58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2020-9418 | HIGH 7.8 | redsoftware pdfescape An untrusted search path vulnerability in the installer of PDFescape Desktop version 4.0.22 and earlier allows an attacker to gain privileges and execute code via DLL hijacking. | 0.4% | — |
| CVE-2020-9391 | MED 5.5 | fedoraproject fedora An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to move upwar | 0.5% | — |
| CVE-2020-9383 | HIGH 7.1 | canonical ubuntu_linux An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it, aka CID-2e90ca68b0d2. | 0.8% | — |
| CVE-2020-9345 | MED 6.5 | signotec signopad-api\/web An issue was discovered in signotec signoPAD-API/Web (formerly Websocket Pad Server) before 3.1.1 on Windows. It is possible to perform a Denial of Service attack because the application doesn't limit the number of opened WebSocket sockets. If a victim visits | 0.9% | — |
| CVE-2020-9343 | MED 6.5 | signotec signopad-api\/web An issue was discovered in signotec signoPAD-API/Web (formerly Websocket Pad Server) before 3.1.1 on Windows. It is possible to perform a Denial of Service attack because the implementation doesn't limit the parsing of nested JSON structures. If a victim visit | 0.9% | — |
| CVE-2020-9295 | MED 4.7 | fortinet antivirus_engine FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6.00144 and below and FortiClient 6.2 running AV engine version 6.00137 and below may not immediately detect certain types of malformed or non-standard RAR archives, | 0.3% | — |
| CVE-2020-9294 | CRIT 9.8 | fortinet fortimail An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a legitimate user by requesting a password change via the user i | 77.8% | — |
| CVE-2020-9292 | CRIT 9.8 | fortinet fortisiem_windows_agent An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the AoWinAgt executable service path. | 1.5% | — |
| CVE-2020-9291 | MED 6.3 | fortinet forticlient An Insecure Temporary File vulnerability in FortiClient for Windows 6.2.1 and below may allow a local user to gain elevated privileges via exhausting the pool of temporary file names combined with a symbolic link attack. | 0.5% | — |
| CVE-2020-9290 | HIGH 7.8 | fortinet forticlient An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attacker with control over the directory in which FortiClientOnlineInstaller.exe and FortiClientVPNOnlineInstaller.exe resides to execute arbitrar | 0.6% | — |
| CVE-2020-9289 | HIGH 7.5 | fortinet fortianalyzer Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below may allow an attacker with access to the CLI configuration or the CLI backup file to decrypt the sensitive data, | 2.2% | — |
| CVE-2020-9288 | MED 5.4 | fortinet fortiwlc An improper neutralization of input vulnerability in FortiWLC 8.5.1 allows a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the ESS profile or the Radius Profile. | 0.9% | — |
| CVE-2020-9287 | HIGH 7.8 | fortinet forticlient_emergency_management_server An Unsafe Search Path vulnerability in FortiClient EMS online installer 6.2.1 and below may allow a local attacker with control over the directory in which FortiClientEMSOnlineInstaller.exe resides to execute arbitrary code on the system via uploading maliciou | 0.6% | — |
| CVE-2020-9286 | MED 6.5 | fortinet fortiadc_firmware An improper authorization vulnerability in FortiADC may allow a remote authenticated user with low privileges to perform certain actions such as rebooting the system. | 1.2% | — |
| CVE-2020-8992 | MED 5.5 | canonical ubuntu_linux ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size. | 0.4% | — |
| CVE-2020-8983 | HIGH 7.5 | citrix sharefile_storagezones_controller An arbitrary file write issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, which allows remote code execution. RCE and file access is granted to everything hos | 4.6% | — |
| CVE-2020-8982 | HIGH 7.5 | citrix sharefile_storagezones_controller An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020. RCE and file access is granted to everything hosted by ShareFile, be | 27.1% | — |
| CVE-2020-8956 | LOW 3.3 | pulsesecure pulse_secure_desktop Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled. | 1.2% | — |
| CVE-2020-8950 | HIGH 7.8 | amd user_experience_program The AUEPLauncher service in Radeon AMD User Experience Program Launcher through 1.0.0.1 on Windows allows elevation of privilege by placing a crafted file in %PROGRAMDATA%\AMD\PPC\upload and then creating a symbolic link in %PROGRAMDATA%\AMD\PPC\temp that poin | 1.0% | — |
| CVE-2020-8927 | MED 5.3 | canonical ubuntu_linux A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is | 3.2% | — |
| CVE-2020-8883 | MED 4.3 | foxitsoftware foxit_studio_photo This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.916. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a maliciou | 8.4% | — |
| CVE-2020-8882 | HIGH 8.8 | foxitsoftware foxit_studio_photo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.916. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | 11.1% | — |
| CVE-2020-8881 | HIGH 8.8 | foxitsoftware foxit_studio_photo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.916. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | 11.1% | — |
| CVE-2020-8880 | HIGH 8.8 | foxitsoftware foxit_studio_photo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.916. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | 11.1% | — |
| CVE-2020-8879 | MED 4.3 | foxitsoftware foxit_studio_photo This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.916. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a maliciou | 8.2% | — |