2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-1460HIGH8.6<p>A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and fi...
CVE-2020-1453HIGH8.6<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source mark...
CVE-2020-1452HIGH8.6<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source mark...
CVE-2020-1440MEDIUM6.3<p>A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker ...
CVE-2020-1376HIGH7.8<p>An elevation of privilege vulnerability exists in the way that fdSSDP.dll handles objects in memory. An attacker who ...
CVE-2020-1345HIGH7.4<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speci...
CVE-2020-1338HIGH7.8<p>A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in m...
CVE-2020-1335HIGH7.8<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle o...
CVE-2020-1332HIGH7.8<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle o...
CVE-2020-1319HIGH7.3<p>A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memo...
CVE-2020-1308HIGH7<p>An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who suc...
CVE-2020-1303MEDIUM5.5<p>An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An atta...
CVE-2020-1285HIGH8.4<p>A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles obje...
CVE-2020-1256MEDIUM5.5<p>An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of it...
CVE-2020-1252HIGH7.8<p>A remote code execution vulnerability exists when Windows improperly handles objects in memory. To exploit the vulner...
CVE-2020-1250MEDIUM5.5<p>An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An a...
CVE-2020-1245HIGH7<p>An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects ...
CVE-2020-1228HIGH7.5<p>A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries. An attacker who suc...
CVE-2020-1227MEDIUM5.4<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speci...
CVE-2020-1224MEDIUM5.5<p>An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. ...
CVE-2020-1218HIGH7.8<p>A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in m...
CVE-2020-1210CRITICAL9.9<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source mark...
CVE-2020-1205MEDIUM4.6<p>A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web r...
CVE-2020-1200HIGH8.6<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source mark...
CVE-2020-1198HIGH7.4<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speci...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now