CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2020-0652

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Memory Corruption Vulnerability'.

    Published: 14 Jan 2020
    5.4
    Medium

    CVE-2020-0647

    Last Modified: 21 Nov 2024

    A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications correctly, aka 'Microsoft Office Online Spoofing Vulnerability'.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0650

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0651, CVE-2020-0653.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0651

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0650, CVE-2020-0653.

    Published: 14 Jan 2020
    9.8
    Critical

    CVE-2020-0646

    Last Modified: 29 Oct 2025

    A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0644

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when Microsoft Windows implements predictable memory section names, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0635.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0642

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0624.

    Published: 14 Jan 2020
    5.5
    Medium

    CVE-2020-0643

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface Plus (GDI+) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI+ Information Disclosure Vulnerability'.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0641

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege Vulnerability'.

    Published: 14 Jan 2020
    7.5
    High

    CVE-2020-0640

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0638

    Last Modified: 29 Oct 2025

    An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'.

    Published: 14 Jan 2020
    6.5
    Medium

    CVE-2020-0637

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when Remote Desktop Web Access improperly handles credential information, aka 'Remote Desktop Web Access Information Disclosure Vulnerability'.

    Published: 14 Jan 2020
    5.5
    Medium

    CVE-2020-0639

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0615.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0635

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0644.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0636

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Subsystem for Linux handles files, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0634

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0633

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0630

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0631

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0632, CVE-2020-0633.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0632

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0633.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0629

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0628

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0626

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0627

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0624

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0642.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0625

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0623

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.

    Published: 14 Jan 2020
    5.5
    Medium

    CVE-2020-0622

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'.

    Published: 14 Jan 2020
    6
    Medium

    CVE-2020-0617

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists when Microsoft Hyper-V Virtual PCI on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Hyper-V Denial of Service Vulnerability'.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0620

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when Microsoft Cryptographic Services improperly handles files, aka 'Microsoft Cryptographic Services Elevation of Privilege Vulnerability'.

    Published: 14 Jan 2020
    4.4
    Medium

    CVE-2020-0621

    Last Modified: 21 Nov 2024

    A security feature bypass vulnerability exists in Windows 10 when third party filters are called during a password update, aka 'Windows Security Feature Bypass Vulnerability'.

    Published: 14 Jan 2020
    5.5
    Medium

    CVE-2020-0616

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.

    Published: 14 Jan 2020
    5.5
    Medium

    CVE-2020-0615

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0639.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0613

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2020-0614

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.

    Published: 14 Jan 2020
    7.5
    High

    CVE-2020-0612

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability'.

    Published: 14 Jan 2020
    7.5
    High

    CVE-2020-0611

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.

    Published: 14 Jan 2020
    5.5
    Medium

    CVE-2020-0608

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.

    Published: 14 Jan 2020
    9.8
    Critical

    CVE-2020-0610

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0609.

    Published: 14 Jan 2020
    9.8
    Critical

    CVE-2020-0609

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0610.

    Published: 14 Jan 2020
    5.5
    Medium

    CVE-2020-0607

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Information Disclosure Vulnerability'.

    Published: 14 Jan 2020
    8.1
    High

    CVE-2020-0601

    Last Modified: 29 Oct 2025

    A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.

    Published: 14 Jan 2020
    5.3
    Medium

    CVE-2020-7057

    Last Modified: 21 Nov 2024

    Hikvision DVR DS-7204HGHI-F1 V4.0.1 build 180903 Web Version sends a different response for failed ISAPI/Security/sessionLogin/capabilities login attempts depending on whether the user account exists, which might make it easier to enumerate users. However, only about 4 or 5 failed logins are allowed.

    Published: 14 Jan 2020
    9.8
    Critical

    CVE-2011-2715

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.

    Published: 14 Jan 2020
    6.1
    Medium

    CVE-2011-2714

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display.

    Published: 14 Jan 2020
    6.1
    Medium

    CVE-2011-2706

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71.

    Published: 14 Jan 2020
    7.8
    High

    CVE-2016-6592

    Last Modified: 21 Nov 2024

    A vulnerability was found in Symantec Norton Download Manager versions prior to 5.6. A remote user can create a specially crafted DLL file that, when placed on the target user's system, will cause the Norton Download Manager component to load the remote user's DLL instead of the intended DLL and execute arbitrary code when the Norton Download Manager component is run by the target user.

    Published: 14 Jan 2020
    8.8
    High

    CVE-2020-7054

    Last Modified: 21 Nov 2024

    MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c in libIEC61850 through 1.4.0 has a heap-based buffer overflow when parsing the MMS_BIT_STRING data type.

    Published: 14 Jan 2020
    7.2
    High

    CVE-2011-2933

    Last Modified: 21 Nov 2024

    An Arbitrary File Upload vulnerability exists in admin/media/upload.php in WebsiteBaker 2.8.1 and earlier due to a failure to restrict uploaded files with .htaccess, .php4, .php5, and .phtl extensions.

    Published: 14 Jan 2020
    8.8
    High

    CVE-2011-2934

    Last Modified: 21 Nov 2024

    A Cross Site Request Forgery (CSRF) vulnerability exists in the administrator functions in WebsiteBaker 2.8.1 and earlier due to inadequate confirmation for sensitive transactions.

    Published: 14 Jan 2020