57.084 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.084 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-16913 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could th | 1.0% | — |
| CVE-2020-16912 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specia | 0.9% | — |
| CVE-2020-16909 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it.</p> <p>An attacker who successfully exploit | 0.9% | — |
| CVE-2020-16908 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in Windows Setup in the way it handles directories.</p> <p>A locally authenticated attacker could run arbitrary code with elevated system privileges. After successfully exploiting the vulnerability, an attacker | 1.0% | — |
| CVE-2020-16907 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could th | 1.0% | — |
| CVE-2020-16902 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.</p> <p>A locally authenticated attacker could run arbitrary code with elevat | 0.9% | — |
| CVE-2020-16895 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash. An attacker who successfully exploited this vulnerability could delete a targeted file leading to an elevated status.</p> <p>To exploit t | 1.0% | — |
| CVE-2020-16892 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in the way that the Windows kernel image handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>To exploit the vulnerability, a | 0.9% | — |
| CVE-2020-16890 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; vi | 1.0% | — |
| CVE-2020-16887 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>To exploit the vu | 0.9% | — |
| CVE-2020-16885 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Storage VSP Driver improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.</p> <p>To exploit the vulnerability, an attacker | 1.0% | — |
| CVE-2020-16881 | HIGH 7.8 | microsoft visual_studio_code <p>A remote code execution vulnerability exists in Visual Studio Code when a user is tricked into opening a malicious 'package.json' file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If | 5.4% | — |
| CVE-2020-16874 | HIGH 7.8 | microsoft visual_studio <p>A remote code execution vulnerability exists in Visual Studio when it improperly handles objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged o | 4.3% | — |
| CVE-2020-16856 | HIGH 7.8 | microsoft visual_studio <p>A remote code execution vulnerability exists in Visual Studio when it improperly handles objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged o | 4.4% | — |
| CVE-2020-1664 | HIGH 7.8 | juniper junos A stack buffer overflow vulnerability in the device control daemon (DCD) on Juniper Networks Junos OS allows a low privilege local user to create a Denial of Service (DoS) against the daemon or execute arbitrary code in the system with root privilege. This iss | 0.4% | — |
| CVE-2020-1594 | HIGH 7.8 | microsoft 365_apps <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If t | 3.9% | — |
| CVE-2020-1587 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Ancillary Function Driver for WinSock improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a sp | 0.9% | — |
| CVE-2020-15852 | HIGH 7.8 | linux linux_kernel An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes a loss of | 0.3% | — |
| CVE-2020-15850 | HIGH 7.8 | nakivo backup_\&_replication_director Insecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access the Nakivo Director web interface and gain root privileges. This occurs because the database containing the users of the web application and | 0.5% | — |
| CVE-2020-1584 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the dnsrslvr.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authentica | 0.9% | — |
| CVE-2020-1582 | HIGH 7.8 | microsoft 365_apps A remote code execution vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the | 2.7% | — |
| CVE-2020-1581 | HIGH 7.8 | microsoft 365_apps An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) components handle objects in memory. An attacker who successfully exploited the vulnerability could elevate privileges. The attacker would need to already have t | 3.7% | — |
| CVE-2020-1579 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a special | 0.9% | — |
| CVE-2020-1577 | HIGH 7.8 | microsoft windows_10 An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There are multiple ways | 7.1% | — |
| CVE-2020-1569 | HIGH 7.8 | microsoft edge A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who | 3.0% | — |