IT
56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.855 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-3339 MED 5.4 cisco prime_infrastructure A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability is due to improper validation of user-submitted paramete 1.1%
CVE-2020-3320 MED 5.4 cisco secure_firewall_management_center A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. 0.6%
CVE-2020-3233 MED 5.4 cisco iox A vulnerability in the web-based Local Manager interface of the Cisco IOx Application Framework could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based Local Manager interface of an af 0.6%
CVE-2020-3185 MED 5.4 cisco telepresence_management_suite A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerabil 0.6%
CVE-2020-3157 MED 5.4 cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to in 0.6%
CVE-2020-3113 MED 5.4 cisco data_center_network_manager A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerabili 0.6%
CVE-2020-29013 MED 5.4 fortinet fortisandbox An improper input validation vulnerability in the sniffer interface of FortiSandbox before 3.2.2 may allow an authenticated attacker to silently halt the sniffer via specifically crafted requests. 0.6%
CVE-2020-26147 MED 5.4 arista c-65_firmware An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even though some of them were sent in plaintext. This vulnerability can be abused to inject packets and/or exfiltrate selected fragments when a 7.6%
CVE-2020-26067 MED 5.4 cisco webex_teams A vulnerability in the web-based interface of Cisco Webex Teams could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of usernames. An attacker could exploit this vulnerabil 0.8%
CVE-2020-1998 MED 5.4 paloaltonetworks pan-os An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of the intended SAML permissions of the account when the username is shared for the purposes of SSO authentication. This can result in authentic 0.9%
CVE-2020-17145 MED 5.4 microsoft azure_devops_server Azure DevOps Server and Team Foundation Services Spoofing Vulnerability 1.4%
CVE-2020-17060 MED 5.4 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 1.9%
CVE-2020-17021 MED 5.4 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 1.4%
CVE-2020-17018 MED 5.4 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 1.4%
CVE-2020-17006 MED 5.4 microsoft dynamics_crm_2015 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 1.4%
CVE-2020-17005 MED 5.4 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 1.4%
CVE-2020-16993 MED 5.4 microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability 0.8%
CVE-2020-16989 MED 5.4 microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability 0.7%
CVE-2020-16978 MED 5.4 microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially 1.4%
CVE-2020-16956 MED 5.4 microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially 1.4%
CVE-2020-16878 MED 5.4 microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially 1.6%
CVE-2020-16871 MED 5.4 microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially 1.6%
CVE-2020-16864 MED 5.4 microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially 1.6%
CVE-2020-16861 MED 5.4 microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially 1.6%
CVE-2020-16859 MED 5.4 microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially 1.6%