56.560 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
CVE Tracker
56.560 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2020-5902 | CRIT 9.8 | ransomware f5 big-ip_access_policy_manager In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclo | 100.0% | |
| CVE-2020-4006 | CRIT 9.1 | vmware cloud_foundation VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. | 23.8% | |
| CVE-2020-3992 | CRIT 9.8 | ransomware vmware cloud_foundation OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine | 83.0% | |
| CVE-2020-3952 | CRIT 9.8 | vmware vcenter_server Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls. | 90.4% | |
| CVE-2020-3950 | HIGH 7.8 | vmware fusion VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitatio | 7.3% | |
| CVE-2020-3580 | MED 6.1 | ransomware cisco adaptive_security_appliance_software Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a | 85.6% | |
| CVE-2020-3569 | HIGH 8.6 | cisco ios_xr Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immediately crash the Internet Group Management Protocol (IGMP) process or make it con | 3.3% | |
| CVE-2020-3566 | HIGH 8.6 | cisco ios_xr A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue managemen | 3.7% | |
| CVE-2020-3452 | HIGH 7.5 | cisco adaptive_security_appliance_software A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files | 100.0% | |
| CVE-2020-3161 | CRIT 9.8 | cisco 8831_firmware A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to | 83.7% | |
| CVE-2020-3118 | HIGH 8.8 | cisco ios_xr A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of str | 11.7% | |
| CVE-2020-24557 | HIGH 7.8 | trendmicro apex_one A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function and attain privilege e | 2.6% | |
| CVE-2020-17530 | CRIT 9.8 | apache struts Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25. | 95.6% | |
| CVE-2020-17144 | HIGH 8.4 | microsoft exchange_server Microsoft Exchange Remote Code Execution Vulnerability | 36.5% | |
| CVE-2020-17087 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Local Elevation of Privilege Vulnerability | 5.4% | |
| CVE-2020-16009 | HIGH 8.8 | cefsharp cefsharp Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 48.6% | |
| CVE-2020-1472 | MED 5.5 | ransomware canonical ubuntu_linux An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run | 99.5% | |
| CVE-2020-1464 | HIGH 7.8 | microsoft windows_10_1507 A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass secur | 41.1% | |
| CVE-2020-1380 | HIGH 7.8 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current u | 24.2% | |
| CVE-2020-1350 | CRIT 10.0 | microsoft windows_server_2008 A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'. | 91.4% | |
| CVE-2020-12812 | CRIT 9.8 | ransomware fortinet fortios An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of | 49.3% | |
| CVE-2020-11652 | MED 6.5 | blackberry workspaces_server An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users. | 86.2% | |
| CVE-2020-11651 | CRIT 9.8 | canonical ubuntu_linux An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be us | 96.6% | |
| CVE-2020-1147 | HIGH 7.8 | microsoft .net_core A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulner | 94.3% | |
| CVE-2020-1054 | HIGH 7.0 | microsoft windows_10_1507 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then | 52.8% |