57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-3753 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a stack exhaustion vulnerability. Successful exploitation could lead to memory leak . | 2.2% | — |
| CVE-2020-3747 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure . | 2.7% | — |
| CVE-2020-3744 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure . | 8.9% | — |
| CVE-2020-37267 | HIGH 7.5 | Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because the git http.extraheader=AUTHORIZATION parameter is logged without redaction. Anyone with access to saved logs c | 0.3% | — |
| CVE-2020-36767 | HIGH 7.5 | vareille tinyfiledialogs tinyfiledialogs (aka tiny file dialogs) before 3.8.0 allows shell metacharacters in titles, messages, and other input data. | 0.4% | — |
| CVE-2020-36281 | HIGH 7.5 | debian debian_linux Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c. | 2.9% | — |
| CVE-2020-36279 | HIGH 7.5 | debian debian_linux Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptmap.c. | 2.6% | — |
| CVE-2020-36278 | HIGH 7.5 | debian debian_linux Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c. | 2.9% | — |
| CVE-2020-36277 | HIGH 7.5 | debian debian_linux Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c. | 2.4% | — |
| CVE-2020-36230 | HIGH 7.5 | apache bookkeeper A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service. | 12.3% | — |
| CVE-2020-3574 | HIGH 7.5 | cisco ip_dect_210_firmware A vulnerability in the TCP packet processing functionality of Cisco IP Phones could allow an unauthenticated, remote attacker to cause the phone to stop responding to incoming calls, drop connected calls, or unexpectedly reload. The vulnerability is due to ins | 8.0% | — |
| CVE-2020-3554 | HIGH 7.5 | cisco adaptive_security_appliance A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected devic | 2.7% | — |
| CVE-2020-3452 | HIGH 7.5 | cisco adaptive_security_appliance_software A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files | 100.0% | |
| CVE-2020-3444 | HIGH 7.5 | cisco ios_xe A vulnerability in the packet filtering features of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to bypass L3 and L4 traffic filters. The vulnerability is due to improper traffic filtering conditions on an affected device. An attacker | 1.5% | — |
| CVE-2020-3426 | HIGH 7.5 | cisco ios A vulnerability in the implementation of the Low Power, Wide Area (LPWA) subsystem of Cisco IOS Software for Cisco 800 Series Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an unauthe | 2.2% | — |
| CVE-2020-3422 | HIGH 7.5 | cisco ios_xe A vulnerability in the IP Service Level Agreement (SLA) responder feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the IP SLA responder to reuse an existing port, resulting in a denial of service (DoS) condition. The vu | 1.3% | — |
| CVE-2020-3411 | HIGH 7.5 | cisco catalyst_center A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker access to sensitive information on an affected system. The vulnerability is due to improper handling of authentication tokens by the affected software. An attacker coul | 2.2% | — |
| CVE-2020-3402 | HIGH 7.5 | cisco unified_customer_voice_portal A vulnerability in the Java Remote Method Invocation (RMI) interface of Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability exists because certain RM | 1.6% | — |
| CVE-2020-3392 | HIGH 7.5 | cisco iot_field_network_director A vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive information on an affected system. The vulnerability exists because the affected software does not properly authenticate API | 1.5% | — |
| CVE-2020-3369 | HIGH 7.5 | cisco sd-wan_firmware A vulnerability in the deep packet inspection (DPI) engine of Cisco SD-WAN vEdge Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper processing of FTP | 1.4% | — |
| CVE-2020-3341 | HIGH 7.5 | canonical ubuntu_linux A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a stack buf | 3.4% | — |
| CVE-2020-3338 | HIGH 7.5 | cisco nx-os A vulnerability in the Protocol Independent Multicast (PIM) feature for IPv6 networks (PIM6) of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to | 1.8% | — |
| CVE-2020-3327 | HIGH 7.5 | canonical ubuntu_linux A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a heap buffer overf | 5.1% | — |
| CVE-2020-3317 | HIGH 7.5 | cisco secure_firewall_threat_defense A vulnerability in the ssl_inspection component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to crash Snort instances. The vulnerability is due to insufficient input validation in the ssl_inspection component | 1.0% | — |
| CVE-2020-3312 | HIGH 7.5 | cisco secure_firewall_management_center A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data on an affected device. The vulnerability is due to insuf | 1.1% | — |