure.
Published Jun 1, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.1
IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174739.
Published Jun 4, 2020 · Updated Sep 16, 2024
High · CVSS 8.8
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted request to the REST API, an attacker could exploit this vulnerability to bypass access restrictions, and execute arbitrary actions with administrative privileges. IBM X-Force ID: 182114.
Published Jun 2, 2021 · Updated Sep 16, 2024
Medium · CVSS 4.1
IBM Security Guardium 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174852.
Published Jun 4, 2020 · Updated Sep 16, 2024
Unknown · CVSS Not scored
An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service.
Published Jun 11, 2021 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the app run a different executable in place of the app's cmd.exe via a untrusted search path vulnerability.
Published Jun 1, 2020 · Updated Sep 16, 2024
Critical · CVSS 9.8
The password for the safety PLC is the default and thus easy to find (in manuals, etc.). This allows a manipulated program to be uploaded to the safety PLC, effectively disabling the emergency stop in case an object is too close to the robot. Navigation and any other components dependent on the laser scanner are not affected (thus it is hard to detect before something happens) though the laser scanner configuration can also be affected altering further the safety of the device.
Published Jun 24, 2020 · Updated Sep 16, 2024
Medium · CVSS 5.9
IBM API Connect V2018.4.1.0 through 2018.4.1.11 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 181324.
Published Jun 29, 2020 · Updated Sep 16, 2024
Unknown · CVSS Not scored
An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows 10 may cause arbitrary code execution in the kernel, leading to escalation of privilege or denial of service.
Published Jun 11, 2021 · Updated Sep 16, 2024
Medium · CVSS 4
GeoVision Door Access Control device family improperly stores and controls access to system logs, any users can read these logs.
Published Jun 12, 2020 · Updated Sep 16, 2024
High · CVSS 7.8
Privilege Escalation vulnerability during daily DAT updates when using McAfee Virus Scan Enterprise (VSE) prior to 8.8 Patch 15 allows local users to cause the deletion and creation of files they would not normally have permission to through altering the target of symbolic links. This is timing dependent.
Published Jun 10, 2020 · Updated Sep 16, 2024
High · CVSS 7.2
An OS Command Injection vulnerability in the PAN-OS web management interface allows authenticated administrators to execute arbitrary OS commands with root privileges by sending a malicious request to generate new certificates for use in the PAN-OS configuration. This issue affects: All versions of PAN-OS 8.0; PAN-OS 7.1 versions earlier than PAN-OS 7.1.26; PAN-OS 8.1 versions earlier than PAN-OS 8.1.13.
Published Jun 10, 2020 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get the ID of configured Jira application links via an information disclosure vulnerability.
Published Jun 1, 2020 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page, in some situations this may have allowed unauthorised attackers to determine if certain resources exist or not through an Information Disclosure vulnerability.
Published Jun 23, 2020 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the XML export view.
Published Jun 1, 2020 · Updated Sep 16, 2024
Medium · CVSS 5.4
IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176474.
Published Jun 19, 2020 · Updated Sep 16, 2024
Medium · CVSS 5.4
IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176408.
Published Jun 19, 2020 · Updated Sep 16, 2024
Critical · CVSS 10
There is an improper Neutralization of Special Elements used in an SQL Command (SQL Injection) vulnerability in php files of GESIO ERP. GESIO ERP all versions prior to 11.2 allows malicious users to retrieve all database information.
Published Jun 1, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.5
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper group permissions. IBM X-Force ID: 191945.
Published Jun 24, 2021 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A potential denial of service (DoS) vulnerability exists in the integrated chipset that may allow a malicious attacker to hang the system when it is rebooted.
Published Jun 11, 2021 · Updated Sep 16, 2024
High · CVSS 8.8
IBM Security Guardium 11.1 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 174735.
Published Jun 3, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.5
IBM Security Guardium 11.1 could allow an attacker on the same network to gain access to the Solr dashboard and cause a denial of service attack. IBM X-Force ID: 176997.
Published Jun 3, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.1
The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings such as boot order. This can be leveraged by a Malicious operator to boot from a Live Image.
Published Jun 24, 2020 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk screen, to execute arbitrary OS commands via the Theme Module by visiting the admin/index.php?id=themes&action=edit_chunk URI. NOTE: there is no indication that the Edit Chunk feature was intended to prevent an administrator from using PHP's exec feature
Published Jun 9, 2020 · Updated Aug 27, 2024
Unknown · CVSS Not scored
An issue was discovered in the Linux kernel before 5.8.2. fs/io_uring.c has a use-after-free related to io_async_task_func and ctx reference holding, aka CID-6d816e088c35.
Published Jun 7, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the Linux kernel before 5.8.1. net/bluetooth/hci_event.c has a slab out-of-bounds read in hci_extended_inquiry_result_evt, aka CID-51c19bf3d5cf.
Published Jun 7, 2021 · Updated Aug 4, 2024
Medium · CVSS 6.1
PageLayer before 1.3.5 allows reflected XSS via color settings.
Published Jun 7, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
pam_setquota.c in the pam_setquota module before 2020-05-29 for Linux-PAM allows local attackers to set their quota on an arbitrary filesystem, in certain situations where the attacker's home directory is a FUSE filesystem mounted under /home.
Published Jun 22, 2021 · Updated Aug 4, 2024
Medium · CVSS 6.1
PageLayer before 1.3.5 allows reflected XSS via the font-size parameter.
Published Jun 7, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In CiviCRM before 5.28.1 and CiviCRM ESR before 5.27.5 ESR, the CKEditor configuration form allows CSRF.
Published Jun 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the Linux kernel before 5.10. drivers/infiniband/core/ucma.c has a use-after-free because the ctx is reached via the ctx_list in some ucma_migrate_id situations where ucma_close is called, aka CID-f5449e74802c.
Published Jun 7, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase via incorrect authentication token data in an early phase of the user authentication resulting in a denial of service.
Published Jun 4, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In CiviCRM before 5.21.3 and 5.22.x through 5.24.x before 5.24.3, users may be able to upload and execute a crafted PHAR archive.
Published Jun 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter.
Published Jun 4, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'fileurl' parameter.
Published Jun 4, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=editor' to change any file content (Locally/Remotely).
Published Jun 4, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' header.
Published Jun 4, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
AppCMS 2.0.101 in /admin/download_frame.php has a SQL injection vulnerability which allows attackers to obtain sensitive database information.
Published Jun 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
AppCMS 2.0.101 in /admin/template/tpl_app.php has a cross site scripting attack vulnerability which allows the attacker to obtain sensitive information of other users.
Published Jun 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
OBottle 2.0 in \c\t.php contains an arbitrary file write vulnerability.
Published Jun 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
AppCMS 2.0.101 in /admin/info.php has an arbitrary file deletion vulnerability which allows attackers to delete arbitrary files on the site.
Published Jun 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
AppCMS 2.0.101 in /admin/app.php has an arbitrary file deletion vulnerability which allows attackers to delete arbitrary files on the site.
Published Jun 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
OBottle 2.0 in \c\g.php contains an arbitrary file download vulnerability.
Published Jun 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A storage XSS vulnerability is found in YzmCMS v5.8, which can be used by attackers to inject JS code and attack malicious XSS on the /admin/system_manage/user_config_edit.html page.
Published Jun 3, 2021 · Updated Aug 4, 2024