58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.414 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-26076 | HIGH 7.5 | cisco iot_field_network_director A vulnerability in Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive database information on an affected device. The vulnerability is due to the absence of authentication for sensitive information. An atta | 1.3% | — |
| CVE-2020-26073 | HIGH 7.5 | cisco catalyst_sd-wan_manager A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character s | 12.6% | — |
| CVE-2020-25672 | HIGH 7.5 | debian debian_linux A memory leak vulnerability was found in Linux kernel in llcp_sock_connect | 3.1% | — |
| CVE-2020-25649 | HIGH 7.5 | apache iotdb A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity. | 17.8% | — |
| CVE-2020-25645 | HIGH 7.5 | canonical ubuntu_linux A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints t | 2.4% | — |
| CVE-2020-24560 | HIGH 7.5 | trendmicro antivirus\+_2019 An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a maliciou | 1.8% | — |
| CVE-2020-24425 | HIGH 7.5 | adobe dreamweaver Dreamweaver version 20.2 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. Successful exploitation could result in a local user with permissions to write to the file system running system co | 0.7% | — |
| CVE-2020-23315 | HIGH 7.5 | microsoft chakracore There is an ASSERTION (pFuncBody->GetYieldRegister() == oldYieldRegister) failed in Js::DebugContext::RundownSourcesAndReparse in ChakraCore version 1.12.0.0-beta. | 2.4% | — |
| CVE-2020-2041 | HIGH 7.5 | paloaltonetworks pan-os An insecure configuration of the appweb daemon of Palo Alto Networks PAN-OS 8.1 allows a remote unauthenticated user to send a specifically crafted request to the device that causes the appweb service to crash. Repeated attempts to send this request result in | 2.1% | — |
| CVE-2020-2022 | HIGH 7.5 | paloaltonetworks pan-os An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Panorama web interface administrator's session to a managed device when the Panorama administrator performs a context switch into that device. | 1.2% | — |
| CVE-2020-2012 | HIGH 7.5 | paloaltonetworks pan-os Improper restriction of XML external entity reference ('XXE') vulnerability in Palo Alto Networks Panorama management service allows remote unauthenticated attackers with network access to the Panorama management interface to read arbitrary files on the system | 1.9% | — |
| CVE-2020-2011 | HIGH 7.5 | paloaltonetworks pan-os An improper input validation vulnerability in the configuration daemon of Palo Alto Networks PAN-OS Panorama allows for a remote unauthenticated user to send a specifically crafted registration request to the device that causes the configuration service to cra | 1.8% | — |
| CVE-2020-1977 | HIGH 7.5 | paloaltonetworks expedition_migration_tool Insufficient Cross-Site Request Forgery (XSRF) protection on Expedition Migration Tool allows remote unauthenticated attackers to hijack the authentication of administrators and to perform actions on the Expedition Migration Tool. This issue affects Expedition | 0.5% | — |
| CVE-2020-1942 | HIGH 7.5 | apache nifi In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join a cluster and the cluster flow was not inheritable, the flow fingerprint of both | 3.1% | — |
| CVE-2020-1940 | HIGH 7.5 | apache jackrabbit_oak The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensitive information disclosure vulnerability. The code mandates the changed password to be passed as an additional attribute | 4.5% | — |
| CVE-2020-1929 | HIGH 7.5 | apache beam The Apache Beam MongoDB connector in versions 2.10.0 to 2.16.0 has an option to disable SSL trust verification. However this configuration is not respected and the certificate verification disables trust verification in every case. This exclusion also gets reg | 1.0% | — |
| CVE-2020-1925 | HIGH 7.5 | apache olingo Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends a GET or DELETE request to this URL. It may allow to implement a SSRF attack. If an attacker tricks a client to connect t | 2.8% | — |
| CVE-2020-17527 | HIGH 7.5 | apache tomcat While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated wit | 24.6% | — |
| CVE-2020-17525 | HIGH 7.5 | apache subversion Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. | 40.1% | — |
| CVE-2020-17519 | HIGH 7.5 | apache flink A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by | 97.8% | |
| CVE-2020-17518 | HIGH 7.5 | apache flink Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER. The files can be written to any location accessible by Flink 1.5.1. All users | 50.0% | — |
| CVE-2020-17517 | HIGH 7.5 | apache ozone The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The current security vulnerability allows access to keys and buckets through a curl command or an unauthenticated HTTP request. This enables unauthori | 2.3% | — |
| CVE-2020-17516 | HIGH 7.5 | apache cassandra Apache Cassandra versions 2.1.0 to 2.1.22, 2.2.0 to 2.2.19, 3.0.0 to 3.0.23, and 3.11.0 to 3.11.9, when using 'dc' or 'rack' internode_encryption setting, allows both encrypted and unencrypted internode connections. A misconfigured node or a malicious user can | 1.9% | — |
| CVE-2020-17509 | HIGH 7.5 | apache traffic_server ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected. | 1.8% | — |
| CVE-2020-17508 | HIGH 7.5 | apache traffic_server The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected. | 2.0% | — |