57.080 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.080 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-3979 | HIGH 7.8 | installbuilder installbuilder InstallBuilder for Qt Windows (versions prior to 20.7.0) installers look for plugins at a predictable location at initialization time, writable by non-admin users. While those plugins are not required, they are loaded if present, which could allow an attacker | 0.4% | — |
| CVE-2020-3974 | HIGH 7.8 | vmware fusion VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior before 11.2.0 ) and Horizon Client for Mac (5.x and prior before 5.4.3) contain a privilege escalation vulnerability due to improper XPC Client validation. Successful exploitatio | 0.4% | — |
| CVE-2020-3969 | HIGH 7.8 | vmware cloud_foundation VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an off-by-one heap-overflow vulnerability in the SVGA device. A ma | 0.5% | — |
| CVE-2020-3961 | HIGH 7.8 | vmware horizon_client VMware Horizon Client for Windows (prior to 5.4.3) contains a privilege escalation vulnerability due to folder permission configuration and unsafe loading of libraries. A local user on the system where the software is installed may exploit this issue to run co | 0.4% | — |
| CVE-2020-3950 | HIGH 7.8 | vmware fusion VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitatio | 7.3% | |
| CVE-2020-3948 | HIGH 7.8 | vmware fusion Linux Guest VMs running on VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a local privilege escalation vulnerability due to improper file permissions in Cortado Thinprint. Local attackers with non-administrative access to a Lin | 0.3% | — |
| CVE-2020-3803 | HIGH 7.8 | adobe acrobat_dc Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and 2015.006.30510 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploita | 0.8% | — |
| CVE-2020-3766 | HIGH 7.8 | adobe genuine_integrity_service Adobe Genuine Integrity Service versions Version 6.4 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation. | 0.9% | — |
| CVE-2020-3764 | HIGH 7.8 | adobe media_encoder Adobe Media Encoder versions 14.0 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | 5.1% | — |
| CVE-2020-3748 | HIGH 7.8 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution . | 3.6% | — |
| CVE-2020-3714 | HIGH 7.8 | adobe illustrator_cc Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | 3.6% | — |
| CVE-2020-3713 | HIGH 7.8 | adobe illustrator_cc Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | 3.6% | — |
| CVE-2020-3712 | HIGH 7.8 | adobe illustrator_cc Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | 3.5% | — |
| CVE-2020-3711 | HIGH 7.8 | adobe illustrator_cc Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | 3.5% | — |
| CVE-2020-3710 | HIGH 7.8 | adobe illustrator_cc Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | 3.6% | — |
| CVE-2020-36791 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net_sched: keep alloc_hash updated after hash allocation In commit 599be01ee567 ("net_sched: fix an OOB access in cls_tcindex") I moved cp->hash calculation before the first tcindex_alloc_pe | 0.2% | — |
| CVE-2020-36788 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: avoid a use-after-free when BO init fails nouveau_bo_init() is backed by ttm_bo_init() and ferries its return code back to the caller. On failures, ttm_bo_init() invokes the pro | 0.2% | — |
| CVE-2020-36787 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: media: aspeed: fix clock handling logic Video engine uses eclk and vclk for its clock sources and its reset control is coupled with eclk so the current clock enabling sequence works like bel | 0.2% | — |
| CVE-2020-36785 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: media: atomisp: Fix use after free in atomisp_alloc_css_stat_bufs() The "s3a_buf" is freed along with all the other items on the "asd->s3a_stats" list. It leads to a double free and a use a | 0.2% | — |
| CVE-2020-36405 | HIGH 7.8 | keystone-engine keystone_engine Keystone Engine 0.9.2 has a use-after-free in llvm_ks::X86Operand::getToken. | 1.1% | — |
| CVE-2020-36404 | HIGH 7.8 | keystone-engine keystone Keystone Engine 0.9.2 has an invalid free in llvm_ks::SmallVectorImpl<llvm_ks::MCFixup>::~SmallVectorImpl. | 1.1% | — |
| CVE-2020-36402 | HIGH 7.8 | soliditylang solidity Solidity 0.7.5 has a stack-use-after-return issue in smtutil::CHCSmtLib2Interface::querySolver. NOTE: c39a5e2b7a3fabbf687f53a2823fc087be6c1a7e is cited in the OSV "fixed" field but does not have a code change. | 1.0% | — |
| CVE-2020-36401 | HIGH 7.8 | mruby mruby mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free). | 1.0% | — |
| CVE-2020-36387 | HIGH 7.8 | linux linux_kernel An issue was discovered in the Linux kernel before 5.8.2. fs/io_uring.c has a use-after-free related to io_async_task_func and ctx reference holding, aka CID-6d816e088c35. | 0.4% | — |
| CVE-2020-36385 | HIGH 7.8 | linux linux_kernel An issue was discovered in the Linux kernel before 5.10. drivers/infiniband/core/ucma.c has a use-after-free because the ctx is reached via the ctx_list in some ucma_migrate_id situations where ucma_close is called, aka CID-f5449e74802c. | 1.5% | — |