Vulnerabilities
Tracked app vulnerabilities
8,495 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 8,495
- Actively exploited
- 214
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2020-0774
HIGH 5.5
Windows GDI Information Disclosure Vulnerability |
|
CVE-2020-0773
HIGH 7.8
Windows ActiveX Installer Service Elevation of Privilege Vulnerability |
|
CVE-2020-0772
HIGH 7.8
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2020-0771
HIGH 7.8
Windows CSC Service Elevation of Privilege Vulnerability |
|
CVE-2020-0770
HIGH 7.8
Windows ActiveX Installer Service Elevation of Privilege Vulnerability |
|
CVE-2020-0769
HIGH 7.8
Windows CSC Service Elevation of Privilege Vulnerability |
|
CVE-2020-0763
HIGH 7.8
Windows Defender Security Center Elevation of Privilege Vulnerability |
|
CVE-2020-0762
HIGH 7.8
Windows Defender Security Center Elevation of Privilege Vulnerability |
|
CVE-2020-0690
HIGH 7.0
DirectX Elevation of Privilege Vulnerability |
|
CVE-2020-0684
CRITICAL 8.8
LNK Remote Code Execution Vulnerability |
|
CVE-2020-0645
HIGH 7.5
Microsoft IIS Server Tampering Vulnerability |
|
CVE-2020-6800
HIGH 8.8
1 app
Mozilla developers and community members reported memory safety bugs present in Firefox 72 and Firefox ESR 68.4. Some of these bugs showed evidence of memory c… |
|
CVE-2020-6798
MEDIUM 6.1
1 app
If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that … |
|
CVE-2020-6797
MEDIUM 4.3
1 app
By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. The attacker is re… |
|
CVE-2020-6795
MEDIUM 6.5
1 app
When processing a message that contains multiple S/MIME signatures, a bug in the MIME processing code caused a null pointer dereference, leading to an unexploi… |
|
CVE-2020-6794
MEDIUM 6.5
1 app
If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is becau… |
|
CVE-2020-6793
MEDIUM 6.5
1 app
When processing an email message with an ill-formed envelope, Thunderbird could read data from a random memory location. This vulnerability affects Thunderbird… |
|
CVE-2020-6792
MEDIUM 4.3
1 app
When deriving an identifier for an email message, uninitialized memory was used in addition to the message contents. This vulnerability affects Thunderbird < 6… |
|
CVE-2019-17026
HIGH 8.8
KEV
1 app
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild a… |
|
CVE-2019-8741
HIGH 7.5
1 app
A denial of service issue was addressed with improved input validation. |
|
CVE-2020-3861
HIGH 7.1
1 app
The issue was addressed with improved permissions logic. This issue is fixed in iTunes for Windows 12.10.4. A user may gain access to protected parts of the fi… |
|
CVE-2014-4650
CRITICAL 9.8
1 app
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attacke… |
|
CVE-2014-9390
CRITICAL 9.8
2 apps
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows a… |
|
CVE-2020-0818
HIGH 7.8
Windows Elevation of Privilege Vulnerability |
|
CVE-2020-0817
CRITICAL 7.5
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2020-0792
HIGH 7.0
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2020-0757
HIGH 8.2
Windows SSH Elevation of Privilege Vulnerability |
|
CVE-2020-0756
HIGH 5.5
Windows Key Isolation Service Information Disclosure Vulnerability |
|
CVE-2020-0755
HIGH 5.5
Windows Key Isolation Service Information Disclosure Vulnerability |
|
CVE-2020-0754
HIGH 7.8
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2020-0753
HIGH 7.8
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2020-0752
HIGH 7.8
Windows Search Indexer Elevation of Privilege Vulnerability |
|
CVE-2020-0751
HIGH 6.0
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2020-0750
HIGH 7.8
Connected Devices Platform Service Elevation of Privilege Vulnerability |
|
CVE-2020-0749
HIGH 7.8
Connected Devices Platform Service Elevation of Privilege Vulnerability |
|
CVE-2020-0748
HIGH 5.5
Windows Key Isolation Service Information Disclosure Vulnerability |
|
CVE-2020-0747
HIGH 7.8
Windows Data Sharing Service Elevation of Privilege Vulnerability |
|
CVE-2020-0746
HIGH 5.5
Microsoft Graphics Components Information Disclosure Vulnerability |
|
CVE-2020-0745
HIGH 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2020-0744
HIGH 5.5
Windows GDI Information Disclosure Vulnerability |
|
CVE-2020-0743
HIGH 7.8
Connected Devices Platform Service Elevation of Privilege Vulnerability |
|
CVE-2020-0742
HIGH 7.8
Connected Devices Platform Service Elevation of Privilege Vulnerability |
|
CVE-2020-0741
HIGH 7.8
Connected Devices Platform Service Elevation of Privilege Vulnerability |
|
CVE-2020-0740
HIGH 7.8
Connected Devices Platform Service Elevation of Privilege Vulnerability |
|
CVE-2020-0739
HIGH 7.8
Windows Elevation of Privilege Vulnerability |
|
CVE-2020-0738
CRITICAL 8.8
Media Foundation Memory Corruption Vulnerability |
|
CVE-2020-0737
HIGH 7.8
Windows Elevation of Privilege Vulnerability |
|
CVE-2020-0735
HIGH 7.8
Windows Search Indexer Elevation of Privilege Vulnerability |
|
CVE-2020-0734
CRITICAL 7.5
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2020-0732
HIGH 7.0
DirectX Elevation of Privilege Vulnerability |