Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

8,539 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
8,539
Actively exploited
214
Publication window
2002-10-04 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

8,539 entries Windows Clear all
CVE
CVE-2020-1372
HIGH 7.8

Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability

CVE-2020-1371
HIGH 7.8

Windows Event Logging Service Elevation of Privilege Vulnerability

CVE-2020-1370
HIGH 7.8

Windows Runtime Elevation of Privilege Vulnerability

CVE-2020-1369
HIGH 7.8

Windows WalletService Elevation of Privilege Vulnerability

CVE-2020-1368
HIGH 7.8

Windows Credential Enrollment Manager Service Elevation of Privilege Vulnerability

CVE-2020-1367
HIGH 5.5

Windows Kernel Information Disclosure Vulnerability

CVE-2020-1366
HIGH 7.0

Windows Print Workflow Service Elevation of Privilege Vulnerability

CVE-2020-1365
HIGH 7.8

Windows Event Logging Service Elevation of Privilege Vulnerability

CVE-2020-1364
HIGH 7.1

Windows WalletService Denial of Service Vulnerability

CVE-2020-1363
HIGH 7.8

Windows Picker Platform Elevation of Privilege Vulnerability

CVE-2020-1362
HIGH 7.8

Windows WalletService Elevation of Privilege Vulnerability

CVE-2020-1361
HIGH 5.5

Windows WalletService Information Disclosure Vulnerability

CVE-2020-1360
HIGH 7.8

Windows Profile Service Elevation of Privilege Vulnerability

CVE-2020-1359
HIGH 7.8

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

CVE-2020-1358
HIGH 5.5

Windows Resource Policy Information Disclosure Vulnerability

CVE-2020-1357
HIGH 7.8

Windows System Events Broker Elevation of Privilege Vulnerability

CVE-2020-1356
HIGH 7.8

Windows iSCSI Target Service Elevation of Privilege Vulnerability

CVE-2020-1355
HIGH 7.8

Windows Font Driver Host Remote Code Execution Vulnerability

CVE-2020-1354
HIGH 7.8

Windows UPnP Device Host Elevation of Privilege Vulnerability

CVE-2020-1353
HIGH 7.8

Windows Runtime Elevation of Privilege Vulnerability

CVE-2020-1352
HIGH 7.8

Windows USO Core Worker Elevation of Privilege Vulnerability

CVE-2020-1351
HIGH 5.5

Microsoft Graphics Component Information Disclosure Vulnerability

CVE-2020-1350
CRITICAL 10.0 KEV

Windows DNS Server Remote Code Execution Vulnerability

CVE-2020-1347
HIGH 7.8

Windows Storage Services Elevation of Privilege Vulnerability

CVE-2020-1346
HIGH 7.8

Windows Modules Installer Elevation of Privilege Vulnerability

CVE-2020-1344
HIGH 7.8

Windows WalletService Elevation of Privilege Vulnerability

CVE-2020-1336
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2020-1333
HIGH 6.7

Group Policy Services Policy Processing Elevation of Privilege Vulnerability

CVE-2020-1330
HIGH 5.5

Windows Mobile Device Management Diagnostics Information Disclosure Vulnerability

CVE-2020-1267
HIGH 4.9

Local Security Authority Subsystem Service Denial of Service Vulnerability

CVE-2020-1249
HIGH 7.8

Windows Runtime Elevation of Privilege Vulnerability

CVE-2020-1085
HIGH 7.8

Windows Function Discovery Service Elevation of Privilege Vulnerability

CVE-2020-1043
CRITICAL 8.0

Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability

CVE-2020-1042
CRITICAL 8.0

Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability

CVE-2020-1041
CRITICAL 8.0

Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability

CVE-2020-1040
CRITICAL 8.0 KEV

Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability

CVE-2020-1036
CRITICAL 8.0

Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability

CVE-2020-1032
CRITICAL 8.0

Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability

CVE-2019-20907
HIGH 7.5 1 app

In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pa…

CVE-2020-12421
MEDIUM 6.5 1 app

When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) …

CVE-2020-12420
HIGH 8.8 1 app

When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potentially explo…

CVE-2020-12419
HIGH 8.8 1 app

When processing callbacks that occurred during window flushing in the parent process, the associated window may die; causing a use-after-free condition. This c…

CVE-2020-12418
MEDIUM 6.5 1 app

Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affec…

CVE-2020-12417
HIGH 8.8 1 app

Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitab…

CVE-2020-12406
HIGH 8.8 1 app

Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effort that it…

CVE-2020-12405
MEDIUM 5.3 1 app

When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects…

CVE-2020-12399
MEDIUM 4.4 1 app

NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thund…

CVE-2020-12398
HIGH 7.5 1 app

If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted co…

CVE-2018-12371
HIGH 8.8 1 app

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the …

CVE-2020-15523
HIGH 7.8 1 app

In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases wh…