56.864 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.864 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-4340 | MED 4.3 | ibm security_secret_server IBM Security Secret Server prior to 10.9 could allow an attacker to bypass SSL security due to improper certificate validation. IBM X-Force ID: 178180. | 0.7% | — |
| CVE-2020-4324 | MED 4.3 | ibm security_secret_server IBM Security Secret Server proir to 10.9 could allow a remote attacker to bypass security restrictions, caused by improper input validation. IBM X-Force ID: 177515. | 1.2% | — |
| CVE-2020-4299 | MED 4.3 | ibm sterling_file_gateway IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 could expose sensitive information to a user through a specially crafted HTTP request. IBM X-Force ID: 176606. | 1.0% | — |
| CVE-2020-4189 | MED 4.3 | ibm security_guardium IBM Security Guardium 11.2 discloses sensitive information in the response headers that could be used in further attacks against the system. IBM X-Force ID: 174850. | 0.6% | — |
| CVE-2020-4173 | MED 4.3 | ibm infosphere_guardium_activity_monitor IBM Guardium Activity Insights 10.6 and 11.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. T | 0.9% | — |
| CVE-2020-4170 | MED 4.3 | ibm security_guardium_insights IBM Security Guardium Insights 2.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 174406. | 0.4% | — |
| CVE-2020-3791 | MED 4.3 | adobe photoshop_2020 Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.2% | — |
| CVE-2020-3782 | MED 4.3 | adobe photoshop_2020 Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.2% | — |
| CVE-2020-3781 | MED 4.3 | adobe photoshop_2020 Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.2% | — |
| CVE-2020-3778 | MED 4.3 | adobe photoshop_2020 Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.2% | — |
| CVE-2020-3771 | MED 4.3 | adobe photoshop_2020 Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.2% | — |
| CVE-2020-36639 | MED 4.3 | alliedmods amx_mod_x A vulnerability has been found in AlliedModders AMX Mod X on Windows and classified as critical. This vulnerability affects the function cmdVoteMap of the file plugins/adminvote.sma of the component Console Command Handler. The manipulation of the argument amx | 0.9% | — |
| CVE-2020-3591 | MED 4.3 | cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-ba | 0.7% | — |
| CVE-2020-3547 | MED 4.3 | cisco asyncos A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to | 0.9% | — |
| CVE-2020-3525 | MED 4.3 | cisco identity_services_engine A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to recover service account passwords that are saved on an affected system. The vulnerability is due to the incorrect inclusion of sa | 0.6% | — |
| CVE-2020-3516 | MED 4.3 | cisco ios_xe A vulnerability in the web server authentication of Cisco IOS XE Software could allow an authenticated, remote attacker to crash the web server on the device. The vulnerability is due to insufficient input validation during authentication. An attacker could ex | 1.7% | — |
| CVE-2020-3475 | MED 4.3 | cisco ios Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to gain unauthorized read access to sensitive data or cause the web management software to hang or crash, | 1.4% | — |
| CVE-2020-3474 | MED 4.3 | cisco ios_xe Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to gain unauthorized read access to sensitive data or cause the web management software to hang or crash, | 0.9% | — |
| CVE-2020-3449 | MED 4.3 | cisco ios_xr A vulnerability in the Border Gateway Protocol (BGP) additional paths feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to prevent authorized users from monitoring the BGP status and cause the BGP process to stop processing new u | 1.1% | — |
| CVE-2020-3413 | MED 4.3 | cisco webex_meetings_online A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote attacker to delete a scheduled meeting template that belongs to another user in their organization. The vulnerability is due to insufficient | 0.7% | — |
| CVE-2020-3412 | MED 4.3 | cisco webex_meetings_online A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote attacker to create a scheduled meeting template that would belong to another user in their organization. The vulnerability is due to insuffic | 0.7% | — |
| CVE-2020-3378 | MED 4.3 | cisco sd-wan_firmware A vulnerability in the web-based management interface for Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficient val | 0.7% | — |
| CVE-2020-3365 | MED 4.3 | cisco enterprise_nfv_infrastructure_software A vulnerability in the directory permissions of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform a directory traversal attack on a limited set of restricted directories. The vulnerability is due to a | 1.6% | — |
| CVE-2020-3345 | MED 4.3 | cisco webex_meetings A vulnerability in certain web pages of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to modify a web page in the context of a browser. The vulnerability is due to improper checks on parameter values withi | 1.2% | — |
| CVE-2020-3329 | MED 4.3 | cisco integrated_management_controller_supervisor A vulnerability in role-based access control of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow a read-only authenticated, remote attacker to disable user accounts on an affec | 0.7% | — |