IT
58.352 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.352 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2020-17513 MED 5.3 apache airflow In Apache Airflow versions prior to 1.10.13, the Charts and Query View of the old (Flask-admin based) UI were vulnerable for SSRF attack. 4.4% —
CVE-2020-17511 MED 6.5 apache airflow In Airflow versions prior to 1.10.13, when creating a user using airflow CLI, the password gets logged in plain text in the Log table in Airflow Metadatase. Same happened when creating a Connection with a password field. 2.6% —
CVE-2020-17510 CRIT 9.8 apache shiro Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. 8.2% —
CVE-2020-17509 HIGH 7.5 apache traffic_server ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected. 1.8% —
CVE-2020-17508 HIGH 7.5 apache traffic_server The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected. 2.0% —
CVE-2020-1749 HIGH 7.5 linux linux_kernel A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tunnels over IPv6. When an encrypted tunnel is created between two hosts, the kernel isn't correctly routing tunneled data over the encrypted 1.2% —
CVE-2020-17417 HIGH 7.8 foxitsoftware foxit_reader This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.0.1.35811. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The 9.1% —
CVE-2020-17416 HIGH 7.8 foxitsoftware foxit_reader This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.0.0.35798. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The 9.1% —
CVE-2020-17415 HIGH 7.8 foxitsoftware foxit_reader This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PhantomPDF 10.0.0.35798. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. T 2.1% —
CVE-2020-17414 HIGH 7.8 foxitsoftware foxit_reader This vulnerability allows local attackers to escalate privileges on affected installations of Foxit Reader 10.0.0.35798. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The s 1.9% —
CVE-2020-17413 HIGH 7.8 foxitsoftware 3d This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.0.0.35798. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. 4.2% —
CVE-2020-17412 HIGH 7.8 foxitsoftware 3d This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.0.0.35798. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. 4.2% —
CVE-2020-17411 LOW 3.3 foxitsoftware 3d This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 10.0.0.35798. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio 3.1% —
CVE-2020-17410 HIGH 7.8 foxitsoftware foxit_reader This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.0.0.35798. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. 9.1% —
CVE-2020-17404 HIGH 7.8 foxitsoftware foxit_studio_photo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. 4.3% —
CVE-2020-17403 HIGH 7.8 foxitsoftware foxit_studio_photo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. 4.3% —
CVE-2020-17163 HIGH 7.8 microsoft python Visual Studio Code Python Extension Remote Code Execution Vulnerability 0.6% —
CVE-2020-17162 HIGH 8.8 microsoft windows_10 Microsoft Windows Security Feature Bypass Vulnerability 2.4% —
CVE-2020-17158 HIGH 8.8 microsoft dynamics_365 Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability 3.0% —
CVE-2020-17156 HIGH 7.8 microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability 3.1% —
CVE-2020-17153 MED 4.3 microsoft edge Microsoft Edge for Android Spoofing Vulnerability 2.2% —
CVE-2020-17152 HIGH 8.8 microsoft dynamics_365 Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability 3.0% —
CVE-2020-17150 HIGH 7.8 microsoft tslint Visual Studio Code Remote Code Execution Vulnerability 3.2% —
CVE-2020-17148 HIGH 7.8 microsoft visual_studio_code Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability 3.8% —
CVE-2020-17147 HIGH 8.7 microsoft dynamics_365 Dynamics CRM Webclient Cross-site Scripting Vulnerability 1.4% —