Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In October 2020
A logic issue was addressed with improved validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5. An application may be able to gain elevated privileges.
CVSS Score
7.8
EPSS Score
0.003
Published
2020-10-22
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. An application may be able to execute arbitrary code with kernel privileges.
CVSS Score
7.8
EPSS Score
0.005
Published
2020-10-22
tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.
CVSS Score
9.8
EPSS Score
0.911
Published
2020-10-22
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. An application may be able to gain elevated privileges.
CVSS Score
7.8
EPSS Score
0.001
Published
2020-10-22
An issue was discovered in Octopus Deploy through 2020.4.4. If enabled, the websocket endpoint may allow an untrusted tentacle host to present itself as a trusted one.
CVSS Score
7.5
EPSS Score
0.004
Published
2020-10-22
HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or artifact stanzas. Fixed in 0.12.6, 0.11.5, and 0.10.6
CVSS Score
9.1
EPSS Score
0.004
Published
2020-10-22
Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex queries. This could result in the search disclosing the existence of documents the attacker should not be able to view. This could result in an attacker gaining additional insight into potentially sensitive indices.
CVSS Score
3.1
EPSS Score
0.001
Published
2020-10-22
AtomXCMS 2.0 is affected by Incorrect Access Control via admin/dump.php
CVSS Score
8.1
EPSS Score
0.002
Published
2020-10-22
AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php
CVSS Score
5.3
EPSS Score
0.002
Published
2020-10-22
A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.
CVSS Score
5.4
EPSS Score
0.005
Published
2020-10-22


Contact Us

Shodan ® - All rights reserved