LiveActive security incident?Get immediate response
CVE archive

September 2020

Browse CVE records published in September 2020, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1721 matching CVEs · Page 5 of 35.

High · CVSS 7.1

CVE-2020-7729: Arbitrary Code Execution

The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.

Published Sep 3, 2020 · Updated Sep 17, 2024

Critical · CVSS 9.8

CVE-2020-7719: Prototype Pollution

Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.

Published Sep 1, 2020 · Updated Sep 17, 2024

Medium · CVSS 6.9

CVE-2020-7323: Authentication Protection Bypass vulnerability in ENS for Windows

Authentication Protection Bypass vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows physical local users to bypass the Windows lock screen via triggering certain detection events while the computer screen is locked and the McTray.exe is running with elevated privileges. This issue is timing dependent and requires physical access to the machine.

Published Sep 9, 2020 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2020-14180: Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticate...

Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticated as a non-administrator user to view Project Request-Types and Descriptions, via an Information Disclosure vulnerability in the editform request-type-fields resource. The affected versions are before version 4.12.0.

Published Sep 21, 2020 · Updated Sep 17, 2024

Medium · CVSS 6.3

CVE-2020-8340: A cross-site scripting (XSS) vulnerability was discovered in the legacy IBM and Lenovo System x IMM2 (Integ...

A cross-site scripting (XSS) vulnerability was discovered in the legacy IBM and Lenovo System x IMM2 (Integrated Management Module 2), prior to version 5.60, embedded Baseboard Management Controller (BMC) web interface during an internal security review. This vulnerability could allow JavaScript code to be executed in the user's web browser if the user is convinced to visit a crafted URL, possibly through phishing. Successful exploitation requires specific knowledge about the user’s network to be included in the crafted URL. Impact is limited to the normal access restrictions and permissions of the user clicking the crafted URL, and subject to the user being able to connect to and already being authenticated to IMM2 or other systems. The JavaScript code is not executed on IMM2 itself.

Published Sep 15, 2020 · Updated Sep 17, 2024

Critical · CVSS 9

CVE-2020-9732: Stored XSS in AEM Sites Components

The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Sites component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.

Published Sep 10, 2020 · Updated Sep 17, 2024

Medium · CVSS 5.4

CVE-2020-4530: IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are vulnerable to...

IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-ForceID: 182714.

Published Sep 15, 2020 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2020-14177: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application...

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Regex-based Denial of Service (DoS) vulnerability in JQL version searching. The affected versions are before version 7.13.16; from version 7.14.0 before 8.5.7; from version 8.6.0 before 8.10.2; and from version 8.11.0 before 8.11.1.

Published Sep 21, 2020 · Updated Sep 17, 2024

High · CVSS 7.2

CVE-2020-2042: PAN-OS: Buffer overflow in the management web interface

A buffer overflow vulnerability in the PAN-OS management web interface allows authenticated administrators to disrupt system processes and potentially execute arbitrary code with root privileges. This issue impacts only PAN-OS 10.0 versions earlier than PAN-OS 10.0.1.

Published Sep 9, 2020 · Updated Sep 17, 2024

Medium · CVSS 6.4

CVE-2020-4698: IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnera...

IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186841.

Published Sep 8, 2020 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2020-16242: GE Reason S20 Ethernet Switch

The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow an attacker to trick application users into performing critical application actions that include, but are not limited to, adding and updating accounts.

Published Sep 25, 2020 · Updated Sep 17, 2024

Medium · CVSS 4.8

CVE-2020-7068: Use of freed hash key in the phar_parse_zipfile function

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

Published Sep 9, 2020 · Updated Sep 17, 2024

High · CVSS 8.2

CVE-2020-7314: Privilege Escalation vulnerability in McAfee DXL for Mac

Privilege Escalation Vulnerability in the installer in McAfee Data Exchange Layer (DXL) Client for Mac shipped with McAfee Agent (MA) for Mac prior to MA 5.6.6 allows local users to run commands as root via incorrectly applied permissions on temporary files.

Published Sep 10, 2020 · Updated Sep 17, 2024

Critical · CVSS 9.1

CVE-2020-12506: WAGO: Authentication Bypass Vulnerability in WAGO 750-36X and WAGO 750-8XX Versions <= FW03

Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by sending specifically constructed requests without authentication This issue affects: WAGO 750-362, WAGO 750-363, WAGO 750-823, WAGO 750-832/xxx-xxx, WAGO 750-862, WAGO 750-891, WAGO 750-890/xxx-xxx in versions FW03 and prior versions.

Published Sep 30, 2020 · Updated Sep 17, 2024

Critical · CVSS 9.8

CVE-2020-7726: Prototype Pollution

All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function.

Published Sep 1, 2020 · Updated Sep 17, 2024

Critical · CVSS 9.8

CVE-2020-7717: Prototype Pollution

All versions of package dot-notes are vulnerable to Prototype Pollution via the create function.

Published Sep 1, 2020 · Updated Sep 16, 2024

High · CVSS 7.8

CVE-2020-9728: Out-of-bounds memory access could lead to code execution

A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.

Published Sep 10, 2020 · Updated Sep 16, 2024

Critical · CVSS 9.8

CVE-2020-7722: Prototype Pollution

All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function.

Published Sep 1, 2020 · Updated Sep 16, 2024

Medium · CVSS 5.4

CVE-2020-4615: IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site scripting.

IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 184928.

Published Sep 22, 2020 · Updated Sep 16, 2024

Medium · CVSS 6.8

CVE-2020-9735: Stored XSS in AEM's Content Repository Development Environment

AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields. These scripts may be executed in a victim’s browser when search queries return the page containing the vulnerable field.

Published Sep 10, 2020 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2020-8341: In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash.

In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). After resuming from S3 sleep mode in various versions of BIOS for some Lenovo ThinkPad systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected.

Published Sep 1, 2020 · Updated Sep 16, 2024

Critical · CVSS 9.8

CVE-2020-7724: Prototype Pollution

All versions of package tiny-conf are vulnerable to Prototype Pollution via the set function.

Published Sep 1, 2020 · Updated Sep 16, 2024

Critical · CVSS 9.8

CVE-2020-7725: Prototype Pollution

All versions of package worksmith are vulnerable to Prototype Pollution via the setValue function.

Published Sep 1, 2020 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2020-14178: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys...

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affected versions are before version 7.13.7, from version 8.0.0 before 8.5.8, and from version 8.6.0 before 8.12.0.

Published Sep 1, 2020 · Updated Sep 16, 2024

Critical · CVSS 9.8

CVE-2020-2040: PAN-OS: Buffer overflow when Captive Portal or Multi-Factor Authentication (MFA) is enabled

A buffer overflow vulnerability in PAN-OS allows an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface. This issue impacts: All versions of PAN-OS 8.0; PAN-OS 8.1 versions earlier than PAN-OS 8.1.15; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9; PAN-OS 9.1 versions earlier than PAN-OS 9.1.3.

Published Sep 9, 2020 · Updated Sep 16, 2024

High · CVSS 7.8

CVE-2020-4545: IBM Aspera Connect 3.9.9 could allow a remote attacker to execute arbitrary code on the system, caused by i...

IBM Aspera Connect 3.9.9 could allow a remote attacker to execute arbitrary code on the system, caused by improper loading of Dynamic Link Libraries by the import feature. By persuading a victim to open a specially-crafted .DLL file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183190.

Published Sep 4, 2020 · Updated Sep 16, 2024

Critical · CVSS 9.8

CVE-2020-7718: Prototype Pollution

All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions.

Published Sep 1, 2020 · Updated Sep 16, 2024

Medium · CVSS 6.1

CVE-2020-9745: Adobe Media Encoder PSD File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory locations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

Published Sep 18, 2020 · Updated Sep 16, 2024

Low · CVSS 3.2

CVE-2020-15731: Local Privilege Escalation in Bitdefender Engines (VA-8953)

An improper Input Validation vulnerability in the code handling file renaming and recovery in Bitdefender Engines allows an attacker to write an arbitrary file in a location hardcoded in a specially-crafted malicious file name. This issue affects: Bitdefender Engines versions prior to 7.85448.

Published Sep 30, 2020 · Updated Sep 16, 2024

Critical · CVSS 9

CVE-2020-9741: Stored XSS in AEM Forms Components

The AEM forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.

Published Sep 10, 2020 · Updated Sep 16, 2024