High · CVSS 7.1
The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.
Published Sep 3, 2020 · Updated Sep 17, 2024
High · CVSS 8.8
IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to bypass security and execute actions reserved for admins. IBM X-Force ID: 184922.
Published Sep 22, 2020 · Updated Sep 17, 2024
Low · CVSS 3.3
IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security restrictions due to improper input validation. IBM X-Force ID: 184884.
Published Sep 29, 2020 · Updated Sep 17, 2024
High · CVSS 7.8
Privilege Escalation vulnerability in the installer in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to assume SYSTEM rights during the installation of MA via manipulation of log files.
Published Sep 10, 2020 · Updated Sep 17, 2024
Critical · CVSS 9.8
Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.
Published Sep 1, 2020 · Updated Sep 17, 2024
Medium · CVSS 6.9
Authentication Protection Bypass vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows physical local users to bypass the Windows lock screen via triggering certain detection events while the computer screen is locked and the McTray.exe is running with elevated privileges. This issue is timing dependent and requires physical access to the machine.
Published Sep 9, 2020 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticated as a non-administrator user to view Project Request-Types and Descriptions, via an Information Disclosure vulnerability in the editform request-type-fields resource. The affected versions are before version 4.12.0.
Published Sep 21, 2020 · Updated Sep 17, 2024
Medium · CVSS 6.3
A cross-site scripting (XSS) vulnerability was discovered in the legacy IBM and Lenovo System x IMM2 (Integrated Management Module 2), prior to version 5.60, embedded Baseboard Management Controller (BMC) web interface during an internal security review. This vulnerability could allow JavaScript code to be executed in the user's web browser if the user is convinced to visit a crafted URL, possibly through phishing. Successful exploitation requires specific knowledge about the user’s network to be included in the crafted URL. Impact is limited to the normal access restrictions and permissions of the user clicking the crafted URL, and subject to the user being able to connect to and already being authenticated to IMM2 or other systems. The JavaScript code is not executed on IMM2 itself.
Published Sep 15, 2020 · Updated Sep 17, 2024
Medium · CVSS 6.5
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 187501.
Published Sep 15, 2020 · Updated Sep 17, 2024
Medium · CVSS 6.1
IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
Published Sep 25, 2020 · Updated Sep 17, 2024
High · CVSS 7.5
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information. IBM X-Force ID: 185590.
Published Sep 21, 2020 · Updated Sep 17, 2024
Critical · CVSS 9
The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Sites component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
Published Sep 10, 2020 · Updated Sep 17, 2024
Medium · CVSS 5.4
IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-ForceID: 182714.
Published Sep 15, 2020 · Updated Sep 17, 2024
Medium · CVSS 5.7
IBM InfoSphere Metadata Asset Manager 11.7 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to submit or control server requests. IBM X-Force ID: 185416.
Published Sep 4, 2020 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Regex-based Denial of Service (DoS) vulnerability in JQL version searching. The affected versions are before version 7.13.16; from version 7.14.0 before 8.5.7; from version 8.6.0 before 8.10.2; and from version 8.11.0 before 8.11.1.
Published Sep 21, 2020 · Updated Sep 17, 2024
High · CVSS 7.2
A buffer overflow vulnerability in the PAN-OS management web interface allows authenticated administrators to disrupt system processes and potentially execute arbitrary code with root privileges. This issue impacts only PAN-OS 10.0 versions earlier than PAN-OS 10.0.1.
Published Sep 9, 2020 · Updated Sep 17, 2024
Critical · CVSS 9.8
A vulnerability in Base Software for SoftControl allows an attacker to insert and run arbitrary code in a computer running the affected product. This issue affects: .
Published Sep 8, 2021 · Updated Sep 17, 2024
Medium · CVSS 6.4
IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186841.
Published Sep 8, 2020 · Updated Sep 17, 2024
Unknown · CVSS Not scored
The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow an attacker to trick application users into performing critical application actions that include, but are not limited to, adding and updating accounts.
Published Sep 25, 2020 · Updated Sep 17, 2024
Medium · CVSS 4.8
In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.
Published Sep 9, 2020 · Updated Sep 17, 2024
Medium · CVSS 5.9
IBM Data Risk Manager (iDNA) 2.0.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 184983.
Published Sep 22, 2020 · Updated Sep 17, 2024
High · CVSS 8.2
Privilege Escalation Vulnerability in the installer in McAfee Data Exchange Layer (DXL) Client for Mac shipped with McAfee Agent (MA) for Mac prior to MA 5.6.6 allows local users to run commands as root via incorrectly applied permissions on temporary files.
Published Sep 10, 2020 · Updated Sep 17, 2024
Medium · CVSS 4.3
IBM Edge 4.2 could reveal sensitive version information about the server from error pages that could aid an attacker in further attacks against the system. IBM X-Force ID: 191941.
Published Sep 23, 2021 · Updated Sep 17, 2024
Critical · CVSS 9.1
Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by sending specifically constructed requests without authentication This issue affects: WAGO 750-362, WAGO 750-363, WAGO 750-823, WAGO 750-832/xxx-xxx, WAGO 750-862, WAGO 750-891, WAGO 750-890/xxx-xxx in versions FW03 and prior versions.
Published Sep 30, 2020 · Updated Sep 17, 2024
Medium · CVSS 4.3
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 176609.
Published Sep 1, 2022 · Updated Sep 17, 2024
High · CVSS 7.3
A race condition vulnerability was reported in Lenovo System Update prior to version 5.07.0106 that could allow escalation of privilege.
Published Sep 15, 2020 · Updated Sep 17, 2024
Medium · CVSS 6.5
IBM API Connect 2018.4.1.0 through 2018.4.1.12 could allow an attacker to launch phishing attacks by tricking the server to generate user registration emails that contain malicious URLs. IBM X-Force ID: 177933.
Published Sep 3, 2020 · Updated Sep 17, 2024
Low · CVSS 3.1
Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controller.read" scope, but no roles in any spaces, to list all droplets in all spaces (whereas they should see none).
Published Sep 3, 2020 · Updated Sep 17, 2024
Critical · CVSS 9.8
All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function.
Published Sep 1, 2020 · Updated Sep 17, 2024
Critical · CVSS 9.8
All versions of package dot-notes are vulnerable to Prototype Pollution via the create function.
Published Sep 1, 2020 · Updated Sep 16, 2024
High · CVSS 7.8
A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.
Published Sep 10, 2020 · Updated Sep 16, 2024
Critical · CVSS 9.8
All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function.
Published Sep 1, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.1
Improper Access Control vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to bypass security mechanisms and deny access to the SYSTEM folder via incorrectly applied permissions.
Published Sep 9, 2020 · Updated Sep 16, 2024
Low · CVSS 3.1
IBM Security Secret Server prior to 10.9 could allow an attacker to bypass SSL security due to improper certificate validation. IBM X-Force ID: 178180.
Published Sep 23, 2020 · Updated Sep 16, 2024
Medium · CVSS 5.4
IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 184928.
Published Sep 22, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.8
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields. These scripts may be executed in a victim’s browser when search queries return the page containing the vulnerable field.
Published Sep 10, 2020 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). After resuming from S3 sleep mode in various versions of BIOS for some Lenovo ThinkPad systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected.
Published Sep 1, 2020 · Updated Sep 16, 2024
High · CVSS 7.2
IBM API Connect's API Manager 2018.4.1.0 through 2018.4.1.12 is vulnerable to privilege escalation. An invitee to an API Provider organization can escalate privileges by manipulating the invitation link. IBM X-Force ID: 185508.
Published Sep 3, 2020 · Updated Sep 16, 2024
Low · CVSS 2.9
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensitive information from a detailed technical error message. This information could be used in further attacks against the system. IBM X-Force ID: 185370.
Published Sep 30, 2020 · Updated Sep 16, 2024
High · CVSS 7.5
This affects all versions of package github.com/u-root/u-root/pkg/uzip. It is vulnerable to both leading and non-leading relative path traversal attacks in zip file extraction.
Published Sep 1, 2020 · Updated Sep 16, 2024
Critical · CVSS 9.8
All versions of package tiny-conf are vulnerable to Prototype Pollution via the set function.
Published Sep 1, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.8
Dell Inspiron 7347 BIOS versions prior to A13 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in System Management Mode (SMM).
Published Sep 2, 2020 · Updated Sep 16, 2024
Critical · CVSS 9.8
All versions of package worksmith are vulnerable to Prototype Pollution via the setValue function.
Published Sep 1, 2020 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affected versions are before version 7.13.7, from version 8.0.0 before 8.5.8, and from version 8.6.0 before 8.12.0.
Published Sep 1, 2020 · Updated Sep 16, 2024
Critical · CVSS 9.8
A buffer overflow vulnerability in PAN-OS allows an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface. This issue impacts: All versions of PAN-OS 8.0; PAN-OS 8.1 versions earlier than PAN-OS 8.1.15; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9; PAN-OS 9.1 versions earlier than PAN-OS 9.1.3.
Published Sep 9, 2020 · Updated Sep 16, 2024
High · CVSS 7.8
IBM Aspera Connect 3.9.9 could allow a remote attacker to execute arbitrary code on the system, caused by improper loading of Dynamic Link Libraries by the import feature. By persuading a victim to open a specially-crafted .DLL file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183190.
Published Sep 4, 2020 · Updated Sep 16, 2024
Critical · CVSS 9.8
All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions.
Published Sep 1, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.1
Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory locations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Published Sep 18, 2020 · Updated Sep 16, 2024
Low · CVSS 3.2
An improper Input Validation vulnerability in the code handling file renaming and recovery in Bitdefender Engines allows an attacker to write an arbitrary file in a location hardcoded in a specially-crafted malicious file name. This issue affects: Bitdefender Engines versions prior to 7.85448.
Published Sep 30, 2020 · Updated Sep 16, 2024
Critical · CVSS 9
The AEM forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
Published Sep 10, 2020 · Updated Sep 16, 2024