57.925 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.925 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-8607 | MED 6.7 | trendmicro antivirus_toolkit An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address t | 0.6% | — |
| CVE-2020-5892 | MED 6.7 | f5 big-ip_access_policy_manager In versions 7.1.5-7.1.8, the BIG-IP Edge Client components in BIG-IP APM, Edge Gateway, and FirePass legacy allow attackers to obtain the full session ID from process memory. | 0.3% | — |
| CVE-2020-4230 | MED 6.7 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 and 11.5 is vulnerable to an escalation of privilege when an authenticated local attacker with special permissions executes specially crafted Db2 commands. IBM X-Force ID: 175212. | 0.4% | — |
| CVE-2020-3980 | MED 6.7 | vmware fusion VMware Fusion (11.x) contains a privilege escalation vulnerability due to the way it allows configuring the system wide path. An attacker with normal user privileges may exploit this issue to trick an admin user into executing malicious code on the system wher | 0.3% | — |
| CVE-2020-36694 | MED 6.7 | linux linux_kernel An issue was discovered in netfilter in the Linux kernel before 5.10. There can be a use-after-free in the packet processing context, because the per-CPU sequence count is mishandled during concurrent iptables rules replacement. This could be exploited with th | 0.4% | — |
| CVE-2020-35499 | MED 6.7 | linux linux_kernel A NULL pointer dereference flaw in Linux kernel versions prior to 5.11 may be seen if sco_sock_getsockopt function in net/bluetooth/sco.c do not have a sanity check for a socket connection, when using BT_SNDMTU/BT_RCVMTU for SCO sockets. This could allow a loc | 0.3% | — |
| CVE-2020-3513 | MED 6.7 | cisco ios_xe Multiple vulnerabilities in the initialization routines that are executed during bootup of Cisco IOS XE Software for Cisco ASR 900 Series Aggregation Services Routers with a Route Switch Processor 3 (RSP3) installed could allow an authenticated, local attacker | 0.3% | — |
| CVE-2020-3458 | MED 6.7 | cisco adaptive_security_appliance_software Multiple vulnerabilities in the secure boot process of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software for the Firepower 1000 Series and Firepower 2100 Series Appliances could allow an authenticated, local attacker | 0.3% | — |
| CVE-2020-3457 | MED 6.7 | cisco adaptive_security_appliance_software A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation of commands supplied by the user. An a | 0.4% | — |
| CVE-2020-3416 | MED 6.7 | cisco ios_xe Multiple vulnerabilities in the initialization routines that are executed during bootup of Cisco IOS XE Software for Cisco ASR 900 Series Aggregation Services Routers with a Route Switch Processor 3 (RSP3) installed could allow an authenticated, local attacker | 0.3% | — |
| CVE-2020-3253 | MED 6.7 | cisco secure_firewall_threat_defense A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access the shell of an affected device even though expert mode is disabled. The vulnerability is due to improper conf | 0.3% | — |
| CVE-2020-3236 | MED 6.7 | cisco enterprise_nfv_infrastructure_software A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to gain root shell access to the underlying operating system and overwrite or read arbitrary files. The attacker would need valid ad | 0.5% | — |
| CVE-2020-3215 | MED 6.7 | cisco ios_xe A vulnerability in the Virtual Services Container of Cisco IOS XE Software could allow an authenticated, local attacker to gain root-level privileges on an affected device. The vulnerability is due to insufficient validation of a user-supplied open virtual app | 0.4% | — |
| CVE-2020-3214 | MED 6.7 | cisco ios_xe A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to escalate their privileges to a user with root-level privileges. The vulnerability is due to insufficient validation of user-supplied content. This vulnerability could allo | 0.4% | — |
| CVE-2020-3213 | MED 6.7 | cisco ios_xe A vulnerability in the ROMMON of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to those of the root user of the underlying operating system. The vulnerability is due to the ROMMON allowing for special parameters to be | 0.4% | — |
| CVE-2020-3210 | MED 6.7 | cisco ios A vulnerability in the CLI parsers of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an authenticated, local attacker to execute arbitrary she | 0.4% | — |
| CVE-2020-3208 | MED 6.7 | cisco ios A vulnerability in the image verification feature of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) could allow an authenticated, local attacker to boot a malicious software image on an affected device. The vu | 0.3% | — |
| CVE-2020-3207 | MED 6.7 | cisco ios_xe A vulnerability in the processing of boot options of specific Cisco IOS XE Software switches could allow an authenticated, local attacker with root shell access to the underlying operating system (OS) to conduct a command injection attack during device boot. T | 0.6% | — |
| CVE-2020-3204 | MED 6.7 | cisco ios A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker with privileged EXEC credentials to execute arbitrary code on the underlying operating system (OS) with | 0.4% | — |
| CVE-2020-3176 | MED 6.7 | cisco remote_phy_120_firmware A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exists because the affected software does not prope | 0.4% | — |
| CVE-2020-3169 | MED 6.7 | cisco firepower_extensible_operating_system A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with a privilege level of root on an affected device. The vulnerability is due to insufficient | 0.4% | — |
| CVE-2020-3166 | MED 6.7 | cisco adaptive_security_appliance_software A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to read or write arbitrary files on the underlying operating system (OS). The vulnerability is due to insufficient input validation. An attacker could exploit this v | 0.3% | — |
| CVE-2020-3152 | MED 6.7 | cisco connected_mobile_experiences A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administrative credentials to execute arbitrary commands with root privileges. The vulnerability is due to improper user permissions that are configur | 0.4% | — |
| CVE-2020-3151 | MED 6.7 | cisco connected_mobile_experiences A vulnerability in the CLI of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administrative credentials to bypass restrictions on the CLI. The vulnerability is due to insufficient security mechanisms in the restricte | 0.3% | — |
| CVE-2020-3138 | MED 6.7 | cisco enterprise_nfv_infrastructure_software A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to install a malicious file when upgrading. The vulnerability is due to insufficient signature validation. An attacker | 0.2% | — |