58.306 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-8835 | HIGH 7.8 | canonical ubuntu_linux In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable s | 6.0% | — |
| CVE-2020-8763 | HIGH 7.8 | intel realsense_d415_firmware Improper permissions in the installer for the Intel(R) RealSense(TM) D400 Series UWP driver for Windows* 10 may allow an authenticated user to potentially enable escalation of privilege via local access. | 0.3% | — |
| CVE-2020-8601 | HIGH 7.8 | trendmicro vulnerability_protection Trend Micro Vulnerability Protection 2.0 is affected by a vulnerability that could allow an attack to use the product installer to load other DLL files located in the same directory. | 0.4% | — |
| CVE-2020-8199 | HIGH 7.8 | citrix gateway_plug-in_for_linux Improper access control in Citrix ADC Gateway Linux client versions before 1.0.0.137 results in local privilege escalation to root. | 0.4% | — |
| CVE-2020-8146 | HIGH 7.8 | ui unifi_video In UniFi Video v3.10.1 (for Windows 7/8/10 x64) there is a Local Privileges Escalation to SYSTEM from arbitrary file deletion and DLL hijack vulnerabilities. The issue was fixed by adjusting the .tsExport folder when the controller is running on Windows and ad | 0.5% | — |
| CVE-2020-7860 | HIGH 7.8 | unegg_project unegg UnEGG v0.5 and eariler versions have a Integer overflow vulnerability, triggered when the user opens a malformed specific file that is mishandled by UnEGG. Attackers could exploit this and arbitrary code execution. This issue affects: Estsoft UnEGG 0.5 version | 0.9% | — |
| CVE-2020-7852 | HIGH 7.8 | hmtalk daviewindy DaviewIndy has a Heap-based overflow vulnerability, triggered when the user opens a malformed ex.j2c format file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution. | 0.9% | — |
| CVE-2020-7851 | HIGH 7.8 | innorix file_transfer_solution Innorix Web-Based File Transfer Solution versuibs prior to and including 9.2.18.385 contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the internal method. A remote attacker could induce a user to a | 0.7% | — |
| CVE-2020-7850 | HIGH 7.8 | douzone nbbdownloader.ocx NBBDownloader.ocx ActiveX Control in Groupware contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the activex method. A remote attacker could induce a user to access a crafted web page, causing dama | 0.8% | — |
| CVE-2020-7829 | HIGH 7.8 | hmtalk daviewindy DaviewIndy 8.98.4 and earlier version contain Heap-based overflow vulnerability, triggered when the user opens a malformed specific file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution. | 1.2% | — |
| CVE-2020-7828 | HIGH 7.8 | hmtalk daviewindy DaviewIndy 8.98.4 and earlier version contain Heap-based overflow vulnerability, triggered when the user opens a malformed specific file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution. | 1.2% | — |
| CVE-2020-7827 | HIGH 7.8 | hmtalk daviewindy DaviewIndy 8.98.7 and earlier version contain Use-After-Free vulnerability, triggered when the user opens a malformed specific file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution. | 1.3% | — |
| CVE-2020-7822 | HIGH 7.8 | hmtalk daviewindy DaviewIndy has a Heap-based overflow vulnerability, triggered when the user opens a malformed image file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution. | 1.2% | — |
| CVE-2020-7821 | HIGH 7.8 | nexaweb nexacro_14 Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by modifying the value of registry path. This can be leveraged for code execution by rebooting the victim’s PC | 1.6% | — |
| CVE-2020-7820 | HIGH 7.8 | nexaweb nexacro_14 Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by setting the arguments to the vulnerable API. This can be leveraged for code execution by rebooting the victim’s PC | 1.6% | — |
| CVE-2020-7815 | HIGH 7.8 | tobesoft xplatform XPLATFORM v9.2.260 and eariler versions contain a vulnerability that could allow remote files to be downloaded by setting the arguments to the vulnerable method. this can be leveraged for code execution. File download vulnerability in ____COMPONENT____ of TOBE | 1.2% | — |
| CVE-2020-7814 | HIGH 7.8 | raonwiz raon_k_upload RAONWIZ v2018.0.2.50 and eariler versions contains a vulnerability that could allow remote files to be downloaded and excuted by lack of validation to file extension, witch can used as remote-code-excution attacks by hackers File download & execution vulnerabi | 1.2% | — |
| CVE-2020-7812 | HIGH 7.8 | kaoni ezhttptrans Ezhttptrans.ocx ActiveX Control in Kaoni ezHTTPTrans 1.0.0.70 and prior versions contain a vulnerability that could allow remote attacker to download arbitrary file by setting the arguments to the activex method. This can be leveraged for code execution by reb | 0.7% | — |
| CVE-2020-7806 | HIGH 7.8 | tobesoft xplatform Tobesoft Xplatform 9.2.2.250 and earlier version have an arbitrary code execution vulnerability by using method supported by Xplatform ActiveX Control. It allows attacker to cause remote code execution. | 0.7% | — |
| CVE-2020-7803 | HIGH 7.8 | imgtech zoneplayer IMGTech Co,Ltd ZInsX.ocx ActiveX Control in Zoneplayer 2.0.1.3, version 2.0.1.4 and prior versions on Windows. File Donwload vulnerability in ZInsX.ocx of IMGTech Co,Ltd Zoneplayer allows attacker to cause arbitrary code execution. | 1.2% | — |
| CVE-2020-7290 | HIGH 7.8 | mcafee active_response Privilege Escalation vulnerability in McAfee Active Response (MAR) for Linux prior to 2.4.3 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to. | 0.3% | — |
| CVE-2020-7289 | HIGH 7.8 | mcafee active_response Privilege Escalation vulnerability in McAfee Active Response (MAR) for Windows prior to 2.4.3 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to. | 0.3% | — |
| CVE-2020-7287 | HIGH 7.8 | mcafee endpoint_detection_and_response Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Linux prior to 3.1.0 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to. | 0.3% | — |
| CVE-2020-7286 | HIGH 7.8 | mcafee endpoint_detection_and_response Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Windows prior to 3.1.0 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to. | 0.3% | — |
| CVE-2020-7053 | HIGH 7.8 | linux linux_kernel In the Linux kernel 4.14 longterm through 4.14.165 and 4.19 longterm through 4.19.96 (and 5.x before 5.2), there is a use-after-free (write) in the i915_ppgtt_close function in drivers/gpu/drm/i915/i915_gem_gtt.c, aka CID-7dc40713618c. This is related to i915_ | 0.6% | — |