Vulnerabilities
Tracked app vulnerabilities
8,473 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 8,473
- Actively exploited
- 213
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2020-1117
HIGH 8.8
A remote code execution vulnerability exists in the way that the Color Management Module (ICM32.dll) handles objects in memory. An attacker who successfully ex… |
|
CVE-2020-1116
MEDIUM 5.5
An information disclosure vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory. An attacke… |
|
CVE-2020-1114
HIGH 7.8
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this … |
|
CVE-2020-1113
MEDIUM 5.3
A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over RPC. An at… |
|
CVE-2020-1112
HIGH 8.5
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content. … |
|
CVE-2020-1111
HIGH 7.8
An elevation of privilege vulnerability exists when Windows improperly handles calls to Clipboard Service. An attacker who successfully exploited this vulnerab… |
|
CVE-2020-1110
HIGH 7.8
An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory. An attacker who successfully exploited… |
|
CVE-2020-1109
HIGH 7.8
An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory. An attacker who successfully exploited… |
|
CVE-2020-1090
HIGH 7.8
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulne… |
|
CVE-2020-1088
HIGH 7.8
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of… |
|
CVE-2020-1087
HIGH 7.8
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnera… |
|
CVE-2020-1086
HIGH 7.8
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulne… |
|
CVE-2020-1084
MEDIUM 5.5
A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values. An attacker who succe… |
|
CVE-2020-1082
HIGH 7.8
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of… |
|
CVE-2020-1081
HIGH 7.8
An elevation of privilege vulnerability exists when the Windows Printer Service improperly validates file paths while loading printer drivers. An authenticated… |
|
CVE-2020-1079
HIGH 7.8
An elevation of privilege vulnerability exists when the Windows fails to properly handle objects in memory. An attacker who successfully exploited this vulnera… |
|
CVE-2020-1078
HIGH 7.8
An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations. To exploit the … |
|
CVE-2020-1077
HIGH 7.8
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulne… |
|
CVE-2020-1076
MEDIUM 5.5
A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could caus… |
|
CVE-2020-1075
MEDIUM 5.5
An information disclosure vulnerability exists when Windows Subsystem for Linux improperly handles objects in memory. An attacker who successfully exploited th… |
|
CVE-2020-1072
MEDIUM 5.5
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulner… |
|
CVE-2020-1071
MEDIUM 6.8
An elevation of privilege vulnerability exists when Windows improperly handles errors tied to Remote Access Common Dialog. An attacker who successfully exploit… |
|
CVE-2020-1070
HIGH 7.8
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who s… |
|
CVE-2020-1068
HIGH 7.8
An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in arbitrary locations. To exploit the vulnerability, an atta… |
|
CVE-2020-1067
HIGH 7.8
A remote code execution vulnerability exists in the way that Windows handles objects in memory. An attacker who successfully exploited the vulnerability could … |
|
CVE-2020-1061
HIGH 7.5
A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles objects in memory. The vulnerability could corrupt memory in … |
|
CVE-2020-1055
MEDIUM 5.5
A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize user inputs. An un-authenticated … |
|
CVE-2020-1054
HIGH 7.0
KEV
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who succe… |
|
CVE-2020-1051
HIGH 7.8
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited … |
|
CVE-2020-1048
HIGH 7.8
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who s… |
|
CVE-2020-1028
HIGH 7.8
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnera… |
|
CVE-2020-1021
HIGH 7.8
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of… |
|
CVE-2020-1010
HIGH 7.8
An elevation of privilege vulnerability exists in Windows Block Level Backup Engine Service (wbengine) that allows file deletion in arbitrary locations. To exp… |
|
CVE-2020-0963
MEDIUM 5.5
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exp… |
|
CVE-2020-0909
HIGH 7.5
A denial of service vulnerability exists when Hyper-V on a Windows Server fails to properly handle specially crafted network packets. To exploit the vulnerabil… |
|
CVE-2020-6825
CRITICAL 9.8
1 app
Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox 74 and Firefox ESR 68.6. Some of these… |
|
CVE-2020-6822
HIGH 8.8
1 app
On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in <code>GMPDecodeData</code>. It is possible that with … |
|
CVE-2020-6821
HIGH 7.5
1 app
When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method, the specification requires the returne… |
|
CVE-2020-6820
HIGH 8.1
KEV
1 app
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing thi… |
|
CVE-2020-6819
HIGH 8.1
KEV
1 app
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abu… |
|
CVE-2020-0935
MEDIUM 5.5
1 app
An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links, aka 'OneDrive for Windows E… |
|
CVE-2020-11765
MEDIUM 5.5
1 app
An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, le… |
|
CVE-2020-11764
MEDIUM 5.5
1 app
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp. |
|
CVE-2020-11763
MEDIUM 5.5
1 app
An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp. |
|
CVE-2020-11762
MEDIUM 5.5
1 app
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when handling th… |
|
CVE-2020-11761
MEDIUM 5.5
1 app
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfF… |
|
CVE-2020-11760
MEDIUM 5.5
1 app
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp. |
|
CVE-2020-11759
MEDIUM 5.5
1 app
An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineB… |
|
CVE-2020-11758
MEDIUM 5.5
1 app
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h. |
|
CVE-2020-1094
HIGH 7.8
Windows Work Folder Service Elevation of Privilege Vulnerability |