58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.414 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1932 | MED 6.5 | apache superset An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed passwords, by accessing an unused and undocumented API endpoint | 1.4% | — |
| CVE-2020-17520 | MED 6.5 | apache pulsar_manager In the Pulsar manager 0.1.0 version, malicious users will be able to bypass pulsar-manager's admin, permission verification mechanism by constructing special URLs, thereby accessing any HTTP API. | 1.4% | — |
| CVE-2020-17511 | MED 6.5 | apache airflow In Airflow versions prior to 1.10.13, when creating a user using airflow CLI, the password gets logged in plain text in the Log table in Airflow Metadatase. Same happened when creating a Connection with a password field. | 2.6% | — |
| CVE-2020-17133 | MED 6.5 | microsoft dynamics_nav Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability | 3.6% | — |
| CVE-2020-17130 | MED 6.5 | microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability | 2.3% | — |
| CVE-2020-17119 | MED 6.5 | microsoft 365_apps Microsoft Outlook Information Disclosure Vulnerability | 4.0% | — |
| CVE-2020-17040 | MED 6.5 | microsoft windows_10 Windows Hyper-V Security Feature Bypass Vulnerability | 2.7% | — |
| CVE-2020-16996 | MED 6.5 | microsoft windows_server_2012 Kerberos Security Feature Bypass Vulnerability | 2.4% | — |
| CVE-2020-16953 | MED 6.5 | microsoft sharepoint_enterprise_server <p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p>To | 3.8% | — |
| CVE-2020-16948 | MED 6.5 | microsoft sharepoint_enterprise_server <p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p>To | 3.8% | — |
| CVE-2020-16943 | MED 6.5 | microsoft dynamics_365 <p>An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Commerce. An unauthenticated attacker who successfully exploited this vulnerability could update data without proper authorization.</p> <p>To exploit the vulnerability, an attacker wou | 1.1% | — |
| CVE-2020-1689 | MED 6.5 | juniper junos On Juniper Networks EX4300-MP Series, EX4600 Series and QFX5K Series deployed in a Virtual Chassis configuration, receipt of a stream of specific layer 2 frames can cause high CPU load, which could lead to traffic interruption. This issue does not occur when t | 0.5% | — |
| CVE-2020-1688 | MED 6.5 | juniper junos On Juniper Networks SRX Series and NFX Series, a local authenticated user with access to the shell may obtain the Web API service private key that is used to provide encrypted communication between the Juniper device and the authenticator services. Exploitatio | 0.3% | — |
| CVE-2020-1687 | MED 6.5 | juniper junos On Juniper Networks EX4300-MP Series, EX4600 Series and QFX5K Series deployed in (Ethernet VPN) EVPN-(Virtual Extensible LAN) VXLAN configuration, receipt of a stream of specific VXLAN encapsulated layer 2 frames can cause high CPU load, which could lead to ne | 0.5% | — |
| CVE-2020-1681 | MED 6.5 | juniper junos_os_evolved Receipt of a specifically malformed NDP packet sent from the local area network (LAN) to a device running Juniper Networks Junos OS Evolved can cause the ndp process to crash, resulting in a Denial of Service (DoS). The process automatically restarts without i | 0.5% | — |
| CVE-2020-1678 | MED 6.5 | juniper junos On Juniper Networks Junos OS and Junos OS Evolved platforms with EVPN configured, receipt of specific BGP packets causes a slow memory leak. If the memory is exhausted the rpd process might crash. If the issue occurs, the memory leak could be seen by executing | 0.4% | — |
| CVE-2020-1670 | MED 6.5 | juniper junos On Juniper Networks EX4300 Series, receipt of a stream of specific IPv4 packets can cause Routing Engine (RE) high CPU load, which could lead to network protocol operation issue and traffic interruption. This specific packets can originate only from within the | 0.5% | — |
| CVE-2020-1668 | MED 6.5 | juniper junos On Juniper Networks EX2300 Series, receipt of a stream of specific multicast packets by the layer2 interface can cause high CPU load, which could lead to traffic interruption. This issue occurs when multicast packets are received by the layer 2 interface. To c | 0.5% | — |
| CVE-2020-1651 | MED 6.5 | juniper junos On Juniper Networks MX series, receipt of a stream of specific Layer 2 frames may cause a memory leak resulting in the packet forwarding engine (PFE) on the line card to crash and restart, causing traffic interruption. By continuously sending this stream of sp | 0.5% | — |
| CVE-2020-1641 | MED 6.5 | juniper junos A Race Condition vulnerability in Juniper Networks Junos OS LLDP implementation allows an attacker to cause LLDP to crash leading to a Denial of Service (DoS). This issue occurs when crafted LLDP packets are received by the device from an adjacent device. Mult | 0.4% | — |
| CVE-2020-1625 | MED 6.5 | juniper junos The kernel memory usage represented as "temp" via 'show system virtual-memory' may constantly increase when Integrated Routing and Bridging (IRB) is configured with multiple underlay physical interfaces, and one interface flaps. This memory leak can affect run | 0.8% | — |
| CVE-2020-1611 | MED 6.5 | juniper junos_space A Local File Inclusion vulnerability in Juniper Networks Junos Space allows an attacker to view all files on the target when the device receives malicious HTTP packets. This issue affects: Juniper Networks Junos Space versions prior to 19.4R1. | 1.7% | — |
| CVE-2020-1604 | MED 6.5 | juniper junos On EX4300, EX4600, QFX3500, and QFX5100 Series, a vulnerability in the IP firewall filter component may cause the firewall filter evaluation of certain packets to fail. This issue only affects firewall filter evaluation of certain packets destined to the devic | 0.8% | — |
| CVE-2020-1600 | MED 6.5 | juniper junos In a Point-to-Multipoint (P2MP) Label Switched Path (LSP) scenario, an uncontrolled resource consumption vulnerability in the Routing Protocol Daemon (RPD) in Juniper Networks Junos OS allows a specific SNMP request to trigger an infinite loop causing a high C | 1.2% | — |
| CVE-2020-1468 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. | 5.2% | — |