IT
56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.855 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-3170 MED 5.3 cisco nx-os A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart. The vulnerability is due to incorrect validation of the HTTP header of a request that is se 1.7%
CVE-2020-3164 MED 5.3 cisco cloud_email_security A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated remote attacker to cause h 1.3%
CVE-2020-3160 MED 5.3 cisco meeting_server A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) feature of Cisco Meeting Server software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition for users of XMPP conferencing applications. Other ap 1.2%
CVE-2020-3139 MED 5.3 cisco application_policy_infrastructure_controller A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Infrastructure Controller (APIC) could allow an unauthenticated, remote attacker to bypass configured deny entries for specific IP ports. These 1.0%
CVE-2020-3122 MED 5.3 cisco asyncos A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to obtain sensitive network information. 0.4%
CVE-2020-29019 MED 5.3 fortinet fortiweb A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow a remote, unauthenticated attacker to crash the httpd daemon thread by sending a request with a crafted cookie header. 2.1%
CVE-2020-26235 MED 5.3 time_project time In Rust time crate from version 0.2.7 and before version 0.2.23, unix-like operating systems may segfault due to dereferencing a dangling pointer in specific circumstances. This requires the user to set any environment variable in a different thread than the a 1.6%
CVE-2020-26139 MED 5.3 arista c-100_firmware An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-servi 6.5%
CVE-2020-26062 MED 5.3 cisco unified_computing_system A vulnerability in Cisco Integrated Management Controller could allow an unauthenticated, remote attacker to enumerate valid usernames within the vulnerable application. The vulnerability is due to differences in authentication responses sent back from t 0.8%
CVE-2020-2039 MED 5.3 paloaltonetworks pan-os An uncontrolled resource consumption vulnerability in Palo Alto Networks PAN-OS allows for a remote unauthenticated user to upload temporary files through the management web interface that are not properly deleted after the request is finished. It is possible 46.4%
CVE-2020-2033 MED 5.3 paloaltonetworks globalprotect When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authentication cookie to a man-in-the-middle attacker on the same local area network segment with the ability to manipu 0.8%
CVE-2020-1999 MED 5.3 paloaltonetworks pan-os A vulnerability exists in the Palo Alto Network PAN-OS signature-based threat detection engine that allows an attacker to communicate with devices in the network in a way that is not analyzed for threats by sending data through specifically crafted TCP packets 1.3%
CVE-2020-1997 MED 5.3 paloaltonetworks pan-os An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to specify an arbitrary redirection target away from the trusted GlobalProtect gateway. If the user then successfully authenticates it will cause t 0.9%
CVE-2020-1996 MED 5.3 paloaltonetworks pan-os A missing authorization vulnerability in the management server component of PAN-OS Panorama allows a remote unauthenticated user to inject messages into the management server ms.log file. This vulnerability can be leveraged to obfuscate an ongoing attack or fa 0.9%
CVE-2020-1954 MED 5.3 apache cxf Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in- 6.1%
CVE-2020-1934 MED 5.3 apache http_server In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server. 52.0%
CVE-2020-1928 MED 5.3 apache nifi An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal values entered in a sensitive property when no parameter was present. 4.0%
CVE-2020-17513 MED 5.3 apache airflow In Apache Airflow versions prior to 1.10.13, the Charts and Query View of the old (Flask-admin based) UI were vulnerable for SSRF attack. 4.3%
CVE-2020-17120 MED 5.3 microsoft sharepoint_foundation Microsoft SharePoint Information Disclosure Vulnerability 2.9%
CVE-2020-17090 MED 5.3 microsoft windows_10 Microsoft Defender for Endpoint Security Feature Bypass Vulnerability 3.3%
CVE-2020-17017 MED 5.3 microsoft sharepoint_enterprise_server Microsoft SharePoint Information Disclosure Vulnerability 3.8%
CVE-2020-16979 MED 5.3 microsoft sharepoint_enterprise_server Microsoft SharePoint Information Disclosure Vulnerability 3.1%
CVE-2020-16922 MED 5.3 microsoft windows_10 <p>A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files.</p> <p>In an attack scenario, an attacker could by 0.8%
CVE-2020-16904 MED 5.3 microsoft azure_functions <p>An elevation of privilege vulnerability exists in the way Azure Functions validate access keys.</p> <p>An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization.</p> <p>This security 3.4%
CVE-2020-16886 MED 5.3 microsoft powershellget <p>A security feature bypass vulnerability exists in the PowerShellGet V2 module. An attacker who successfully exploited this vulnerability could bypass WDAC (Windows Defender Application Control) policy and execute arbitrary code on a policy locked-down machi 0.8%