Reference material - not professional advice. Test in staging, back up first, verify against your specific version. Use your own judgment for your environment.
Showing 145 of 145 guides from 2020
CRITICAL⚠ KEVRCE

How to Fix Remote Code Execution in Microsoft SQL Server

CVE-2020-0618 - Remote Code Execution in Microsoft SQL Server. Runnable patch commands, mitigation snippets, and verification steps on this

CVE-2020-0618 · MicrosoftRead fix →
CRITICAL⚠ KEVRCE

How to Fix Remote Code Execution

CVE-2020-0646: Remote Code Execution in Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2. Patch commands and verification.

CVE-2020-0646 · MicrosoftRead fix →
CRITICAL⚠ KEVBuffer Overflow

How to Fix Buffer overflow in Microsoft Windows

CVE-2020-0796 is a buffer overflow in Microsoft Windows. This page lists verified fix commands and short-term mitigations you can run today.

CVE-2020-0796 · MicrosoftRead fix →
CRITICAL⚠ KEVAuth Bypass

How to Fix CWE-288 Authentication Bypass Using an Alternate Path or Channel

CVE-2020-10148: CWE-288 Authentication Bypass Using an Alternate Path or Channel in Orion Platform. Patch commands and verification.

CVE-2020-10148 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix n/a in n/a

CVE-2020-10181 is a n/a in the vendor n/a. CVSS 9.8 Critical. Patch commands, mitigations, and verification.

CVE-2020-10181 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix n/a in n/a

CVE-2020-10189 is a n/a in the vendor n/a. CVSS 9.8 Critical. Patch commands, mitigations, and verification.

CVE-2020-10189 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix Remote Code Execution in Windows Server

CVE-2020-1040 is a remote code execution in Microsoft Windows Server. CVSS 9 Critical. Patch commands, mitigations, and verification.

CVE-2020-1040 · MicrosoftRead fix →
CRITICAL⚠ KEV

How to Fix n/a in n/a

CVE-2020-10987 is a n/a in the vendor n/a. CVSS 9.8 Critical. Patch commands, mitigations, and verification.

CVE-2020-10987 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix n/a in n/a

CVE-2020-11651 is a n/a in the vendor n/a. CVSS 9.8 Critical. Patch commands, mitigations, and verification.

CVE-2020-11651 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix n/a in n/a

CVE-2020-12271 is a n/a in the vendor n/a. CVSS 10 Critical. Patch commands, mitigations, and verification.

CVE-2020-12271 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Improper Neutralization of Special Elements used in an OS Command ('OS Command I

CVE-2020-12641 improper neutralization of special elements used in an os command ('os command i in Roundcube Webmail. Runnable upgrade comma

CVE-2020-12641 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Improper Access Control in Fortinet FortiOS

CVE-2020-12812 is a improper access control in Fortinet FortiOS. CVSS 9.8 Critical. Patch commands, mitigations, and verification.

CVE-2020-12812 · FortinetRead fix →
CRITICAL⚠ KEVRCE

How to Fix Remote Code Execution in Windows Server

CVE-2020-1350 is a remote code execution in Microsoft Windows Server. CVSS 10 Critical. Patch commands, mitigations, and verification.

CVE-2020-1350 · MicrosoftRead fix →
CRITICAL⚠ KEVAuth Bypass

How to Fix Missing authentication in Apache Airflow

CVE-2020-13927 is a missing authentication in Apache Airflow. This page lists verified fix commands and short-term mitigations you can run t

CVE-2020-13927 · ApacheRead fix →
CRITICAL⚠ KEVRCE

How to Fix Remote Code Execution in WebLogic Server

CVE-2020-14644 - Remote Code Execution in WebLogic Server. Runnable patch commands, mitigation snippets, and verification steps on this page

CVE-2020-14644 · OracleRead fix →
CRITICAL⚠ KEV

How to Fix Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server.

CVE-2020-14750: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic

CVE-2020-14750 · OracleRead fix →
CRITICAL⚠ KEV

How to Fix Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris.

CVE-2020-14871: Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Or

CVE-2020-14871 · OracleRead fix →
CRITICAL⚠ KEV

How to Fix Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server.

CVE-2020-14882: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic

CVE-2020-14882 · OracleRead fix →
CRITICAL⚠ KEVRCE

How to Fix Remote Code Execution in XG Firewall

CVE-2020-15069 - Remote Code Execution in XG Firewall. Runnable patch commands, mitigation snippets, and verification steps on this page.

CVE-2020-15069 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix Command Injection in Multiple Vigor Routers

CVE-2020-15415 - Command Injection in Multiple Vigor Routers. Runnable patch commands, mitigation snippets, and verification steps on this p

CVE-2020-15415 · GoRead fix →
CRITICAL⚠ KEV

How to Fix n/a in n/a

CVE-2020-15505 is a n/a in the vendor n/a. CVSS 9.8 Critical. Patch commands, mitigations, and verification.

CVE-2020-15505 · OtherRead fix →
CRITICAL⚠ KEVBuffer Overflow

How to Fix Heap buffer overflow in Chrome

CVE-2020-15999 is a heap buffer overflow in Google Chrome. CVSS 9.6 Critical. Patch commands, mitigations, and verification.

CVE-2020-15999 · GoogleRead fix →
CRITICAL⚠ KEVBuffer Overflow

How to Fix Heap buffer overflow in Chrome

CVE-2020-16010 is a heap buffer overflow in Google Chrome. CVSS 9.6 Critical. Patch commands, mitigations, and verification.

CVE-2020-16010 · GoogleRead fix →
CRITICAL⚠ KEVUse After Free

How to Fix Use after free in Chrome

CVE-2020-16017 is a use after free in Google Chrome. CVSS 9.6 Critical. Patch commands, mitigations, and verification.

CVE-2020-16017 · GoogleRead fix →
CRITICAL⚠ KEV

How to Fix n/a in n/a

CVE-2020-16846 is a n/a in the vendor n/a. CVSS 9.8 Critical. Patch commands, mitigations, and verification.

CVE-2020-16846 · OtherRead fix →
CRITICAL⚠ KEVSQLi

How to Fix SQL injection in FUEL CMS

CVE-2020-17463 is a SQL injection in FUEL CMS. This page lists verified fix commands and short-term mitigations you can run today.

CVE-2020-17463 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix n/a in n/a

CVE-2020-17496 is a n/a in the vendor n/a. CVSS 9.8 Critical. Patch commands, mitigations, and verification.

CVE-2020-17496 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Files Accessible to External Parties in Apache Flink

CVE-2020-17519 - Files Accessible to External Parties in Apache Flink. Runnable patch commands, mitigation snippets, and verification steps

CVE-2020-17519 · ApacheRead fix →
CRITICAL⚠ KEV

How to Fix Neutralization of special elements used in in Apache Struts

CVE-2020-17530 is a neutralization of special elements used in in Apache Struts. This page lists verified fix commands and short-term mitiga

CVE-2020-17530 · ApacheRead fix →
CRITICAL⚠ KEV

How to Fix Security vulnerability in Apache Tomcat

CVE-2020-1938 is a security vulnerability in Apache Tomcat. This page lists verified fix commands and short-term mitigations you can run tod

CVE-2020-1938 · ApacheRead fix →
CRITICAL⚠ KEV

How to Fix Improper Verification of Cryptographic Signature in Palo Alto Networks PAN-OS

CVE-2020-2021: Improper Verification of Cryptographic Signature in Palo Alto Networks PAN-OS. Runnable fix commands and patched builds.

CVE-2020-2021 · Palo AltoRead fix →
CRITICAL⚠ KEVRCE

How to Fix Command Injection in QNAP Network-Attached Storage (NAS)

CVE-2020-2509: Command Injection in QNAP Network-Attached Storage (NAS). Runnable fix commands and patched builds.

CVE-2020-2509 · QnapRead fix →
CRITICAL⚠ KEV

How to Fix n/a in n/a

CVE-2020-25213 is a n/a in the vendor n/a. CVSS 10 Critical. Patch commands, mitigations, and verification.

CVE-2020-25213 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix OS Command Injection in Sophos SG UTM

CVE-2020-25223 is a OS Command Injection flaw in Sophos SG UTM. Actively exploited per CISA KEV. Verified patched builds and runnable fix co

CVE-2020-25223 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix n/a in n/a

CVE-2020-25506 is a n/a in the vendor n/a. CVSS 9.8 Critical. Patch commands, mitigations, and verification.

CVE-2020-25506 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Security Vulnerability in Weblogic Server

CVE-2020-2551 is a security vulnerability in Weblogic Server. Patched version, runnable upgrade commands, and how to verify the fix landed.

CVE-2020-2551 · OracleRead fix →
CRITICAL⚠ KEV

How to Fix Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence.

CVE-2020-2555: Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. S

CVE-2020-2555 · OracleRead fix →
CRITICAL⚠ KEV

How to Fix n/a in n/a

CVE-2020-26919 is a n/a in the vendor n/a. CVSS 9.8 Critical. Patch commands, mitigations, and verification.

CVE-2020-26919 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Security Vulnerability in WebLogic Server

CVE-2020-2883 - Security Vulnerability in WebLogic Server. Runnable patch commands, mitigation snippets, and verification steps on this page

CVE-2020-2883 · OracleRead fix →
CRITICAL⚠ KEV

How to Fix n/a in n/a

CVE-2020-29557 is a n/a in the vendor n/a. CVSS 9.8 Critical. Patch commands, mitigations, and verification.

CVE-2020-29557 · OtherRead fix →
CRITICAL⚠ KEVSQLi

How to Fix SQL Injection in CyberoamOS

CVE-2020-29574 - SQL Injection in CyberoamOS. Runnable patch commands, mitigation snippets, and verification steps on this page.

CVE-2020-29574 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Improper Input Validation in Cisco IP phone

CVE-2020-3161 is a improper input validation in Cisco IP phone. CVSS 9.8 Critical. Patch commands, mitigations, and verification.

CVE-2020-3161 · CiscoRead fix →
CRITICAL⚠ KEVInfo Disclosure

How to Fix Critical Information Disclosure in VMware vCenter Server

CVE-2020-3952 is a critical information disclosure in VMware vCenter Server. CVSS 9.8 Critical. Patch commands, mitigations, and verificatio

CVE-2020-3952 · VmwareRead fix →
CRITICAL⚠ KEVRCE

How to Fix Remote code execution vulnerability in VMware ESXi

CVE-2020-3992 is a remote code execution vulnerability in VMware ESXi. CVSS 9.8 Critical. Patch commands, mitigations, and verification.

CVE-2020-3992 · VmwareRead fix →
CRITICAL⚠ KEVRCE

How to Fix Command Injection

CVE-2020-4006: Command Injection in VMware Workspace One Access (Access), VMware Workspace One Access Connector (Access Connector), VMware I

CVE-2020-4006 · VmwareRead fix →
CRITICAL⚠ KEV

How to Fix Bypass Security in Data Risk Manager

CVE-2020-4427 is a bypass security in IBM Data Risk Manager. CVSS 9 Critical. Patch commands, mitigations, and verification.

CVE-2020-4427 · IbmRead fix →
CRITICAL⚠ KEV

How to Fix Gain Access in Data Risk Manager

CVE-2020-4428 is a gain access in IBM Data Risk Manager. CVSS 9.1 Critical. Patch commands, mitigations, and verification.

CVE-2020-4428 · IbmRead fix →
CRITICAL⚠ KEVBuffer Overflow

How to Fix Buffer Overflow in SonicWall SonicOS

CVE-2020-5135 is a Buffer Overflow flaw in SonicWall SonicOS. Actively exploited per CISA KEV. Verified patched builds and runnable fix comm

CVE-2020-5135 · SonicwallRead fix →
CRITICAL⚠ KEVSQLi

How to Fix SQL injection in Grandstream UCM6200 Series

CVE-2020-5722 is a SQL injection in Grandstream UCM6200 Series. This page lists verified fix commands and short-term mitigations you can run

CVE-2020-5722 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix n/a in n/a

CVE-2020-5847 is a n/a in the vendor n/a. CVSS 9.8 Critical. Patch commands, mitigations, and verification.

CVE-2020-5847 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix RCE in BIG-IP

CVE-2020-5902 is a rce in F5 BIG-IP. CVSS 9.8 Critical. Patch commands, mitigations, and verification.

CVE-2020-5902 · F5Read fix →
CRITICAL⚠ KEVAuth Bypass

How to Fix Missing Authentication Check

CVE-2020-6207: Missing Authentication Check in SAP Solution Manager (User Experience Monitoring). Patch commands and verification.

CVE-2020-6207 · SapRead fix →
CRITICAL⚠ KEVAuth Bypass

How to Fix Missing Authentication Check

CVE-2020-6287: Missing Authentication Check in SAP NetWeaver AS JAVA (LM Configuration Wizard). Patch commands and verification.

CVE-2020-6287 · SapRead fix →
CRITICAL⚠ KEV

How to Fix Improper Handling of Exceptional Conditions in OpenBSD OpenSMTPD

CVE-2020-7247: Improper Handling of Exceptional Conditions in OpenBSD OpenSMTPD. Runnable fix commands and patched builds.

CVE-2020-7247 · OtherRead fix →
CRITICAL⚠ KEVSSRF

How to Fix Server-Side Request Forgery in Zimbra Collaboration Suite

CVE-2020-7796 - Server-Side Request Forgery in Zimbra Collaboration Suite. Runnable patch commands and verification on this page.

CVE-2020-7796 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix n/a in n/a

CVE-2020-7961 is a n/a in the vendor n/a. CVSS 9.8 Critical. Patch commands, mitigations, and verification.

CVE-2020-7961 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix n/a in n/a

CVE-2020-8515 is a n/a in the vendor n/a. CVSS 9.8 Critical. Patch commands, mitigations, and verification.

CVE-2020-8515 · OtherRead fix →
CRITICAL⚠ KEVPath Traversal

How to Fix Arbitrary File Upload Directory Traversal

CVE-2020-8599: Arbitrary File Upload Directory Traversal in Trend Micro OfficeScan, Trend Micro Apex One. Patch commands and verification.

CVE-2020-8599 · Trend MicroRead fix →
CRITICAL⚠ KEV

How to Fix n/a in n/a

CVE-2020-8644 is a n/a in the vendor n/a. CVSS 9.8 Critical. Patch commands, mitigations, and verification.

CVE-2020-8644 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix n/a in n/a

CVE-2020-8657 is a n/a in the vendor n/a. CVSS 9.8 Critical. Patch commands, mitigations, and verification.

CVE-2020-8657 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix OS command injection in Pi

CVE-2020-8816 is an OS command injection in Pi. This page lists verified fix commands and short-term mitigations you can run today.

CVE-2020-8816 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix OS Command Injection in Zyxel Multiple Network-Attached Storage (NAS) Devices

CVE-2020-9054: OS Command Injection in Zyxel Multiple Network-Attached Storage (NAS) Devices. Runnable fix commands and patched builds.

CVE-2020-9054 · OtherRead fix →
HIGH⚠ KEV

How to Fix Improper input validation in Android

CVE-2020-0041 is an improper input validation in Android. This page lists verified fix commands and short-term mitigations you can run today

CVE-2020-0041 · AndroidRead fix →
HIGH⚠ KEVBuffer Overflow

How to Fix Out-of-bounds write in Android

CVE-2020-0069 is an out-of-bounds write in Android. This page lists verified fix commands and short-term mitigations you can run today.

CVE-2020-0069 · LinuxRead fix →
HIGH⚠ KEV

How to Fix Spoofing in Windows

CVE-2020-0601 is a spoofing in Microsoft Windows. CVSS 8.1 High. Patch commands, mitigations, and verification.

CVE-2020-0601 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Improper Link Resolution Before File Access in Microsoft Update Notification Manager

CVE-2020-0638: Improper Link Resolution Before File Access in Microsoft Update Notification Manager. Runnable fix commands and patched build

CVE-2020-0638 · MicrosoftRead fix →
HIGH⚠ KEVRCE

How to Fix Remote Code Execution in Internet Explorer 10

CVE-2020-0674 is a remote code execution in Microsoft Internet Explorer 10. CVSS 7.5 High. Patch commands, mitigations, and verification.

CVE-2020-0674 · MicrosoftRead fix →
HIGH⚠ KEVPrivilege Escalation

How to Fix Elevation of Privilege in Windows

CVE-2020-0683 is a elevation of privilege in Microsoft Windows. CVSS 7.8 High. Patch commands, mitigations, and verification.

CVE-2020-0683 · MicrosoftRead fix →
HIGH⚠ KEVRCE

How to Fix Remote Code Execution in Microsoft Exchange Server 2013

CVE-2020-0688 is a remote code execution in Microsoft Exchange Server 2013. CVSS 8.8 High. Patch commands, mitigations, and verification.

CVE-2020-0688 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Link resolution before file access in Microsoft Windows

CVE-2020-0787 is a link resolution before file access in Microsoft Windows. This page lists verified fix commands and short-term mitigations

CVE-2020-0787 · MicrosoftRead fix →
HIGH⚠ KEVRCE

How to Fix Remote Code Execution in Windows

CVE-2020-0938 is a remote code execution in Microsoft Windows. CVSS 7.8 High. Patch commands, mitigations, and verification.

CVE-2020-0938 · MicrosoftRead fix →
HIGH⚠ KEVRCE

How to Fix Remote Code Execution in Internet Explorer 9

CVE-2020-0968 is a remote code execution in Microsoft Internet Explorer 9. CVSS 7.5 High. Patch commands, mitigations, and verification.

CVE-2020-0968 · MicrosoftRead fix →
HIGH⚠ KEVPrivilege Escalation

How to Fix Elevation of Privilege in Windows

CVE-2020-0986 is a elevation of privilege in Microsoft Windows. CVSS 7.8 High. Patch commands, mitigations, and verification.

CVE-2020-0986 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix n/a in n/a

CVE-2020-10199 is a n/a in the vendor n/a. CVSS 8.8 High. Patch commands, mitigations, and verification.

CVE-2020-10199 · OtherRead fix →
HIGH⚠ KEVRCE

How to Fix Remote Code Execution in Windows

CVE-2020-1020 is a remote code execution in Microsoft Windows. CVSS 8.8 High. Patch commands, mitigations, and verification.

CVE-2020-1020 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix n/a in n/a

CVE-2020-10221 is a n/a in the vendor n/a. CVSS 8.8 High. Patch commands, mitigations, and verification.

CVE-2020-10221 · OtherRead fix →
HIGH⚠ KEVBuffer Overflow

How to Fix Out-of-Bounds Write in Microsoft Windows

CVE-2020-1027 is a Out-of-Bounds Write flaw in Microsoft Windows. Actively exploited per CISA KEV. Verified patched builds and runnable fix

CVE-2020-1027 · MicrosoftRead fix →
HIGH⚠ KEVPrivilege Escalation

How to Fix Elevation of Privilege in Windows

CVE-2020-1054 is a elevation of privilege in Microsoft Windows. CVSS 7.8 High. Patch commands, mitigations, and verification.

CVE-2020-1054 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix input validation flaw in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2020-11261 is an improper input validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Sna

CVE-2020-11261 · GoRead fix →
HIGH⚠ KEVRCE

How to Fix Remote Code Execution in Microsoft SharePoint Enterprise Server

CVE-2020-1147 is a remote code execution in Microsoft SharePoint Enterprise Server. CVSS 7.8 High. Patch commands, mitigations, and verifica

CVE-2020-1147 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix n/a in n/a

CVE-2020-11738 is a n/a in the vendor n/a. CVSS 7.5 High. Patch commands, mitigations, and verification.

CVE-2020-11738 · OtherRead fix →
HIGH⚠ KEVRCE

How to Fix OS command injection in Apache Airflow

CVE-2020-11978 is an OS command injection in Apache Airflow. This page lists verified fix commands and short-term mitigations you can run to

CVE-2020-11978 · ApacheRead fix →
HIGH⚠ KEVFile Upload

How to Fix Unrestricted file upload in Drupal Core

CVE-2020-13671 is an unrestricted file upload in Drupal Core. This page lists verified fix commands and short-term mitigations you can run t

CVE-2020-13671 · DrupalRead fix →
HIGH⚠ KEV

How to Fix Scripting Engine Memory Corruption in Internet Explorer 11

CVE-2020-1380 is a scripting engine memory corruption in Microsoft Internet Explorer 11. CVSS 7.8 High. Patch commands, mitigations, and ver

CVE-2020-1380 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Windows Spoofing in Windows 10 Version 1803

CVE-2020-1464 is a windows spoofing in Microsoft Windows 10 Version 1803. CVSS 7.8 High. Patch commands, mitigations, and verification.

CVE-2020-1464 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Security vulnerability in Business Intelligence Enterprise Edition

CVE-2020-14864 is a security vulnerability in Business Intelligence Enterprise Edition. This page lists verified fix commands and short-term

CVE-2020-14864 · OracleRead fix →
HIGH⚠ KEV

How to Fix Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server.

CVE-2020-14883: Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic

CVE-2020-14883 · OracleRead fix →
HIGH⚠ KEV

How to Fix Inappropriate implementation in Chrome

CVE-2020-16009 is a inappropriate implementation in Google Chrome. CVSS 8.8 High. Patch commands, mitigations, and verification.

CVE-2020-16009 · GoogleRead fix →
HIGH⚠ KEV

How to Fix Inappropriate implementation in Chrome

CVE-2020-16013 is a inappropriate implementation in Google Chrome. CVSS 8.8 High. Patch commands, mitigations, and verification.

CVE-2020-16013 · GoogleRead fix →
HIGH⚠ KEVPath Traversal

How to Fix Path Traversal in Juniper Junos OS

CVE-2020-1631 is a Path Traversal flaw in Juniper Junos OS. Actively exploited per CISA KEV. Verified patched builds and runnable fix comman

CVE-2020-1631 · JuniperRead fix →
HIGH⚠ KEVPrivilege Escalation

How to Fix Windows Kernel Local Elevation of Privilege in Windows 10 Version 1803

CVE-2020-17087: Windows Kernel Local Elevation of Privilege in Windows 10 Version 1803. Patch commands and verification.

CVE-2020-17087 · MicrosoftRead fix →
HIGH⚠ KEVRCE

How to Fix Microsoft Exchange Remote Code Execution

CVE-2020-17144: Microsoft Exchange Remote Code Execution in Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 31. Patch commands a

CVE-2020-17144 · MicrosoftRead fix →
HIGH⚠ KEVRCE

How to Fix OS Command Injection in Apache Kylin

CVE-2020-1956 is a OS Command Injection flaw in Apache Kylin. Actively exploited per CISA KEV. Verified patched builds and runnable fix comm

CVE-2020-1956 · ApacheRead fix →
HIGH⚠ KEV

How to Fix Security Vulnerability in TL-WA855RE

CVE-2020-24363 - Security Vulnerability in TL-WA855RE. Runnable patch commands, mitigation snippets, and verification steps on this page.

CVE-2020-24363 · Tp-LinkRead fix →
HIGH⚠ KEVPrivilege Escalation

How to Fix Improper Access Control Privilege Escalation in Trend Micro Apex One

CVE-2020-24557 is a improper access control privilege escalation in Trend Micro Apex One. CVSS 7.8 High. Patch commands, mitigations, and ve

CVE-2020-24557 · Trend MicroRead fix →
HIGH⚠ KEV

How to Fix Improper Access Control in QNAP Systems Helpdesk

CVE-2020-2506: Improper Access Control in QNAP Systems Helpdesk. Runnable fix commands and patched builds.

CVE-2020-2506 · QnapRead fix →
HIGH⚠ KEV

How to Fix Security Vulnerability in DCS-2530L and DCS-2670L Devices

CVE-2020-25078 - Security Vulnerability in DCS-2530L and DCS-2670L Devices. Runnable patch commands and verification on this page.

CVE-2020-25078 · OtherRead fix →
HIGH⚠ KEVRCE

How to Fix Command Injection in DCS-2530L and DCS-2670L Devices

CVE-2020-25079 - Command Injection in DCS-2530L and DCS-2670L Devices. Runnable patch commands, mitigation snippets, and verification steps

CVE-2020-25079 · OtherRead fix →
HIGH⚠ KEVDoS

How to Fix Out-of-bounds write in Apple iOS and iPadOS

CVE-2020-27930 is an out-of-bounds write in Apple iOS and iPadOS. This page lists verified fix commands and short-term mitigations you can r

CVE-2020-27930 · AppleRead fix →
HIGH⚠ KEVRCE

How to Fix Access of resource using incompatible type in Apple iOS and iPadOS

CVE-2020-27932 is an access of resource using incompatible type in Apple iOS and iPadOS. This page lists verified fix commands and short-ter

CVE-2020-27932 · AppleRead fix →
HIGH⚠ KEV

How to Fix Security Vulnerability in Archive Tar

CVE-2020-28949 is a security vulnerability in Archive Tar. Patched version, runnable upgrade commands, and how to verify the fix landed.

CVE-2020-28949 · OtherRead fix →
HIGH⚠ KEV

How to Fix Cisco IOS XR Software Cisco Discovery Protocol Format String

CVE-2020-3118: Cisco IOS XR Software Cisco Discovery Protocol Format String in Cisco IOS XR Software. Patch commands and verification.

CVE-2020-3118 · CiscoRead fix →
HIGH⚠ KEV

How to Fix Security Vulnerability in Cisco Adaptive Security Appliance (Asa) Software

CVE-2020-3259 security vulnerability in Cisco Adaptive Security Appliance (Asa) Software. Runnable upgrade commands and verification steps f

CVE-2020-3259 · CiscoRead fix →
HIGH⚠ KEV

How to Fix Security Vulnerability in Cisco Anyconnect Secure Mobility Client

CVE-2020-3433 security vulnerability in Cisco Anyconnect Secure Mobility Client. Runnable upgrade commands and verification steps for sysadm

CVE-2020-3433 · CiscoRead fix →
HIGH⚠ KEV

How to Fix input validation in Cisco Adaptive Security Appliance (ASA) Software

CVE-2020-3452 is an improper input validation in Cisco Adaptive Security Appliance (ASA) Software. This page lists verified fix commands and

CVE-2020-3452 · CiscoRead fix →
HIGH⚠ KEV

How to Fix Cisco IOS XR Software DVMRP Memory Exhaustion in Cisco IOS XR Software

CVE-2020-3566 is a cisco ios xr software dvmrp memory exhaustion in Cisco IOS XR Software. CVSS 8.6 High. Patch commands, mitigations, and v

CVE-2020-3566 · CiscoRead fix →
HIGH⚠ KEV

How to Fix Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerabilities

CVE-2020-3569: Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerabilities in Cisco IOS XR Software. Patch commands and verification.

CVE-2020-3569 · CiscoRead fix →
HIGH⚠ KEV

How to Fix Improper Link Resolution Before File Access ('Link Following') in Archive Tar

CVE-2020-36193 improper link resolution before file access ('link following') in Archive Tar. Runnable upgrade commands and verification ste

CVE-2020-36193 · OtherRead fix →
HIGH⚠ KEVBuffer Overflow

How to Fix Out-of-bounds Write in Ios

CVE-2020-3837 is a out-of-bounds write in Ios. Patched version, runnable upgrade commands, and how to verify the fix landed.

CVE-2020-3837 · AppleRead fix →
HIGH⚠ KEVPrivilege Escalation

How to Fix Privilege escalation vulnerability

CVE-2020-3950: Privilege escalation vulnerability in VMware Fusion, VMware Remote Console for Mac and Horizon Client for Mac. Patch commands

CVE-2020-3950 · VmwareRead fix →
HIGH⚠ KEVPath Traversal

How to Fix CWE-23: Relative Path Traversal in VMware Tanzu Spring Cloud Configuration (Config) Server

CVE-2020-5410: CWE-23: Relative Path Traversal in VMware Tanzu Spring Cloud Configuration (Config) Server. Runnable fix commands and patched

CVE-2020-5410 · VmwareRead fix →
HIGH⚠ KEVBuffer Overflow

How to Fix Stack buffer overflow in Amcrest

CVE-2020-5735 is a stack buffer overflow in Amcrest. This page lists verified fix commands and short-term mitigations you can run today.

CVE-2020-5735 · OtherRead fix →
HIGH⚠ KEVDeserialization

How to Fix Deserialization of Untrusted Data in Plex Media Server (Windows)

CVE-2020-5741 deserialization of untrusted data in Plex Media Server (Windows). Runnable upgrade commands and verification steps for sysadmi

CVE-2020-5741 · WindowsRead fix →
HIGH⚠ KEV

How to Fix n/a in n/a

CVE-2020-5849 is a n/a in the vendor n/a. CVSS 7.5 High. Patch commands, mitigations, and verification.

CVE-2020-5849 · OtherRead fix →
HIGH⚠ KEV

How to Fix Type confusion in Chrome

CVE-2020-6418 is a type confusion in Google Chrome. CVSS 8.8 High. Patch commands, mitigations, and verification.

CVE-2020-6418 · GoogleRead fix →
HIGH⚠ KEVUse After Free

How to Fix Use-after-free in Chrome

CVE-2020-6572 is an use-after-free in Chrome. This page lists verified fix commands and short-term mitigations you can run today.

CVE-2020-6572 · GoogleRead fix →
HIGH⚠ KEVUse After Free

How to Fix Use-after-free while running the nsDocShell destructor in Thunderbird

CVE-2020-6819: Use-after-free while running the nsDocShell destructor in Thunderbird. Patch commands and verification.

CVE-2020-6819 · OtherRead fix →
HIGH⚠ KEVUse After Free

How to Fix Use-after-free when handling a ReadableStream in Thunderbird

CVE-2020-6820 is a use-after-free when handling a readablestream in Mozilla Thunderbird. CVSS 8.1 High. Patch commands, mitigations, and ver

CVE-2020-6820 · OtherRead fix →
HIGH⚠ KEV

How to Fix Code Injection in Pulse Secure Pulse Connect Secure

CVE-2020-8218: Code Injection in Pulse Secure Pulse Connect Secure. Runnable fix commands and patched builds.

CVE-2020-8218 · OtherRead fix →
HIGH⚠ KEV

How to Fix Code Injection (CWE-94) in Pulse Connect Secre

CVE-2020-8243 is a code injection (cwe-94) in Pulse Secure Pulse Connect Secre. CVSS 7.2 High. Patch commands, mitigations, and verification

CVE-2020-8243 · OtherRead fix →
HIGH⚠ KEV

How to Fix Unrestricted Upload of File with Dangerous Type (CWE-434)

CVE-2020-8260: Unrestricted Upload of File with Dangerous Type (CWE-434) in Pulse Connect Secure / Pulse Policy Secure. Patch commands and v

CVE-2020-8260 · OtherRead fix →
HIGH⚠ KEVRCE

How to Fix RCE in Trend Micro OfficeScan, Trend Micro Apex One

CVE-2020-8467 is a rce in Trend Micro OfficeScan, Trend Micro Apex One. CVSS 8.8 High. Patch commands, mitigations, and verification.

CVE-2020-8467 · Trend MicroRead fix →
HIGH⚠ KEV

How to Fix Content Validation Escape

CVE-2020-8468: Content Validation Escape in Trend Micro OfficeScan, Trend Micro Apex One, Trend Micro Worry-Free Business Security (WFBS). P

CVE-2020-8468 · Trend MicroRead fix →
HIGH⚠ KEV

How to Fix n/a in n/a

CVE-2020-8655 is a n/a in the vendor n/a. CVSS 7.8 High. Patch commands, mitigations, and verification.

CVE-2020-8655 · OtherRead fix →
HIGH⚠ KEVRCE

How to Fix OS Command Injection in D-Link DIR-610 Devices

CVE-2020-9377 is a OS Command Injection flaw in D-Link DIR-610 Devices. Actively exploited per CISA KEV. Verified patched builds and runnabl

CVE-2020-9377 · OtherRead fix →
HIGH⚠ KEVUse After Free

How to Fix Use-After-Free in Adobe Acrobat and Reader

CVE-2020-9715 - Use-After-Free in Adobe Acrobat and Reader. Runnable patch commands, mitigation snippets, and verification steps on this pag

CVE-2020-9715 · AdobeRead fix →
HIGH⚠ KEVBuffer Overflow

How to Fix Out-of-bounds write in iOS

CVE-2020-9818 is an out-of-bounds write in iOS. This page lists verified fix commands and short-term mitigations you can run today.

CVE-2020-9818 · AppleRead fix →
HIGH⚠ KEV

How to Fix Double free in Apple macOS

CVE-2020-9859 is a double free in Apple macOS. This page lists verified fix commands and short-term mitigations you can run today.

CVE-2020-9859 · AppleRead fix →
HIGH⚠ KEVBuffer Overflow

How to Fix Out-of-bounds Write in Ios

CVE-2020-9907 is a out-of-bounds write in Ios. Patched version, runnable upgrade commands, and how to verify the fix landed.

CVE-2020-9907 · AppleRead fix →
MEDIUM⚠ KEV

How to Fix Microsoft Browser Memory Corruption in ChakraCore

CVE-2020-0878 is a microsoft browser memory corruption in Microsoft ChakraCore. CVSS 4.2 Medium. Patch commands, mitigations, and verificati

CVE-2020-0878 · MicrosoftRead fix →
MEDIUM⚠ KEVXSS

How to Fix Cross-Site Scripting in jQuery

CVE-2020-11023 - Cross-Site Scripting in jQuery. Runnable patch commands, mitigation snippets, and verification steps on this page.

CVE-2020-11023 · OtherRead fix →
MEDIUM⚠ KEV

How to Fix n/a in n/a

CVE-2020-11652 is a n/a in the vendor n/a. CVSS 6.5 Medium. Patch commands, mitigations, and verification.

CVE-2020-11652 · OtherRead fix →
MEDIUM⚠ KEVBuffer Overflow

How to Fix Out-of-bounds read in The Treck

CVE-2020-11899 is an out-of-bounds read in The Treck. This page lists verified fix commands and short-term mitigations you can run today.

CVE-2020-11899 · OtherRead fix →
MEDIUM⚠ KEVXSS

How to Fix Cross-Site Scripting in Webmail

CVE-2020-13965 - Cross-Site Scripting in Webmail. Runnable patch commands, mitigation snippets, and verification steps on this page.

CVE-2020-13965 · OtherRead fix →
MEDIUM⚠ KEVPrivilege Escalation

How to Fix Netlogon Elevation of Privilege in Windows Server version 2004

CVE-2020-1472: Netlogon Elevation of Privilege in Windows Server version 2004. Patch commands and verification.

CVE-2020-1472 · MicrosoftRead fix →
MEDIUM⚠ KEVDoS

How to Fix Initialization in Apple iOS and iPadOS

CVE-2020-27950 is an initialization in Apple iOS and iPadOS. This page lists verified fix commands and short-term mitigations you can run to

CVE-2020-27950 · AppleRead fix →
MEDIUM⚠ KEV

How to Fix Security Vulnerability in Cisco Anyconnect Secure Mobility Client

CVE-2020-3153 security vulnerability in Cisco Anyconnect Secure Mobility Client. Runnable upgrade commands and verification steps for sysadm

CVE-2020-3153 · CiscoRead fix →
MEDIUM⚠ KEV

How to Fix Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti

CVE-2020-35730 improper neutralization of input during web page generation ('cross-site scripti in Roundcube Webmail. Runnable upgrade comma

CVE-2020-35730 · OtherRead fix →
MEDIUM⚠ KEVXSS

How to Fix Cross-Site Scripting in Cisco Adaptive Security Appliance (ASA) Software

CVE-2020-3580: Cross-Site Scripting in Cisco Adaptive Security Appliance (ASA) Software. Patch commands and verification.

CVE-2020-3580 · CiscoRead fix →
MEDIUM⚠ KEV

How to Fix Obtain Information in Data Risk Manager

CVE-2020-4430 is a obtain information in IBM Data Risk Manager. CVSS 4.3 Medium. Patch commands, mitigations, and verification.

CVE-2020-4430 · IbmRead fix →
MEDIUM⚠ KEV

How to Fix Improper Access Control - Generic (CWE-284)

CVE-2020-8193: Improper Access Control - Generic (CWE-284) in Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP. Patch commands and verificati

CVE-2020-8193 · CitrixRead fix →
MEDIUM⚠ KEV

How to Fix Improper Input Validation (CWE-20)

CVE-2020-8195: Improper Input Validation (CWE-20) in Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP. Patch commands and verification.

CVE-2020-8195 · CitrixRead fix →
MEDIUM⚠ KEV

How to Fix Improper Access Control - Generic (CWE-284)

CVE-2020-8196: Improper Access Control - Generic (CWE-284) in Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP. Patch commands and verificati

CVE-2020-8196 · CitrixRead fix →
MEDIUM⚠ KEVBuffer Overflow

How to Fix Out-of-bounds write in iOS

CVE-2020-9819 is an out-of-bounds write in iOS. This page lists verified fix commands and short-term mitigations you can run today.

CVE-2020-9819 · AppleRead fix →
MEDIUM⚠ KEV

How to Fix Security Vulnerability in Ios

CVE-2020-9934 is a security vulnerability in Ios. Patched version, runnable upgrade commands, and how to verify the fix landed.

CVE-2020-9934 · AppleRead fix →