Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2020-10548 CVE-2020-10548 HIGH N/A 36.51% cvelistv5
cve-2020-10546 CVE-2020-10546 HIGH N/A 87.33% cvelistv5
cve-2020-1054 Microsoft Win32k Privilege Escalation Vulnerability HIGH 7.0 54.16% cvelistv5 2021-11-03
cve-2020-1040 A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043. CRITICAL 9.0 7.32% cvelistv5 2026-06-17
cve-2020-1027 Microsoft Windows Kernel Privilege Escalation Vulnerability HIGH 7.8 4.55% cvelistv5 2022-05-23
cve-2020-10221 lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the fileName POST parameter. HIGH 8.8 80.22% cvelistv5 2026-06-17
cve-2020-10215 CVE-2020-10215 HIGH N/A 5.25% cvelistv5
cve-2020-1020 Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability HIGH 8.8 65.04% cvelistv5 2021-11-03
cve-2020-10199 Sonatype Nexus Repository Remote Code Execution Vulnerability HIGH 8.8 99.06% cvelistv5 2021-11-03
cve-2020-10189 Zoho ManageEngine Desktop Central File Upload Vulnerability CRITICAL 9.8 99.94% cvelistv5 2021-11-03
cve-2020-10181 Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability CRITICAL 9.8 14.67% cvelistv5 2021-11-03
cve-2020-10173 CVE-2020-10173 HIGH N/A 77.13% cvelistv5
cve-2020-10148 SolarWinds Orion Authentication Bypass Vulnerability CRITICAL 9.8 91.98% cvelistv5 2021-11-03
cve-2020-0986 Microsoft Windows Kernel Privilege Escalation Vulnerability HIGH 7.8 15.93% cvelistv5 2021-11-03
cve-2020-0968 Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability HIGH 7.5 30.68% cvelistv5 2021-11-03
cve-2020-0938 A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1020. HIGH 7.8 69.17% cvelistv5 2026-06-17
cve-2020-0878 Microsoft Edge and Internet Explorer Memory Corruption Vulnerability MEDIUM 4.2 2.70% cvelistv5 2021-11-03
cve-2020-0796 Microsoft SMBv3 Remote Code Execution Vulnerability CRITICAL 10.0 99.81% cvelistv5 2022-02-10
cve-2020-0787 Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability HIGH 7.8 42.52% cvelistv5 2022-01-28
cve-2020-0688 Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability CRITICAL N/A 99.96% cvelistv5 2021-11-03
cve-2020-0683 Microsoft Windows Installer Privilege Escalation Vulnerability HIGH N/A 7.61% cvelistv5 2021-11-03
cve-2020-0674 Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability HIGH 7.5 86.86% cvelistv5 2021-11-03
cve-2020-0646 Microsoft .NET Framework Remote Code Execution Vulnerability CRITICAL 9.8 99.22% cvelistv5 2021-11-03
cve-2020-0638 An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'. HIGH 7.8 3.04% cvelistv5 2026-08-12
cve-2020-0618 Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability HIGH 8.8 99.02% cvelistv5 2024-09-18
cve-2020-0601 Microsoft Windows CryptoAPI Spoofing Vulnerability HIGH N/A 89.44% cvelistv5 2021-11-03
cve-2020-0069 Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability HIGH 7.8 1.37% cvelistv5 2021-11-03
cve-2020-0041 In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-145988638References: Upstream kernel HIGH 7.8 3.22% cvelistv5 2026-06-17
cve-2019-9978 WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability MEDIUM 6.1 72.95% cvelistv5 2021-11-03
cve-2019-9875 Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability HIGH N/A 13.79% cvelistv5 2025-03-26