2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-25278CRITICAL9.8An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The Quram image codec libra...
CVE-2020-23824HIGH8.8ArGo Soft Mail Server 1.8.8.9 is affected by Cross Site Request Forgery (CSRF) for perform remote arbitrary code executi...
CVE-2020-14363HIGH7.8An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged atta...
CVE-2020-14332MEDIUM5.5A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not prop...
CVE-2020-14330MEDIUM5.5An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is ...
CVE-2020-1598MEDIUM6.1<p>An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly han...
CVE-2020-1596MEDIUM5.4<p>A information disclosure vulnerability exists when TLS components use weak hash algorithms. An attacker who successfu...
CVE-2020-1595CRITICAL9.9<p>A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe...
CVE-2020-1594HIGH7.8<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle o...
CVE-2020-1593HIGH7.6<p>A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects. An attacker...
CVE-2020-1592MEDIUM4.4<p>An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.</p> ...
CVE-2020-1590MEDIUM6.6<p>An elevation of privilege vulnerability exists when the Connected User Experiences and Telemetry Service improperly h...
CVE-2020-1589MEDIUM4.4<p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attac...
CVE-2020-1576HIGH8.5<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source mark...
CVE-2020-1575MEDIUM5.4<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speci...
CVE-2020-1559HIGH7.8<p>An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle file operations. A...
CVE-2020-1532HIGH7.8<p>An elevation of privilege vulnerability exists when the Windows InstallService improperly handles memory.</p> <p>To e...
CVE-2020-1523HIGH8.9<p>A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker ...
CVE-2020-1514MEDIUM5.4<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speci...
CVE-2020-1508HIGH7.6<p>A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects. An attacker...
CVE-2020-1507HIGH7.9<p>An elevation of privilege vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. A...
CVE-2020-1506MEDIUM6.1<p>An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker...
CVE-2020-1491HIGH7.8<p>An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Service handles objects...
CVE-2020-1482MEDIUM6.3<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speci...
CVE-2020-1471HIGH7.3<p>An elevation of privilege vulnerability exists when Microsoft Windows CloudExperienceHost fails to check COM objects....

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now