Vulnerabilities
Tracked app vulnerabilities
8,539 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 8,539
- Actively exploited
- 214
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2020-1513
HIGH 7.8
Windows CSC Service Elevation of Privilege Vulnerability |
|
CVE-2020-1512
HIGH 5.5
Windows State Repository Service Information Disclosure Vulnerability |
|
CVE-2020-1511
HIGH 7.8
Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability |
|
CVE-2020-1510
HIGH 5.5
Win32k Information Disclosure Vulnerability |
|
CVE-2020-1509
HIGH 8.8
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability |
|
CVE-2020-1492
CRITICAL 7.8
Media Foundation Memory Corruption Vulnerability |
|
CVE-2020-1490
HIGH 7.0
Windows Storage Service Elevation of Privilege Vulnerability |
|
CVE-2020-1489
HIGH 7.8
Windows CSC Service Elevation of Privilege Vulnerability |
|
CVE-2020-1488
HIGH 7.8
Windows AppX Deployment Extensions Elevation of Privilege Vulnerability |
|
CVE-2020-1487
HIGH 5.5
Media Foundation Information Disclosure Vulnerability |
|
CVE-2020-1486
HIGH
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2020-1485
HIGH 5.0
Windows Image Acquisition Service Information Disclosure Vulnerability |
|
CVE-2020-1484
HIGH 7.8
Windows Work Folders Service Elevation of Privilege Vulnerability |
|
CVE-2020-1480
HIGH 7.8
Windows GDI Elevation of Privilege Vulnerability |
|
CVE-2020-1479
HIGH 7.0
DirectX Elevation of Privilege Vulnerability |
|
CVE-2020-1478
HIGH 7.8
Media Foundation Memory Corruption Vulnerability |
|
CVE-2020-1477
CRITICAL 7.8
Media Foundation Memory Corruption Vulnerability |
|
CVE-2020-1475
HIGH 7.0
Windows Server Resource Management Service Elevation of Privilege Vulnerability |
|
CVE-2020-1474
HIGH 5.5
Windows Image Acquisition Service Information Disclosure Vulnerability |
|
CVE-2020-1473
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2020-1472
CRITICAL 10.0
KEV
Netlogon Elevation of Privilege Vulnerability |
|
CVE-2020-1470
HIGH 7.8
Windows Work Folders Service Elevation of Privilege Vulnerability |
|
CVE-2020-1467
HIGH 7.8
Windows Hard Link Elevation of Privilege Vulnerability |
|
CVE-2020-1466
HIGH 7.5
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability |
|
CVE-2020-1464
HIGH 5.3
KEV
Windows Spoofing Vulnerability |
|
CVE-2020-1459
HIGH 5.5
Windows ARM Information Disclosure Vulnerability |
|
CVE-2020-1417
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2020-1383
HIGH 5.5
Windows RRAS Service Information Disclosure Vulnerability |
|
CVE-2020-1379
CRITICAL 7.8
Media Foundation Memory Corruption Vulnerability |
|
CVE-2020-1378
HIGH 7.8
Windows Registry Elevation of Privilege Vulnerability |
|
CVE-2020-1377
HIGH 7.8
Windows Registry Elevation of Privilege Vulnerability |
|
CVE-2020-1339
CRITICAL 7.3
Windows Media Remote Code Execution Vulnerability |
|
CVE-2020-1337
HIGH 7.8
Windows Print Spooler Elevation of Privilege Vulnerability |
|
CVE-2020-15659
HIGH 8.8
1 app
Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of these bugs showed evidence of memory c… |
|
CVE-2020-15658
MEDIUM 6.5
1 app
The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier p… |
|
CVE-2020-15657
HIGH 7.8
1 app
Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files i… |
|
CVE-2020-15656
HIGH 8.8
1 app
JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mitigated by various precautions in the co… |
|
CVE-2020-15655
MEDIUM 6.5
1 app
A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of cross-ori… |
|
CVE-2020-15654
MEDIUM 6.5
1 app
When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting with the user interface, when they are … |
|
CVE-2020-15653
MEDIUM 6.5
1 app
An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying o… |
|
CVE-2020-15652
MEDIUM 6.5
1 app
By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content … |
|
CVE-2020-15648
MEDIUM 6.5
1 app
Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affec… |
|
CVE-2020-15801
CRITICAL 9.8
1 app
In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The <executable-name… |
|
CVE-2020-1465
HIGH 7.8
1 app
An elevation of privilege vulnerability exists in Microsoft OneDrive that allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker… |
|
CVE-2020-1468
HIGH 5.5
Windows GDI Information Disclosure Vulnerability |
|
CVE-2020-1463
HIGH 7.8
Windows SharedStream Library Elevation of Privilege Vulnerability |
|
CVE-2020-1438
HIGH 7.0
Windows Network Connections Service Elevation of Privilege Vulnerability |
|
CVE-2020-1437
HIGH 7.0
Windows Network Location Awareness Service Elevation of Privilege Vulnerability |
|
CVE-2020-1436
CRITICAL 8.8
Windows Font Library Remote Code Execution Vulnerability |
|
CVE-2020-1435
CRITICAL 8.8
GDI+ Remote Code Execution Vulnerability |