58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-24424 | HIGH 7.0 | adobe premiere_pro Adobe Premiere Pro version 14.4 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a | 1.2% | — |
| CVE-2020-24423 | HIGH 7.0 | adobe media_encoder Adobe Media Encoder version 14.4 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a | 1.2% | — |
| CVE-2020-24420 | HIGH 7.0 | adobe photoshop Adobe Photoshop for Windows version 21.2.1 (and earlier) is affected by an uncontrolled search path element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in | 0.8% | — |
| CVE-2020-24419 | HIGH 7.0 | adobe after_effects Adobe After Effects version 17.1.1 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that | 0.7% | — |
| CVE-2020-2032 | HIGH 7.0 | paloaltonetworks globalprotect A race condition vulnerability Palo Alto Networks GlobalProtect app on Windows allows a local limited Windows user to execute programs with SYSTEM privileges. This issue can be exploited only while performing a GlobalProtect app upgrade. This issue affects: Gl | 0.2% | — |
| CVE-2020-2016 | HIGH 7.0 | paloaltonetworks pan-os A race condition due to insecure creation of a file in a temporary directory vulnerability in PAN-OS allows for root privilege escalation from a limited linux user account. This allows an attacker who has escaped the restricted shell as a low privilege adminis | 0.6% | — |
| CVE-2020-1989 | HIGH 7.0 | paloaltonetworks globalprotect An incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks Global Protect Agent for Linux on ARM platform allows a local authenticated user to gain root privileges on the system. This issue affects Palo Al | 0.3% | — |
| CVE-2020-1981 | HIGH 7.0 | paloaltonetworks pan-os A predictable temporary filename vulnerability in PAN-OS allows local privilege escalation. This issue allows a local attacker who bypassed the restricted shell to execute commands as a low privileged user and gain root access on the PAN-OS hardware or virtual | 0.4% | — |
| CVE-2020-17534 | HIGH 7.0 | apache html\/java_api There exists a race condition between the deletion of the temporary file and the creation of the temporary directory in `webkit` subproject of HTML/Java API version 1.7. A similar vulnerability has recently been disclosed in other Java projects and the fix in | 0.4% | — |
| CVE-2020-17103 | HIGH 7.0 | microsoft windows_10 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 26.5% | — |
| CVE-2020-17057 | HIGH 7.0 | microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability | 1.9% | — |
| CVE-2020-17007 | HIGH 7.0 | microsoft windows_10 Windows Error Reporting Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-16998 | HIGH 7.0 | microsoft windows_10 DirectX Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-16977 | HIGH 7.0 | microsoft visual_studio_code <p>A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads a Jupyter notebook file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current | 3.4% | — |
| CVE-2020-16934 | HIGH 7.0 | microsoft 365_apps <p>An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files. An attacker who successfully exploited the vulnerability could elevate privileges.</p> <p>To exploit this vulnerability, an atta | 2.7% | — |
| CVE-2020-16933 | HIGH 7.0 | microsoft 365_apps <p>A security feature bypass vulnerability exists in Microsoft Word software when it fails to properly handle .LNK files. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of | 2.7% | — |
| CVE-2020-16900 | HIGH 7.0 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Event System improperly handles objects in memory.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specia | 0.7% | — |
| CVE-2020-1488 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. To exploit this vulnerability, an authenticated attacker would need to run a specially cra | 0.8% | — |
| CVE-2020-1477 | HIGH 7.0 | microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user ri | 2.5% | — |
| CVE-2020-1473 | HIGH 7.0 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu | 2.8% | — |
| CVE-2020-14418 | HIGH 7.0 | cisco advanced_malware_protection A TOCTOU vulnerability exists in madCodeHook before 2020-07-16 that allows local attackers to elevate their privileges to SYSTEM. This occurs because path redirection can occur via vectors involving directory junctions. | 0.3% | — |
| CVE-2020-1308 | HIGH 7.0 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or de | 1.0% | — |
| CVE-2020-1245 | HIGH 7.0 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install | 0.8% | — |
| CVE-2020-11884 | HIGH 7.0 | canonical ubuntu_linux In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails to protect against a concurrent page table upgrade, aka CID- | 0.4% | — |
| CVE-2020-1164 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerabilit | 2.2% | — |