2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-1349 | HIGH | 7.8 | 22.5% | Jul 14, 2020 | A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in m... |
| CVE-2020-1347 | HIGH | 7.8 | 0.8% | Jul 14, 2020 | An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle file operations, aka ... |
| CVE-2020-1346 | HIGH | 7.8 | 0.7% | Jul 14, 2020 | An elevation of privilege vulnerability exists when the Windows Modules Installer improperly handles file operations, ak... |
| CVE-2020-1344 | HIGH | 7.8 | 1.0% | Jul 14, 2020 | An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka ... |
| CVE-2020-1342 | MEDIUM | 5.5 | 6.4% | Jul 14, 2020 | An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninit... |
| CVE-2020-1336 | HIGH | 7.8 | 0.9% | Jul 14, 2020 | An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker... |
| CVE-2020-1333 | MEDIUM | 6.7 | 0.9% | Jul 14, 2020 | An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improperly handle reparse po... |
| CVE-2020-1330 | MEDIUM | 5.5 | 1.2% | Jul 14, 2020 | An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handle... |
| CVE-2020-1326 | MEDIUM | 5.4 | 1.6% | Jul 14, 2020 | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided inpu... |
| CVE-2020-1267 | MEDIUM | 4.9 | 4.5% | Jul 14, 2020 | This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when ... |
| CVE-2020-1249 | HIGH | 7.8 | 0.8% | Jul 14, 2020 | An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windo... |
| CVE-2020-1240 | HIGH | 8.8 | 13.8% | Jul 14, 2020 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje... |
| CVE-2020-1147 | HIGH | 7.8 | 94.2% | Jul 14, 2020 | A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the softwar... |
| CVE-2020-1085 | HIGH | 7.8 | 0.7% | Jul 14, 2020 | An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Service handles objects in... |
| CVE-2020-1043 | CRITICAL | 9 | 5.5% | Jul 14, 2020 | A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu... |
| CVE-2020-1042 | CRITICAL | 9 | 5.5% | Jul 14, 2020 | A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu... |
| CVE-2020-1041 | CRITICAL | 9 | 5.5% | Jul 14, 2020 | A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu... |
| CVE-2020-1040 | CRITICAL | 9 | 6.9% | Jul 14, 2020 | A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu... |
| CVE-2020-1036 | CRITICAL | 9 | 6.2% | Jul 14, 2020 | A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu... |
| CVE-2020-1032 | CRITICAL | 9 | 5.5% | Jul 14, 2020 | A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu... |
| CVE-2020-1025 | CRITICAL | 9.8 | 5.9% | Jul 14, 2020 | An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly... |
| CVE-2020-15104 | MEDIUM | 5.4 | 0.3% | Jul 14, 2020 | In Envoy before versions 1.12.6, 1.13.4, 1.14.4, and 1.15.0 when validating TLS certificates, Envoy would incorrectly al... |
| CVE-2020-15101 | LOW | 3.3 | 0.6% | Jul 14, 2020 | In freewvs before 0.1.1, a directory structure of more than 1000 nested directories can interrupt a freewvs scan due to ... |
| CVE-2020-11084 | MEDIUM | 5.4 | 1.4% | Jul 14, 2020 | In iPear, the manual execution of the eval() function can lead to command injection. Only PCs where commands are manuall... |
| CVE-2020-5246 | MEDIUM | 6.5 | 0.9% | Jul 14, 2020 | Traccar GPS Tracking System before version 4.9 has a LDAP injection vulnerability. It occurs when user input is being us... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now