56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.960 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-3549 | HIGH 8.1 | cisco secure_firewall_management_center A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to obtain the device registration hash. The vulnerability is due | 0.9% | — |
| CVE-2020-3519 | HIGH 8.1 | cisco data_center_network_manager A vulnerability in a specific REST API method of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. The vulnerability is due to insufficient validation of us | 1.0% | — |
| CVE-2020-3478 | HIGH 8.1 | cisco enterprise_nfv_infrastructure_software A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to overwrite certain files that should be restricted on an affected device. The vulnerability is due to insufficient authoriza | 1.2% | — |
| CVE-2020-3410 | HIGH 8.1 | cisco secure_firewall_management_center A vulnerability in the Common Access Card (CAC) authentication feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and access the FMC system. The attacker must have a valid CAC to | 1.1% | — |
| CVE-2020-3361 | HIGH 8.1 | cisco webex_meetings A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to gain unauthorized access to a vulnerable Webex site. The vulnerability is due to improper handling of authentication tokens by a vulnerab | 2.4% | — |
| CVE-2020-3302 | HIGH 8.1 | cisco secure_firewall_management_center A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to overwrite files on the file system of an affected device. The vulnerability is due to insufficient input validation. An attacker | 1.7% | — |
| CVE-2020-3257 | HIGH 8.1 | cisco ios Multiple vulnerabilities in the Cisco IOx application environment of Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) that are running Cisco IOS Software could allow an attacker t | 0.7% | — |
| CVE-2020-3238 | HIGH 8.1 | cisco iox A vulnerability in the Cisco Application Framework component of the Cisco IOx application environment could allow an authenticated, remote attacker to write or modify arbitrary files in the virtual instance that is running on the affected device. The vulnerabi | 1.2% | — |
| CVE-2020-28374 | HIGH 8.1 | debian debian_linux In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request, aka CID-2896c93811e3. For | 6.3% | — |
| CVE-2020-28052 | HIGH 8.1 | apache karaf An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed | 7.1% | — |
| CVE-2020-27131 | HIGH 8.1 | cisco security_manager Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. These vulnerabilities are due to insecure deserialization | 87.7% | — |
| CVE-2020-26064 | HIGH 8.1 | cisco catalyst_sd-wan_manager A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Enti | 0.7% | — |
| CVE-2020-2034 | HIGH 8.1 | paloaltonetworks pan-os An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacker to execute arbitrary OS commands with root privileges. An attacker requires some knowledge of the firewall to exploit this issue. This iss | 7.2% | — |
| CVE-2020-2002 | HIGH 8.1 | paloaltonetworks pan-os An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS by failing to verify the integrity of the Kerberos key distribution center (KDC) before authenticating users. This affect | 1.3% | — |
| CVE-2020-2001 | HIGH 8.1 | paloaltonetworks pan-os An external control of path and data vulnerability in the Palo Alto Networks PAN-OS Panorama XSLT processing logic that allows an unauthenticated user with network access to PAN-OS management interface to write attacker supplied file on the system and elevate | 1.3% | — |
| CVE-2020-1992 | HIGH 8.1 | paloaltonetworks pan-os A format string vulnerability in the Varrcvr daemon of PAN-OS on PA-7000 Series devices with a Log Forwarding Card (LFC) allows remote attackers to crash the daemon creating a denial of service condition or potentially execute code with root privileges. This i | 3.5% | — |
| CVE-2020-1979 | HIGH 8.1 | paloaltonetworks pan-os A format string vulnerability in the PAN-OS log daemon (logd) on Panorama allows a network based attacker with knowledge of registered firewall devices and access to Panorama management interfaces to execute arbitrary code, bypassing the restricted shell and e | 1.0% | — |
| CVE-2020-1931 | HIGH 8.1 | apache spamassassin A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.cf) files can be configured to run system commands similar to CVE-2018-11805. This issue is less stealthy and attempts to exploit the issue w | 6.5% | — |
| CVE-2020-1930 | HIGH 8.1 | apache spamassassin A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuration (.cf) files can be configured to run system commands similar to CVE-2018-11805. With this bug unpatched, exploits can be injected in a num | 7.1% | — |
| CVE-2020-17533 | HIGH 8.1 | apache accumulo Apache Accumulo versions 1.5.0 through 1.10.0 and version 2.0.0 do not properly check the return value of some policy enforcement functions before permitting an authenticated user to perform certain administrative operations. Specifically, the return values of | 3.7% | — |
| CVE-2020-17140 | HIGH 8.1 | microsoft windows_10 Windows SMB Information Disclosure Vulnerability | 12.2% | — |
| CVE-2020-17118 | HIGH 8.1 | microsoft sharepoint_foundation Microsoft SharePoint Remote Code Execution Vulnerability | 3.5% | — |
| CVE-2020-16970 | HIGH 8.1 | microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability | 1.4% | — |
| CVE-2020-15605 | HIGH 8.1 | trendmicro deep_security_manager If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2.0 SP2 could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass manager authentication. Enabling | 2.8% | — |
| CVE-2020-15601 | HIGH 8.1 | trendmicro deep_security_manager If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Deep Security 10.x-12.x could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass manager authentication. Enabling multi-fac | 2.8% | — |