Exploited vulnerabilities

CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.

47,772 CVEs · 1,734 known exploited · CVE data updated 1 hour ago · EPSS 1 hour ago

1,734 results · page 58 of 87 EPSS = probability of exploitation in the next 30 days (FIRST)
Matching CVEs
Score CVE Affected EPSS Published
8.8 high CVE-2020-1020 KEV Microsoft Windows A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0938. 65% 15 Apr 2020
7.5 high CVE-2020-0968 KEV Microsoft Internet Explorer 9 A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0970. 31% 15 Apr 2020
7.8 high CVE-2020-0938 KEV Microsoft Windows A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1020. 69% 15 Apr 2020
9.8 critical CVE-2020-2883 KEV Oracle Corporation WebLogic Server Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). 95% 15 Apr 2020
7.5 high CVE-2020-11738 KEV awesomemotive duplicator The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init. 98% 13 Apr 2020
9.8 critical CVE-2020-3952 KEV VMware vCenter Server Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls. 90% 10 Apr 2020
8.8 high CVE-2020-5735 KEV Amcrest Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly execute arbitrary code. 36% 8 Apr 2020
8.8 high CVE-2020-10199 KEV sonatype nexus Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2). 99% 1 Apr 2020
9.8 critical CVE-2020-5722 KEV Grandstream UCM6200 Series The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17. 84% 23 Mar 2020
9.8 critical CVE-2020-7961 KEV liferay portal Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS). >99% 20 Mar 2020
9.8 critical CVE-2020-8599 KEV Trend Micro OfficeScan, Trend Micro Apex One Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authentication is not required to exploit this vulnerability. 12% 18 Mar 2020
8.8 high CVE-2020-8468 KEV Trend Micro OfficeScan, Trend Micro Apex One, Trend Micro Worry-Free Business Security (WFBS) Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted attack requires user authentication. 6.2% 18 Mar 2020
8.8 high CVE-2020-8467 KEV Trend Micro OfficeScan, Trend Micro Apex One A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arbitrary code on affected installations (RCE). An attempted attack requires user authentication. 11% 18 Mar 2020
7.8 high CVE-2020-3950 KEV VMware Fusion, VMware Remote Console for Mac and Horizon Client for Mac VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC or Horizon Client is installed. 7.3% 17 Mar 2020
7.5 high CVE-2020-5849 KEV unraid Unraid 6.8.0 allows authentication bypass. 93% 16 Mar 2020
9.8 critical CVE-2020-5847 KEV unraid Unraid through 6.8.0 allows Remote Code Execution. 96% 16 Mar 2020
10.0 critical CVE-2020-0796 KEV Microsoft Windows 10 Version 1903 for 32-bit Systems A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'. >99% 12 Mar 2020
7.8 high CVE-2020-0787 KEV Microsoft Windows An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'. 43% 12 Mar 2020
9.8 critical CVE-2020-10181 KEV sumavision enhanced multimedia router firmware goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) on a device, as demonstrated by a setString=new_user<*1*>administrator<*1*>123456 request. 15% 11 Mar 2020
9.8 critical CVE-2020-6207 KEV SAP SE SAP Solution Manager (User Experience Monitoring) SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager. 98% 10 Mar 2020