Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2020-1228
<p>A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries. An attacker who successfully exploited this vuln…
Windows Server 2008
Patch available
HIGH 7.4
CVE-2020-1198
<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to a…
Sharepoint Enterprise Server
Patch available
HIGH 7.0
CVE-2020-1245
<p>An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who su…
Windows 10
Patch available
MEDIUM 6.6
CVE-2020-1130
<p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations. An attacker who suc…
Visual Studio
15.9.27 / 16.4.13+
MEDIUM 6.6
CVE-2020-1146
<p>An elevation of privilege vulnerability exists when the Microsoft Store Runtime improperly handles memory.</p>
<p>To exploit this vulnerability, a…
Windows 10
Patch available
MEDIUM 6.6
CVE-2020-1159
<p>An elevation of privilege vulnerability exists in the way that the StartTileData.dll handles file creation in protected locations. An attacker who…
Windows 10
Patch available
MEDIUM 5.8
CVE-2020-1152
<p>An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited the vul…
Windows 10
Patch available
MEDIUM 5.5
CVE-2020-1133
<p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles file operations. An attacker who suc…
Visual Studio
15.9.27 / 16.4.13+
MEDIUM 5.5
CVE-2020-1224
<p>An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the…
365 Apps
Patch available
MEDIUM 5.5
CVE-2020-1250
<p>An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An attacker who successfully expl…
Windows 10
Patch available
MEDIUM 5.4
CVE-2020-1227
<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to a…
Sharepoint Enterprise Server
Patch available
HIGH 8.8
CVE-2020-1129
<p>A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfu…
Windows 10
Patch available
HIGH 7.8
CVE-2020-1039
<p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successful…
Windows 10
Patch available
HIGH 7.8
CVE-2020-1052
<p>An elevation of privilege vulnerability exists in the way that the ssdpsrv.dll handles objects in memory. An attacker who successfully exploited t…
Windows 10
Patch available
HIGH 7.8
CVE-2020-1053
<p>An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vuln…
Windows 10
Patch available
HIGH 7.8
CVE-2020-1074EPSS 53%
<p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successful…
Windows 10
Patch available
HIGH 7.8
CVE-2020-1098
<p>An elevation of privilege vulnerability exists when the Shell infrastructure component improperly handles objects in memory. An attacker who succe…
Windows 10
Patch available
HIGH 7.8
CVE-2020-1115
<p>An elevation of privilege vulnerability exists when the <a href="https://technet.microsoft.com/library/security/dn848375.aspx#CLFS">Windows Common…
Windows 10
Patch available
MEDIUM 6.8
CVE-2020-1034
<p>An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploite…
Windows 10
Patch available
MEDIUM 6.5
CVE-2020-1091
<p>An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who suc…
Windows 10
Patch available
MEDIUM 6.5
CVE-2020-1097
<p>An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who suc…
Windows 10
Patch available
MEDIUM 5.5
CVE-2020-1038
<p>A denial of service vulnerability exists when Windows Routing Utilities improperly handles objects in memory. An attacker who successfully exploit…
Windows 10
Patch available
MEDIUM 5.5
CVE-2020-1083
<p>An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who…
Windows 10
Patch available
MEDIUM 5.5
CVE-2020-1119
<p>An information disclosure vulnerability exists when StartTileData.dll improperly handles objects in memory. An attacker who successfully exploited…
Windows 10
Patch available
MEDIUM 5.5
CVE-2020-1122
<p>An elevation of privilege vulnerability exists when the Windows Language Pack Installer improperly handles file operations. An attacker who succes…
Windows 10
Patch available
HIGH 8.4
CVE-2020-16875EPSS 47%
<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p>
<p>An attacker who s…
Exchange Server
Patch available
HIGH 7.8
CVE-2020-16874
<p>A remote code execution vulnerability exists in Visual Studio when it improperly handles objects in memory. An attacker who successfully exploited…
Visual Studio
after 16.6
HIGH 7.8
CVE-2020-16881EPSS 5%
<p>A remote code execution vulnerability exists in Visual Studio Code when a user is tricked into opening a malicious 'package.json' file. An attacke…
Visual Studio Code
1.48.1+
HIGH 7.8
CVE-2020-1030
<p>An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An a…
Windows 10
Patch available
HIGH 7.6
CVE-2020-16872
<p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request t…
Dynamics 365
Patch available