CVE-2020-1000 to CVE-2020-1999
40 CVEs with public proof-of-concept exploits.
- CVE-2020-10131 PoCGroup Policy Elevation of Privilege Vulnerability
- CVE-2020-10152 PoCsAn elevation of privilege vulnerability exists in the way that the User-Mode Power Service (UMPS) handles objects in memory, aka 'Windows…
- CVE-2020-10202 PoCsKEVA remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a…
- CVE-2020-10271 PoCKEVAn elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation…
- CVE-2020-10302 PoCsWindows Print Spooler Elevation of Privilege Vulnerability
- CVE-2020-10344 PoCsWindows Kernel Elevation of Privilege Vulnerability
- CVE-2020-104810 PoCsWindows Print Spooler Elevation of Privilege Vulnerability
- CVE-2020-10547 PoCsKEVWin32k Elevation of Privilege Vulnerability
- CVE-2020-10621 PoCInternet Explorer Memory Corruption Vulnerability
- CVE-2020-10663 PoCs.NET Framework Elevation of Privilege Vulnerability
- CVE-2020-11477 PoCsKEVA remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check…
- CVE-2020-11701 PoCAn elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the…
- CVE-2020-12068 PoCsAn information disclosure vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain…
- CVE-2020-12342 PoCsAn elevation of privilege vulnerability exists when Windows Error Reporting improperly handles objects in memory.To exploit this…
- CVE-2020-12831 PoCA denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.
- CVE-2020-13001 PoCA remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files.To exploit the vulnerability,…
- CVE-2020-13011 PoCA remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0 (SMBv1) server handles certain…
- CVE-2020-13134 PoCsAn elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file operations, aka…
- CVE-2020-13379 PoCsWindows Print Spooler Elevation of Privilege Vulnerability
- CVE-2020-13491 PoCA remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka…
- CVE-2020-135019 PoCsKEVA remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka…
- CVE-2020-13621 PoCAn elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows…
- CVE-2020-13941 PoCAn elevation of privilege vulnerability exists in the way that the Windows Geolocation Framework handles objects in memory, aka 'Windows…
- CVE-2020-14641 PoCKEVWindows Spoofing Vulnerability
- CVE-2020-147280 PoCsKEVNetlogon Elevation of Privilege Vulnerability
- CVE-2020-14811 PoCA remote code execution vulnerability exists in the ESLint extension for Visual Studio Code when it validates source code after opening a…
- CVE-2020-14931 PoCMicrosoft Outlook Information Disclosure Vulnerability
- CVE-2020-16111 PoCJunos Space: Malicious HTTP packets sent to Junos Space allow an attacker to view all files on the device.
- CVE-2020-16931 PoCA flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An…
- CVE-2020-17351 PoCA flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then…
- CVE-2020-17641 PoCA hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote…
- CVE-2020-19201 PoCA regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cause the application to use excessive…
- CVE-2020-193846 PoCsKEVWhen using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP…
- CVE-2020-19431 PoCData sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.
- CVE-2020-19477 PoCsIn Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML…
- CVE-2020-19485 PoCsThis vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service…
- CVE-2020-19562 PoCsKEVApache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string,…
- CVE-2020-19572 PoCsApache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an…
- CVE-2020-19581 PoCWhen LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the…
- CVE-2020-19712 PoCsEDIPARTYNAME NULL pointer dereference