Vulnerabilities
Tracked app vulnerabilities
8,473 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 8,473
- Actively exploited
- 213
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2020-0937
HIGH 5.5
Media Foundation Information Disclosure Vulnerability |
|
CVE-2020-0936
HIGH 7.1
Windows Scheduled Task Elevation of Privilege Vulnerability |
|
CVE-2020-0934
HIGH 7.8
Windows Elevation of Privilege Vulnerability |
|
CVE-2020-0918
HIGH 8.4
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2020-0917
HIGH 8.4
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2020-0913
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2020-0910
CRITICAL 8.4
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2020-0907
CRITICAL 7.8
Microsoft Graphics Components Remote Code Execution Vulnerability |
|
CVE-2020-0889
HIGH 6.7
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2020-0888
HIGH 7.8
DirectX Elevation of Privilege Vulnerability |
|
CVE-2020-0821
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2020-0794
HIGH 7.1
Windows Denial of Service Vulnerability |
|
CVE-2020-0784
HIGH 7.8
DirectX Elevation of Privilege Vulnerability |
|
CVE-2020-0699
HIGH 4.7
Win32k Information Disclosure Vulnerability |
|
CVE-2020-0687
CRITICAL 8.8
Microsoft Graphics Remote Code Execution Vulnerability |
|
CVE-2020-6814
CRITICAL 9.8
1 app
Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruption and we presume … |
|
CVE-2020-6812
MEDIUM 5.3
1 app
The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microp… |
|
CVE-2020-6811
HIGH 8.8
1 app
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user use… |
|
CVE-2020-6807
HIGH 8.8
1 app
When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> task may have been executed after the stream was destroyed, … |
|
CVE-2020-6806
HIGH 8.8
1 app
By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. This could h… |
|
CVE-2020-6805
HIGH 8.8
1 app
When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially exploitable cra… |
|
CVE-2020-0796
CRITICAL 10.0
KEV
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows S… |
|
CVE-2020-0787
HIGH 7.8
KEV
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows … |
|
CVE-2013-1753
HIGH 7.5
1 app
The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a… |
|
CVE-2020-0898
HIGH 7.0
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2020-0897
HIGH 7.8
Windows Work Folder Service Elevation of Privilege Vulnerability |
|
CVE-2020-0896
HIGH 7.8
Windows Hard Link Elevation of Privilege Vulnerability |
|
CVE-2020-0887
HIGH 7.0
Win32k Elevation of Privilege Vulnerability |
|
CVE-2020-0885
HIGH 4.3
Windows Graphics Component Information Disclosure Vulnerability |
|
CVE-2020-0883
CRITICAL 6.7
GDI+ Remote Code Execution Vulnerability |
|
CVE-2020-0882
HIGH 5.5
Windows GDI Information Disclosure Vulnerability |
|
CVE-2020-0881
CRITICAL 6.7
GDI+ Remote Code Execution Vulnerability |
|
CVE-2020-0880
HIGH 5.5
Windows GDI Information Disclosure Vulnerability |
|
CVE-2020-0879
HIGH 4.7
Windows GDI Information Disclosure Vulnerability |
|
CVE-2020-0877
HIGH 7.0
Win32k Elevation of Privilege Vulnerability |
|
CVE-2020-0876
HIGH 7.0
Win32k Information Disclosure Vulnerability |
|
CVE-2020-0874
HIGH 4.7
Windows GDI Information Disclosure Vulnerability |
|
CVE-2020-0871
HIGH 5.5
Windows Network Connections Service Information Disclosure Vulnerability |
|
CVE-2020-0869
CRITICAL 7.8
Media Foundation Memory Corruption Vulnerability |
|
CVE-2020-0868
HIGH 7.8
Windows Update Orchestrator Service Elevation of Privilege Vulnerability |
|
CVE-2020-0867
HIGH 7.8
Windows Update Orchestrator Service Elevation of Privilege Vulnerability |
|
CVE-2020-0866
HIGH 7.8
Windows Work Folder Service Elevation of Privilege Vulnerability |
|
CVE-2020-0865
HIGH 7.8
Windows Work Folder Service Elevation of Privilege Vulnerability |
|
CVE-2020-0864
HIGH 7.8
Windows Work Folder Service Elevation of Privilege Vulnerability |
|
CVE-2020-0863
HIGH 5.5
Connected User Experiences and Telemetry Service Information Disclosure Vulnerability |
|
CVE-2020-0861
HIGH 5.5
Windows Network Driver Interface Specification (NDIS) Information Disclosure Vulnerability |
|
CVE-2020-0860
HIGH 7.8
Windows ActiveX Installer Service Elevation of Privilege Vulnerability |
|
CVE-2020-0859
HIGH 5.5
Windows Modules Installer Service Information Disclosure Vulnerability |
|
CVE-2020-0858
HIGH 7.8
Windows Elevation of Privilege Vulnerability |
|
CVE-2020-0857
HIGH 7.8
Windows Search Indexer Elevation of Privilege Vulnerability |