IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-3941 HIGH 7.0 vmware tools The repair operation of VMware Tools for Windows 10.x.y has a race condition which may allow for privilege escalation in the Virtual Machine where Tools is installed. This vulnerability is not present in VMware Tools 11.x.y since the affected functionality is 0.3%
CVE-2020-29370 HIGH 7.0 linux linux_kernel An issue was discovered in kmem_cache_alloc_bulk in mm/slub.c in the Linux kernel before 5.5.11. The slowpath lacks the required TID increment, aka CID-fd4d9c7d0c71. 0.6%
CVE-2020-29369 HIGH 7.0 linux linux_kernel An issue was discovered in mm/mmap.c in the Linux kernel before 5.7.11. There is a race condition between certain expand functions (expand_downwards and expand_upwards) and page-table free operations from an munmap call, aka CID-246c320a8cfe. 0.5%
CVE-2020-29368 HIGH 7.0 linux linux_kernel An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check, aka CID-c444eb564fb1. 0.4%
CVE-2020-28912 HIGH 7.0 mariadb mariadb With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining 0.4%
CVE-2020-28209 HIGH 7.0 schneider-electric enterprise_server_installer A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one 0.3%
CVE-2020-28169 HIGH 7.0 debian debian_linux The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account, but a file in bin is executed as NT AUTHORITY\SYSTEM. 1.2%
CVE-2020-27216 HIGH 7.0 apache beam In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the pro 4.4%
CVE-2020-25668 HIGH 7.0 debian debian_linux A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op. 1.0%
CVE-2020-25212 HIGH 7.0 canonical ubuntu_linux A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c, aka CID-b4487b93545 0.3%
CVE-2020-24447 HIGH 7.0 adobe lightroom Adobe Lightroom Classic version 10.0 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in th 0.8%
CVE-2020-24440 HIGH 7.0 adobe prelude Adobe Prelude version 9.0.1 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal 0.6%
CVE-2020-24424 HIGH 7.0 adobe premiere_pro Adobe Premiere Pro version 14.4 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a 1.2%
CVE-2020-24423 HIGH 7.0 adobe media_encoder Adobe Media Encoder version 14.4 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a 1.2%
CVE-2020-24420 HIGH 7.0 adobe photoshop Adobe Photoshop for Windows version 21.2.1 (and earlier) is affected by an uncontrolled search path element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in 0.8%
CVE-2020-24419 HIGH 7.0 adobe after_effects Adobe After Effects version 17.1.1 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that 0.7%
CVE-2020-2032 HIGH 7.0 paloaltonetworks globalprotect A race condition vulnerability Palo Alto Networks GlobalProtect app on Windows allows a local limited Windows user to execute programs with SYSTEM privileges. This issue can be exploited only while performing a GlobalProtect app upgrade. This issue affects: Gl 0.2%
CVE-2020-2016 HIGH 7.0 paloaltonetworks pan-os A race condition due to insecure creation of a file in a temporary directory vulnerability in PAN-OS allows for root privilege escalation from a limited linux user account. This allows an attacker who has escaped the restricted shell as a low privilege adminis 0.6%
CVE-2020-1989 HIGH 7.0 paloaltonetworks globalprotect An incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks Global Protect Agent for Linux on ARM platform allows a local authenticated user to gain root privileges on the system. This issue affects Palo Al 0.3%
CVE-2020-1981 HIGH 7.0 paloaltonetworks pan-os A predictable temporary filename vulnerability in PAN-OS allows local privilege escalation. This issue allows a local attacker who bypassed the restricted shell to execute commands as a low privileged user and gain root access on the PAN-OS hardware or virtual 0.4%
CVE-2020-17534 HIGH 7.0 apache html\/java_api There exists a race condition between the deletion of the temporary file and the creation of the temporary directory in `webkit` subproject of HTML/Java API version 1.7. A similar vulnerability has recently been disclosed in other Java projects and the fix in 0.4%
CVE-2020-17103 HIGH 7.0 microsoft windows_10 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 26.5%
CVE-2020-17057 HIGH 7.0 microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability 1.9%
CVE-2020-17007 HIGH 7.0 microsoft windows_10 Windows Error Reporting Elevation of Privilege Vulnerability 0.8%
CVE-2020-16998 HIGH 7.0 microsoft windows_10 DirectX Elevation of Privilege Vulnerability 0.9%