VULNERABILITY REMEDIATION

CVE remediation guides

Move from asset identification to supported remediation and post-change verification while keeping source evidence visible.

These defensive guides do not provide exploit reproduction or bypass instructions.
01

Confirm exposure first

Match the product, version, installation path, and external exposure before treating a score as an action order.

02

Prefer supported fixes

Use vendor advisories and supported update paths. An unverified fixed-version field stays visibly unresolved.

03

Verify and retain rollback

Confirm version state, service health, access paths, logs, and rollback readiness after the change.

17,661 guide candidatesPage 1412 of 1472
Known exploitedCriticalFixed-version data
CVE-2018-19949

QNAP Network Attached Storage (NAS)

Affected
unspecified, < 4.2.6, >= 4.3.1.0013 < 4.3.3.1161, >= 4.3.4 < 4.3.4.1190, >= 4.3.6 < 4.3.6.1218, >= 4.4.0 < 4.4.1.1201, >= 4.4.2 < 4.4.2.1231, 4.2.6
Fixed
4.2.6, 4.3.3.1161, 4.3.4.1190, 4.3.6.1218, 4.4.1.1201, 4.4.2.1231
Known exploitedMediumFixed-version data
CVE-2018-19943

QNAP Network Attached Storage (NAS)

Affected
unspecified, < 4.2.6, >= 4.3.1.0013 < 4.3.3.1252, >= 4.3.4 < 4.3.4.1282, >= 4.3.6 < 4.3.6.1263, >= 4.4.0 < 4.4.1.1261, >= 4.4.2 < 4.4.2.1270, 4.2.6
Fixed
4.2.6, 4.3.3.1252, 4.3.4.1282, 4.3.6.1263, 4.4.1.1261, 4.4.2.1270
Review reviewHighResearch in progress
CVE-2020-22552

snap7

Affected
1.4.1
Fixed
No verified fixed-version field is available yet
Known exploitedHighResearch in progress
CVE-2020-8260

Ivanti Pulse Connect Secure

Affected
9.1R9, <= 9.0, 9.1
Fixed
No verified fixed-version field is available yet
Review reviewCriticalResearch in progress
CVE-2020-25466

crmeb

Affected
3.0
Fixed
No verified fixed-version field is available yet
Known exploitedMediumFixed-version data
CVE-2020-3580

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

Affected
< 6.4.0.12, >= 6.5.0 < 6.6.4, >= 6.7.0 < 6.7.0.2, < 9.8.4.34, >= 9.9 < 9.9.2.85, >= 9.10 < 9.12.4.13, >= 9.13 < 9.13.1.21, >= 9.14 < 9.14.2.8, >= 9.15 < 9.15.1.15
Fixed
6.4.0.12, 6.6.4, 6.7.0.2, 9.8.4.34, 9.9.2.85, 9.12.4.13, 9.13.1.21, 9.14.2.8, 9.15.1.15
Known exploitedHighResearch in progress
CVE-2020-14883

Oracle WebLogic Server

Affected
10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0
Fixed
No verified fixed-version field is available yet
Known exploitedCriticalResearch in progress
CVE-2020-14882

Oracle WebLogic Server

Affected
10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0
Fixed
No verified fixed-version field is available yet
Known exploitedCriticalFixed-version data
CVE-2020-14871

Oracle Solaris and Zettabyte File System (ZFS)

Affected
10, 11, >= 10 < 11.1, 9
Fixed
11.1
Known exploitedHighResearch in progress
CVE-2020-14864

Oracle Intelligence Enterprise Edition

Affected
5.5.0.0.0, 12.2.1.3.0, 12.2.1.4.0
Fixed
No verified fixed-version field is available yet
Known exploitedCriticalFixed-version data
CVE-2020-3992

VMware ESXi

Affected
VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG), >= 3.0 < 3.10.1.2, >= 4.0 < 4.1.0.1, 6.5, 6.7, 7.0.0
Fixed
3.10.1.2, 4.1.0.1
Known exploitedMediumFixed-version data
CVE-2020-9934

Apple iOS, iPadOS, and macOS

Affected
unspecified, < 13.6, < 10.15.6
Fixed
13.6, 10.15.6