Vulnerabilities
Tracked app vulnerabilities
8,539 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 8,539
- Actively exploited
- 214
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2020-1372
HIGH 7.8
Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability |
|
CVE-2020-1371
HIGH 7.8
Windows Event Logging Service Elevation of Privilege Vulnerability |
|
CVE-2020-1370
HIGH 7.8
Windows Runtime Elevation of Privilege Vulnerability |
|
CVE-2020-1369
HIGH 7.8
Windows WalletService Elevation of Privilege Vulnerability |
|
CVE-2020-1368
HIGH 7.8
Windows Credential Enrollment Manager Service Elevation of Privilege Vulnerability |
|
CVE-2020-1367
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2020-1366
HIGH 7.0
Windows Print Workflow Service Elevation of Privilege Vulnerability |
|
CVE-2020-1365
HIGH 7.8
Windows Event Logging Service Elevation of Privilege Vulnerability |
|
CVE-2020-1364
HIGH 7.1
Windows WalletService Denial of Service Vulnerability |
|
CVE-2020-1363
HIGH 7.8
Windows Picker Platform Elevation of Privilege Vulnerability |
|
CVE-2020-1362
HIGH 7.8
Windows WalletService Elevation of Privilege Vulnerability |
|
CVE-2020-1361
HIGH 5.5
Windows WalletService Information Disclosure Vulnerability |
|
CVE-2020-1360
HIGH 7.8
Windows Profile Service Elevation of Privilege Vulnerability |
|
CVE-2020-1359
HIGH 7.8
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability |
|
CVE-2020-1358
HIGH 5.5
Windows Resource Policy Information Disclosure Vulnerability |
|
CVE-2020-1357
HIGH 7.8
Windows System Events Broker Elevation of Privilege Vulnerability |
|
CVE-2020-1356
HIGH 7.8
Windows iSCSI Target Service Elevation of Privilege Vulnerability |
|
CVE-2020-1355
HIGH 7.8
Windows Font Driver Host Remote Code Execution Vulnerability |
|
CVE-2020-1354
HIGH 7.8
Windows UPnP Device Host Elevation of Privilege Vulnerability |
|
CVE-2020-1353
HIGH 7.8
Windows Runtime Elevation of Privilege Vulnerability |
|
CVE-2020-1352
HIGH 7.8
Windows USO Core Worker Elevation of Privilege Vulnerability |
|
CVE-2020-1351
HIGH 5.5
Microsoft Graphics Component Information Disclosure Vulnerability |
|
CVE-2020-1350
CRITICAL 10.0
KEV
Windows DNS Server Remote Code Execution Vulnerability |
|
CVE-2020-1347
HIGH 7.8
Windows Storage Services Elevation of Privilege Vulnerability |
|
CVE-2020-1346
HIGH 7.8
Windows Modules Installer Elevation of Privilege Vulnerability |
|
CVE-2020-1344
HIGH 7.8
Windows WalletService Elevation of Privilege Vulnerability |
|
CVE-2020-1336
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2020-1333
HIGH 6.7
Group Policy Services Policy Processing Elevation of Privilege Vulnerability |
|
CVE-2020-1330
HIGH 5.5
Windows Mobile Device Management Diagnostics Information Disclosure Vulnerability |
|
CVE-2020-1267
HIGH 4.9
Local Security Authority Subsystem Service Denial of Service Vulnerability |
|
CVE-2020-1249
HIGH 7.8
Windows Runtime Elevation of Privilege Vulnerability |
|
CVE-2020-1085
HIGH 7.8
Windows Function Discovery Service Elevation of Privilege Vulnerability |
|
CVE-2020-1043
CRITICAL 8.0
Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability |
|
CVE-2020-1042
CRITICAL 8.0
Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability |
|
CVE-2020-1041
CRITICAL 8.0
Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability |
|
CVE-2020-1040
CRITICAL 8.0
KEV
Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability |
|
CVE-2020-1036
CRITICAL 8.0
Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability |
|
CVE-2020-1032
CRITICAL 8.0
Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability |
|
CVE-2019-20907
HIGH 7.5
1 app
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pa… |
|
CVE-2020-12421
MEDIUM 6.5
1 app
When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) … |
|
CVE-2020-12420
HIGH 8.8
1 app
When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potentially explo… |
|
CVE-2020-12419
HIGH 8.8
1 app
When processing callbacks that occurred during window flushing in the parent process, the associated window may die; causing a use-after-free condition. This c… |
|
CVE-2020-12418
MEDIUM 6.5
1 app
Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affec… |
|
CVE-2020-12417
HIGH 8.8
1 app
Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitab… |
|
CVE-2020-12406
HIGH 8.8
1 app
Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effort that it… |
|
CVE-2020-12405
MEDIUM 5.3
1 app
When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects… |
|
CVE-2020-12399
MEDIUM 4.4
1 app
NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thund… |
|
CVE-2020-12398
HIGH 7.5
1 app
If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted co… |
|
CVE-2018-12371
HIGH 8.8
1 app
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the … |
|
CVE-2020-15523
HIGH 7.8
1 app
In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases wh… |