Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

8,539 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
8,539
Actively exploited
214
Publication window
2002-10-04 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

8,539 entries Windows Clear all
CVE
CVE-2020-1513
HIGH 7.8

Windows CSC Service Elevation of Privilege Vulnerability

CVE-2020-1512
HIGH 5.5

Windows State Repository Service Information Disclosure Vulnerability

CVE-2020-1511
HIGH 7.8

Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability

CVE-2020-1510
HIGH 5.5

Win32k Information Disclosure Vulnerability

CVE-2020-1509
HIGH 8.8

Local Security Authority Subsystem Service Elevation of Privilege Vulnerability

CVE-2020-1492
CRITICAL 7.8

Media Foundation Memory Corruption Vulnerability

CVE-2020-1490
HIGH 7.0

Windows Storage Service Elevation of Privilege Vulnerability

CVE-2020-1489
HIGH 7.8

Windows CSC Service Elevation of Privilege Vulnerability

CVE-2020-1488
HIGH 7.8

Windows AppX Deployment Extensions Elevation of Privilege Vulnerability

CVE-2020-1487
HIGH 5.5

Media Foundation Information Disclosure Vulnerability

CVE-2020-1486
HIGH

Windows Kernel Elevation of Privilege Vulnerability

CVE-2020-1485
HIGH 5.0

Windows Image Acquisition Service Information Disclosure Vulnerability

CVE-2020-1484
HIGH 7.8

Windows Work Folders Service Elevation of Privilege Vulnerability

CVE-2020-1480
HIGH 7.8

Windows GDI Elevation of Privilege Vulnerability

CVE-2020-1479
HIGH 7.0

DirectX Elevation of Privilege Vulnerability

CVE-2020-1478
HIGH 7.8

Media Foundation Memory Corruption Vulnerability

CVE-2020-1477
CRITICAL 7.8

Media Foundation Memory Corruption Vulnerability

CVE-2020-1475
HIGH 7.0

Windows Server Resource Management Service Elevation of Privilege Vulnerability

CVE-2020-1474
HIGH 5.5

Windows Image Acquisition Service Information Disclosure Vulnerability

CVE-2020-1473
HIGH 7.8

Jet Database Engine Remote Code Execution Vulnerability

CVE-2020-1472
CRITICAL 10.0 KEV

Netlogon Elevation of Privilege Vulnerability

CVE-2020-1470
HIGH 7.8

Windows Work Folders Service Elevation of Privilege Vulnerability

CVE-2020-1467
HIGH 7.8

Windows Hard Link Elevation of Privilege Vulnerability

CVE-2020-1466
HIGH 7.5

Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability

CVE-2020-1464
HIGH 5.3 KEV

Windows Spoofing Vulnerability

CVE-2020-1459
HIGH 5.5

Windows ARM Information Disclosure Vulnerability

CVE-2020-1417
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2020-1383
HIGH 5.5

Windows RRAS Service Information Disclosure Vulnerability

CVE-2020-1379
CRITICAL 7.8

Media Foundation Memory Corruption Vulnerability

CVE-2020-1378
HIGH 7.8

Windows Registry Elevation of Privilege Vulnerability

CVE-2020-1377
HIGH 7.8

Windows Registry Elevation of Privilege Vulnerability

CVE-2020-1339
CRITICAL 7.3

Windows Media Remote Code Execution Vulnerability

CVE-2020-1337
HIGH 7.8

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2020-15659
HIGH 8.8 1 app

Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of these bugs showed evidence of memory c…

CVE-2020-15658
MEDIUM 6.5 1 app

The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier p…

CVE-2020-15657
HIGH 7.8 1 app

Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files i…

CVE-2020-15656
HIGH 8.8 1 app

JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mitigated by various precautions in the co…

CVE-2020-15655
MEDIUM 6.5 1 app

A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of cross-ori…

CVE-2020-15654
MEDIUM 6.5 1 app

When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting with the user interface, when they are …

CVE-2020-15653
MEDIUM 6.5 1 app

An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying o…

CVE-2020-15652
MEDIUM 6.5 1 app

By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content …

CVE-2020-15648
MEDIUM 6.5 1 app

Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affec…

CVE-2020-15801
CRITICAL 9.8 1 app

In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The <executable-name…

CVE-2020-1465
HIGH 7.8 1 app

An elevation of privilege vulnerability exists in Microsoft OneDrive that allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker…

CVE-2020-1468
HIGH 5.5

Windows GDI Information Disclosure Vulnerability

CVE-2020-1463
HIGH 7.8

Windows SharedStream Library Elevation of Privilege Vulnerability

CVE-2020-1438
HIGH 7.0

Windows Network Connections Service Elevation of Privilege Vulnerability

CVE-2020-1437
HIGH 7.0

Windows Network Location Awareness Service Elevation of Privilege Vulnerability

CVE-2020-1436
CRITICAL 8.8

Windows Font Library Remote Code Execution Vulnerability

CVE-2020-1435
CRITICAL 8.8

GDI+ Remote Code Execution Vulnerability