Vulnerabilities
Tracked app vulnerabilities
7,734 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 7,734
- Actively exploited
- 213
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2020-1251
HIGH 7.0
Win32k Elevation of Privilege Vulnerability |
|
CVE-2020-1248
CRITICAL 8.4
GDI+ Remote Code Execution Vulnerability |
|
CVE-2020-1247
HIGH 7.0
Win32k Elevation of Privilege Vulnerability |
|
CVE-2020-1246
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2020-1244
HIGH 6.3
Connected User Experiences and Telemetry Service Denial of Service Vulnerability |
|
CVE-2020-1241
HIGH 5.3
Windows Kernel Security Feature Bypass Vulnerability |
|
CVE-2020-1239
HIGH 8.8
Media Foundation Memory Corruption Vulnerability |
|
CVE-2020-1238
HIGH 8.8
Media Foundation Memory Corruption Vulnerability |
|
CVE-2020-1237
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2020-1236
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2020-1235
HIGH 7.8
Windows Runtime Elevation of Privilege Vulnerability |
|
CVE-2020-1234
HIGH 7.8
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2020-1233
HIGH 7.8
Windows Runtime Elevation of Privilege Vulnerability |
|
CVE-2020-1232
HIGH 6.5
Media Foundation Information Disclosure Vulnerability |
|
CVE-2020-1231
HIGH 7.8
Windows Runtime Elevation of Privilege Vulnerability |
|
CVE-2020-1222
HIGH 7.8
Microsoft Store Runtime Elevation of Privilege Vulnerability |
|
CVE-2020-1217
HIGH 7.0
Windows Runtime Information Disclosure Vulnerability |
|
CVE-2020-1212
HIGH 7.8
OLE Automation Elevation of Privilege Vulnerability |
|
CVE-2020-1211
HIGH 7.8
Connected Devices Platform Service Elevation of Privilege Vulnerability |
|
CVE-2020-1209
HIGH 7.0
Windows Network List Service Elevation of Privilege Vulnerability |
|
CVE-2020-1208
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2020-1207
HIGH 6.4
Win32k Elevation of Privilege Vulnerability |
|
CVE-2020-1206
HIGH 8.6
Windows SMBv3 Client/Server Information Disclosure Vulnerability |
|
CVE-2020-1204
HIGH 6.3
Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability |
|
CVE-2020-1203
HIGH 7.8
Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability |
|
CVE-2020-1202
HIGH 7.0
Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability |
|
CVE-2020-1201
HIGH 7.8
Windows Now Playing Session Manager Elevation of Privilege Vulnerability |
|
CVE-2020-1199
HIGH 7.8
Windows Feedback Hub Elevation of Privilege Vulnerability |
|
CVE-2020-1197
HIGH 6.3
Windows Error Reporting Manager Elevation of Privilege Vulnerability |
|
CVE-2020-1196
HIGH 7.0
Windows Print Configuration Elevation of Privilege Vulnerability |
|
CVE-2020-1194
HIGH 5.5
Windows Registry Denial of Service Vulnerability |
|
CVE-2020-1162
HIGH 7.8
Windows Elevation of Privilege Vulnerability |
|
CVE-2020-1160
HIGH 5.5
Microsoft Graphics Component Information Disclosure Vulnerability |
|
CVE-2020-1120
HIGH 7.1
Connected User Experiences and Telemetry Service Denial of Service Vulnerability |
|
CVE-2020-0986
HIGH
KEV
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2020-0916
HIGH 7.8
Windows GDI Elevation of Privilege Vulnerability |
|
CVE-2020-0915
HIGH 7.8
Windows GDI Elevation of Privilege Vulnerability |
|
CVE-2020-13631
MEDIUM 5.5
1 app
SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c. |
|
CVE-2020-13630
HIGH 7.0
1 app
ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature. |
|
CVE-2020-6831
CRITICAL 9.8
1 app
A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. … |
|
CVE-2020-12392
MEDIUM 5.5
1 app
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user … |
|
CVE-2020-12387
HIGH 8.1
1 app
A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. This vulner… |
|
CVE-2020-12395
CRITICAL 9.8
1 app
Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence of memory c… |
|
CVE-2020-12393
HIGH 7.8
1 app
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user use… |
|
CVE-2020-13434
MEDIUM 5.5
1 app
SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c. |
|
CVE-2020-12397
MEDIUM 4.3
1 app
By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerab… |
|
CVE-2020-1191
HIGH 7.8
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exp… |
|
CVE-2020-1190
HIGH 7.8
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exp… |
|
CVE-2020-1189
HIGH 7.8
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exp… |
|
CVE-2020-1188
HIGH 7.8
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exp… |