2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-8323MEDIUM6.7A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStatio...
CVE-2020-8322MEDIUM6.7A potential vulnerability in the SMI callback function used in the Legacy USB driver in some Lenovo Notebook and ThinkSt...
CVE-2020-8321MEDIUM6.7A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Not...
CVE-2020-8320MEDIUM6.8An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
CVE-2020-1348MEDIUM6.5An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m...
CVE-2020-1343MEDIUM5.9An information disclosure vulnerability exists in Visual Studio Code Live Share Extension when it exposes tokens in plai...
CVE-2020-1340MEDIUM5.4A spoofing vulnerability exists when the NuGetGallery does not properly sanitize input on package metadata values, aka '...
CVE-2020-1334HIGH7.8An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windo...
CVE-2020-1331MEDIUM5.4A spoofing vulnerability exists when System Center Operations Manager (SCOM) does not properly sanitize a specially craf...
CVE-2020-1329MEDIUM6.5A spoofing vulnerability exists when Microsoft Bing Search for Android improperly handles specific HTML content, aka 'Mi...
CVE-2020-1327MEDIUM6.1A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azu...
CVE-2020-1324HIGH7.8An elevation of privilege (user to user) vulnerability exists in Windows Security Health Service when handling certain o...
CVE-2020-1323MEDIUM6.1An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, ...
CVE-2020-1322MEDIUM6.5An information disclosure vulnerability exists when Microsoft Project reads out of bound memory due to an uninitialized ...
CVE-2020-1321HIGH8.8A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in me...
CVE-2020-1320MEDIUM5.4A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall...
CVE-2020-1318MEDIUM5.4A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall...
CVE-2020-1317HIGH8.8An elevation of privilege vulnerability exists when Group Policy improperly checks access, aka 'Group Policy Elevation o...
CVE-2020-1316HIGH7.8An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka '...
CVE-2020-1315MEDIUM5.3An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory, aka 'Interne...
CVE-2020-1314HIGH7.8An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server fails to prop...
CVE-2020-1313HIGH7.8An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file oper...
CVE-2020-1312HIGH7.8An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain...
CVE-2020-1311HIGH7.8An elevation of privilege vulnerability exists when Component Object Model (COM) client uses special case IIDs, aka 'Com...
CVE-2020-1310MEDIUM6.7An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now