58.450 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.450 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2020-1142 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then inst | 0.9% | — |
| CVE-2020-1141 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system. By itself, the information disclosure does not allow arb | 2.0% | — |
| CVE-2020-1140 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delet | 0.9% | — |
| CVE-2020-1139 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerabilit | 2.5% | — |
| CVE-2020-1138 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges on the victim system. To exploit the vulnerability, an attacker | 0.9% | — |
| CVE-2020-1137 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way the Windows Push Notification Service handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install prog | 0.9% | — |
| CVE-2020-1136 | HIGH 7.8 | microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user ri | 3.8% | — |
| CVE-2020-1135 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. In a local attack scenario, an attack | 1.0% | — |
| CVE-2020-1134 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit | 0.8% | — |
| CVE-2020-1133 | MED 5.5 | microsoft visual_studio <p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>An attacker could exp | 1.0% | — |
| CVE-2020-1132 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles file and folder links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. To exploit th | 0.9% | — |
| CVE-2020-1131 | MED 5.5 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit | 1.1% | — |
| CVE-2020-1130 | MED 6.6 | microsoft visual_studio <p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>An attacker could exp | 0.8% | — |
| CVE-2020-1129 | HIGH 8.8 | microsoft windows_10 <p>A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install prog | 4.2% | — |
| CVE-2020-1126 | HIGH 8.8 | microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user ri | 4.0% | — |
| CVE-2020-1125 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerabilit | 2.2% | — |
| CVE-2020-1124 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit | 0.8% | — |
| CVE-2020-1123 | MED 5.5 | microsoft windows_10 A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations. An attacker who successfully exploited this vulnerability could cause a system to stop responding. To exploit the vulnerability, | 1.1% | — |
| CVE-2020-1122 | MED 5.5 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Language Pack Installer improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>An attacker could exploi | 1.0% | — |
| CVE-2020-1121 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles calls to Clipboard Service. An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then in | 0.9% | — |
| CVE-2020-1120 | MED 5.5 | microsoft windows_10 A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-1244. | 1.3% | — |
| CVE-2020-1119 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists when StartTileData.dll improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.</p> <p>To exploit this vul | 1.1% | — |
| CVE-2020-1118 | HIGH 8.6 | microsoft windows_10 A denial of service vulnerability exists in the Windows implementation of Transport Layer Security (TLS) when it improperly handles certain key exchanges. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. | 14.7% | — |
| CVE-2020-1117 | HIGH 8.8 | microsoft windows_10 A remote code execution vulnerability exists in the way that the Color Management Module (ICM32.dll) handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install | 4.0% | — |
| CVE-2020-1116 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the use | 1.3% | — |