CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2020-1215

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1216, CVE-2020-1230, CVE-2020-1260.

    Published: 9 Jun 2020
    7.8
    High

    CVE-2020-1212

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when an OLE Automation component improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'OLE Automation Elevation of Privilege Vulnerability'.

    Published: 9 Jun 2020
    7.5
    High

    CVE-2020-1213

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1230, CVE-2020-1260.

    Published: 9 Jun 2020
    7.8
    High

    CVE-2020-1209

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Network List Service handles objects in memory, aka 'Windows Network List Service Elevation of Privilege Vulnerability'.

    Published: 9 Jun 2020
    7.8
    High

    CVE-2020-1211

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'.

    Published: 9 Jun 2020
    7.8
    High

    CVE-2020-1208

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1236.

    Published: 9 Jun 2020
    7.8
    High

    CVE-2020-1207

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1247, CVE-2020-1251, CVE-2020-1253, CVE-2020-1310.

    Published: 9 Jun 2020
    7.1
    High

    CVE-2020-1204

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'.

    Published: 9 Jun 2020
    7.8
    High

    CVE-2020-1203

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector fail to properly handle objects in memory, aka 'Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1202.

    Published: 9 Jun 2020
    7.5
    High

    CVE-2020-1206

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Information Disclosure Vulnerability'.

    Published: 9 Jun 2020
    7.8
    High

    CVE-2020-1201

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way the Windows Now Playing Session Manager handles objects in memory, aka 'Windows Now Playing Session Manager Elevation of Privilege Vulnerability'.

    Published: 9 Jun 2020
    7.8
    High

    CVE-2020-1202

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector fail to properly handle objects in memory, aka 'Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1203.

    Published: 9 Jun 2020
    7.8
    High

    CVE-2020-1197

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'.

    Published: 9 Jun 2020
    7.8
    High

    CVE-2020-1199

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when the Windows Feedback Hub improperly handles objects in memory, aka 'Windows Feedback Hub Elevation of Privilege Vulnerability'.

    Published: 9 Jun 2020
    5.5
    Medium

    CVE-2020-1194

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists when Windows Registry improperly handles filesystem operations, aka 'Windows Registry Denial of Service Vulnerability'.

    Published: 9 Jun 2020
    7.8
    High

    CVE-2020-1196

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the printconfig.dll handles objects in memory, aka 'Windows Print Configuration Elevation of Privilege Vulnerability'.

    Published: 9 Jun 2020
    8.8
    High

    CVE-2020-1181

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Execution Vulnerability'.

    Published: 9 Jun 2020
    5.4
    Medium

    CVE-2020-1183

    Last Modified: 28 Feb 2025

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1177, CVE-2020-1297, CVE-2020-1298, CVE-2020-1318, CVE-2020-1320.

    Published: 9 Jun 2020
    8.8
    High

    CVE-2020-1178

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authentication request to an affected SharePoint server, aka 'Microsoft SharePoint Server Elevation of Privilege Vulnerability'.

    Published: 9 Jun 2020
    5.4
    Medium

    CVE-2020-1177

    Last Modified: 28 Feb 2025

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1183, CVE-2020-1297, CVE-2020-1298, CVE-2020-1318, CVE-2020-1320.

    Published: 9 Jun 2020
    7.8
    High

    CVE-2020-1170

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1163.

    Published: 9 Jun 2020
    7.8
    High

    CVE-2020-1163

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1170.

    Published: 9 Jun 2020
    7.8
    High

    CVE-2020-1162

    Last Modified: 21 Nov 2024

    An elevation of privilege (user to user) vulnerability exists in Windows Security Health Service when handling certain objects in memory.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1324.

    Published: 9 Jun 2020
    5.4
    Medium

    CVE-2020-1148

    Last Modified: 21 Nov 2024

    A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1289.

    Published: 9 Jun 2020
    5.5
    Medium

    CVE-2020-1160

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'.

    Published: 9 Jun 2020
    8.1
    High

    CVE-2020-1073

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'.

    Published: 9 Jun 2020
    5.5
    Medium

    CVE-2020-1120

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-1244.

    Published: 9 Jun 2020
    7.8
    High

    CVE-2020-0986

    Last Modified: 29 Oct 2025

    An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-1276, CVE-2020-1307, CVE-2020-1316.

    Published: 9 Jun 2020
    7.8
    High

    CVE-2020-0916

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, aka 'Windows GDI Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0915.

    Published: 9 Jun 2020
    7.8
    High

    CVE-2020-0915

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, aka 'Windows GDI Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0916.

    Published: 9 Jun 2020
    6.8
    Medium

    CVE-2020-7456

    Last Modified: 21 Nov 2024

    In FreeBSD 12.1-STABLE before r361918, 12.1-RELEASE before p6, 11.4-STABLE before r361919, 11.3-RELEASE before p10, and 11.4-RC2 before p1, an invalid memory location may be used for HID items if the push/pop level is not restored within the processing of that HID item allowing an attacker with physical access to a USB port to be able to use a specially crafted USB device to gain kernel or user-space code execution.

    Published: 9 Jun 2020
    8.8
    High

    CVE-2020-13872

    Last Modified: 21 Nov 2024

    Royal TS before 5 has a 0.0.0.0 listener, which makes it easier for attackers to bypass tunnel authentication via a brute-force approach.

    Published: 9 Jun 2020
    7.5
    High

    CVE-2020-11957

    Last Modified: 21 Nov 2024

    The Bluetooth Low Energy implementation in Cypress PSoC Creator BLE 4.2 component versions before 3.64 generates a random number (Pairing Random) with significantly less entropy than the specified 128 bits during BLE pairing. This is the case for both authenticated and unauthenticated pairing with both LE Secure Connections as well as LE Legacy Pairing. A predictable or brute-forceable random number allows an attacker (in radio range) to perform a MITM attack during BLE pairing.

    Published: 9 Jun 2020
    9.8
    Critical

    CVE-2020-6265

    Last Modified: 21 Nov 2024

    SAP Commerce, versions - 6.7, 1808, 1811, 1905, and SAP Commerce (Data Hub), versions - 6.7, 1808, 1811, 1905, allows an attacker to bypass the authentication and/or authorization that has been configured by the system administrator due to the use of Hardcoded Credentials.

    Published: 9 Jun 2020
    5.4
    Medium

    CVE-2020-13911

    Last Modified: 21 Nov 2024

    Your Online Shop 1.8.0 allows authenticated users to trigger XSS via a Change Name or Change Surname operation.

    Published: 9 Jun 2020
    7.5
    High

    CVE-2020-12000

    Last Modified: 21 Nov 2024

    The affected product is vulnerable to the handling of serialized data. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (versions prior to 7.9.14), allowing an attacker to obtain sensitive information.

    Published: 9 Jun 2020
    7.5
    High

    CVE-2020-10644

    Last Modified: 21 Nov 2024

    The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (versions prior to 7.9.14), allowing an attacker to obtain sensitive information.

    Published: 9 Jun 2020
    5.4
    Medium

    CVE-2020-13892

    Last Modified: 21 Nov 2024

    The SportsPress plugin before 2.7.2 for WordPress allows XSS.

    Published: 9 Jun 2020
    7.5
    High

    CVE-2020-12004

    Last Modified: 21 Nov 2024

    The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (versions prior to 7.9.14), allowing an attacker to obtain sensitive information.

    Published: 9 Jun 2020
    10
    Critical

    CVE-2020-9412

    Last Modified: 21 Nov 2024

    The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vulnerability that theoretically allows execution of arbitrary commands at the privilege level of the affected system following a failed file transfer. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i: versions 7.1.0 and below, version 8.0.0.

    Published: 9 Jun 2020
    10
    Critical

    CVE-2020-9411

    Last Modified: 21 Nov 2024

    The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vulnerability that theoretically allows an attacker to perform unauthorized network file transfers to and from the file system accessible to the affected component. This vulnerability is exploitable when the configuration option 'Require Node Resp' is set to 'No'. In the event of a successful exploit, the attacker could theoretically read and write any file on the file system accessible to the affected component, thus fully affecting the confidentiality, integrity, and availability of the operating system hosting the deployment of the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i: versions 7.1.0 and below, version 8.0.0.

    Published: 9 Jun 2020
    5.5
    Medium

    CVE-2020-10766

    Last Modified: 21 Nov 2024

    A logic bug flaw was found in Linux kernel before 5.8-rc1 in the implementation of SSBD. A bug in the logic handling allows an attacker with a local account to disable SSBD protection during a context switch when additional speculative execution mitigations are in place. This issue was introduced when the per task/process conditional STIPB switching was added on top of the existing SSBD switching. The highest threat from this vulnerability is to confidentiality.

    Published: 9 Jun 2020
    5.5
    Medium

    CVE-2020-0543

    Last Modified: 21 Nov 2024

    Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 9 Jun 2020
    9.8
    Critical

    CVE-2020-13160

    Last Modified: 21 Nov 2024

    AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.

    Published: 9 Jun 2020
    7.8
    High

    CVE-2020-9852

    Last Modified: 21 Nov 2024

    An integer overflow was addressed through improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 9 Jun 2020
    9.8
    Critical

    CVE-2020-9850

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. A remote attacker may be able to cause arbitrary code execution.

    Published: 9 Jun 2020
    5.3
    Medium

    CVE-2020-9856

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. An application may be able to gain elevated privileges.

    Published: 9 Jun 2020
    7.1
    High

    CVE-2020-9843

    Last Modified: 21 Nov 2024

    An input validation issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to a cross site scripting attack.

    Published: 9 Jun 2020
    7.8
    High

    CVE-2020-9858

    Last Modified: 21 Nov 2024

    A dynamic library loading issue was addressed with improved path searching. This issue is fixed in Windows Migration Assistant 2.2.0.0 (v. 1A11). Running the installer in an untrusted directory may result in arbitrary code execution.

    Published: 9 Jun 2020
    2.4
    Low

    CVE-2020-9848

    Last Modified: 21 Nov 2024

    An authorization issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5. A person with physical access to an iOS device may be able to view notification contents from the lockscreen.

    Published: 9 Jun 2020