2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-1590MEDIUM6.6<p>An elevation of privilege vulnerability exists when the Connected User Experiences and Telemetry Service improperly h...
CVE-2020-1589MEDIUM4.4<p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attac...
CVE-2020-1575MEDIUM5.4<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speci...
CVE-2020-1514MEDIUM5.4<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speci...
CVE-2020-1506MEDIUM6.1<p>An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker...
CVE-2020-1482MEDIUM6.3<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speci...
CVE-2020-1440MEDIUM6.3<p>A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker ...
CVE-2020-1303MEDIUM5.5<p>An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An atta...
CVE-2020-1256MEDIUM5.5<p>An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of it...
CVE-2020-1250MEDIUM5.5<p>An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An a...
CVE-2020-1227MEDIUM5.4<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speci...
CVE-2020-1224MEDIUM5.5<p>An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. ...
CVE-2020-1205MEDIUM4.6<p>A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web r...
CVE-2020-1180MEDIUM4.2<p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memor...
CVE-2020-1172MEDIUM4.2<p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memor...
CVE-2020-1159MEDIUM6.6<p>An elevation of privilege vulnerability exists in the way that the StartTileData.dll handles file creation in protect...
CVE-2020-1152MEDIUM5.8<p>An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who s...
CVE-2020-1146MEDIUM6.6<p>An elevation of privilege vulnerability exists when the Microsoft Store Runtime improperly handles memory.</p> <p>To ...
CVE-2020-1133MEDIUM5.5<p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles file op...
CVE-2020-1130MEDIUM6.6<p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data op...
CVE-2020-1122MEDIUM5.5<p>An elevation of privilege vulnerability exists when the Windows Language Pack Installer improperly handles file opera...
CVE-2020-1119MEDIUM5.5<p>An information disclosure vulnerability exists when StartTileData.dll improperly handles objects in memory. An attack...
CVE-2020-1097MEDIUM6.5<p>An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of it...
CVE-2020-1091MEDIUM6.5<p>An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of it...
CVE-2020-1083MEDIUM5.5<p>An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objec...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now