56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.855 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-17532 | HIGH 8.8 | apache java_chassis When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The problem happens in versions between 2.0.0 ~ 2.1.3 and fixed in Apache ServiceComb-Java-Chassis 2.1.5 | 3.2% | — |
| CVE-2020-17162 | HIGH 8.8 | microsoft windows_10 Microsoft Windows Security Feature Bypass Vulnerability | 2.2% | — |
| CVE-2020-17158 | HIGH 8.8 | microsoft dynamics_365 Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2020-17152 | HIGH 8.8 | microsoft dynamics_365 Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2020-17143 | HIGH 8.8 | microsoft exchange_server Microsoft Exchange Server Information Disclosure Vulnerability | 70.6% | — |
| CVE-2020-17121 | HIGH 8.8 | microsoft sharepoint_foundation Microsoft SharePoint Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2020-17061 | HIGH 8.8 | microsoft sharepoint_foundation Microsoft SharePoint Remote Code Execution Vulnerability | 4.3% | — |
| CVE-2020-17042 | HIGH 8.8 | microsoft windows_10 Windows Print Spooler Remote Code Execution Vulnerability | 5.1% | — |
| CVE-2020-16911 | HIGH 8.8 | microsoft windows_10 <p>A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could th | 4.5% | — |
| CVE-2020-16898 | HIGH 8.8 | microsoft windows_10 <p>A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could gain the ability to execute code on the target server or clien | 10.9% | — |
| CVE-2020-16891 | HIGH 8.8 | microsoft windows_10 <p>A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application o | 0.9% | — |
| CVE-2020-1673 | HIGH 8.8 | juniper junos Insufficient Cross-Site Scripting (XSS) protection in Juniper Networks J-Web and web based (HTTP/HTTPS) services allows an unauthenticated attacker to hijack the target user's HTTP/HTTPS session and perform administrative actions on the Junos device as the tar | 1.6% | — |
| CVE-2020-1656 | HIGH 8.8 | juniper junos The DHCPv6 Relay-Agent service, part of the Juniper Enhanced jdhcpd daemon shipped with Juniper Networks Junos OS has an Improper Input Validation vulnerability which will result in a Denial of Service (DoS) condition when a DHCPv6 client sends a specific DHPC | 1.1% | — |
| CVE-2020-1631 | HIGH 8.8 | juniper junos A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform local file inclusion (LFI) | 4.7% | |
| CVE-2020-1609 | HIGH 8.8 | juniper junos When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv6 packets who may then arbitrarily execute comma | 0.9% | — |
| CVE-2020-1605 | HIGH 8.8 | juniper junos When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv4 packets who may then arbitrarily execute comma | 0.8% | — |
| CVE-2020-16022 | HIGH 8.8 | google chrome Insufficient policy enforcement in networking in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially bypass firewall controls via a crafted HTML page. | 0.8% | — |
| CVE-2020-16009 | HIGH 8.8 | cefsharp cefsharp Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 48.3% | |
| CVE-2020-15934 | HIGH 8.8 | fortinet forticlient An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. may allow local users to elevate their privileges to root by creating a malicious script or program on the target machine | 0.2% | — |
| CVE-2020-1585 | HIGH 8.8 | microsoft windows_10 A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install program | 4.9% | — |
| CVE-2020-1583 | HIGH 8.8 | microsoft 365_apps An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, a | 4.9% | — |
| CVE-2020-1561 | HIGH 8.8 | microsoft windows_10 A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user | 4.3% | — |
| CVE-2020-1555 | HIGH 8.8 | microsoft chakracore A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the | 4.5% | — |
| CVE-2020-1504 | HIGH 8.8 | microsoft excel A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the | 4.2% | — |
| CVE-2020-1498 | HIGH 8.8 | microsoft 365_apps A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the | 3.9% | — |