CVE-2020-16961: Windows Backup Engine Elevation of Privilege Vulnerability
Windows Backup Engine Elevation of Privilege Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Browse CVE records published in 2020 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.
Showing 50 of 19384 matching CVEs · Page 5 of 388.
Windows Backup Engine Elevation of Privilege Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Windows Backup Engine Elevation of Privilege Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Windows Backup Engine Elevation of Privilege Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Windows Backup Engine Elevation of Privilege Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Visual Studio Remote Code Execution Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Visual Studio Code Remote Code Execution Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Dynamics CRM Webclient Cross-site Scripting Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft Exchange Remote Code Execution Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft Exchange Server Information Disclosure Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft Exchange Remote Code Execution Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft Exchange Remote Code Execution Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Windows Overlay Filter Security Feature Bypass Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Windows Error Reporting Information Disclosure Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
DirectX Graphics Kernel Elevation of Privilege Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Azure DevOps Server Spoofing Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft Exchange Remote Code Execution Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft Outlook Information Disclosure Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft SharePoint Remote Code Execution Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft Exchange Remote Code Execution Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Windows Lock Screen Security Feature Bypass Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Windows GDI+ Information Disclosure Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Windows Digital Media Receiver Elevation of Privilege Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Windows NTFS Remote Code Execution Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Windows Hyper-V Remote Code Execution Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Windows Error Reporting Information Disclosure Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Windows Network Connections Service Elevation of Privilege Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft SharePoint Elevation of Privilege Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
HelloTalk through 3.4.1 stores full-precision GPS coordinates even when the user had intended to share only a country or city. Furthermore, these coordinates are placed into a database on the client of other users. (The client side was changed in 2019 to encrypt that database.)
Published Jun 5, 2026 · Updated Jun 5, 2026
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic key utilized to help protect the account password is hard coded into the RSLogix 500 binary file. An attacker could identify cryptographic keys and use it for further cryptographic attacks that could ultimately lead to a remote attacker gaining unauthorized access to the controller.
Published Mar 16, 2020 · Updated Jun 3, 2026
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic function utilized to protect the password in MicroLogix is discoverable.
Published Mar 16, 2020 · Updated Jun 3, 2026
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, A remote, unauthenticated attacker can send a request from the RSLogix 500 software to the victim’s MicroLogix controller. The controller will then respond to the client with used password values to authenticate the user on the client-side. This method of authentication may allow an attacker to bypass authentication altogether, disclose sensitive information, or leak credentials.
Published Mar 16, 2020 · Updated Jun 3, 2026
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), Nucleus NET (All versions < V5.2), Nucleus ReadyStart V3 (All versions < V2012.12), Nucleus Source Code (All versions), PLUSCONTROL 1st Gen (All versions), TALON TC Compact (BACnet) (All versions < V3.5.5), TALON TC Modular (BACnet) (All versions < V3.5.5). Initial Sequence Numbers (ISNs) for TCP connections are derived from an insufficiently random source. As a result, the ISN of current and future TCP connections could be predictable. An attacker could hijack existing sessions or spoof future ones.
Published Feb 9, 2021 · Updated Jun 2, 2026
An attacker could send a specially crafted message to Crimson 3.1 (Build versions prior to 3119.001) that could leak arbitrary memory locations.
Published Jan 6, 2021 · Updated Jun 2, 2026
A NULL pointer deference vulnerability has been identified in the protocol converter. An attacker could send a specially crafted packet that could reboot the device running Crimson 3.1 (Build versions prior to 3119.001).
Published Jan 6, 2021 · Updated Jun 2, 2026
The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify the database without authentication.
Published Jan 6, 2021 · Updated Jun 2, 2026
In all versions of Omron PLC CJ Series, an attacker can send a series of specific data packets within a short period, causing a service error on the PLC Ethernet module, which in turn causes a PLC service denied result.
Published Mar 5, 2020 · Updated Jun 2, 2026
A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V16), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions <= V16), SIMATIC HMI Mobile Panels (All versions <= V16), SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected devices insufficiently block excessive authentication attempts. This could allow a remote attacker to discover user passwords and obtain access to the Sm@rt Server via a brute-force attack.
Published Sep 9, 2020 · Updated Jun 2, 2026
A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP Mobile Panels (All versions < V16 Update 3a), SINAMICS GH150 (All versions), SINAMICS GL150 (with option X30) (All versions), SINAMICS GM150 (with option X30) (All versions), SINAMICS SH150 (All versions), SINAMICS SL150 (All versions), SINAMICS SM120 (All versions), SINAMICS SM150 (All versions), SINAMICS SM150i (All versions). Affected devices with enabled telnet service do not require authentication for this service. This could allow a remote attacker to gain full access to the device. (ZDI-CAN-12046)
Published Feb 9, 2021 · Updated Jun 2, 2026
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions < V4.5.0), SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V2.9.2), SIMATIC S7-1500 Software Controller (All versions < V21.9), SIMATIC S7-PLCSIM Advanced (All versions < V4.0), SINAMICS PERFECT HARMONY GH180 Drives (Drives manufactured before 2021-08-13), SINUMERIK MC (All versions < V6.15), SINUMERIK ONE (All versions < V6.15). Affected devices are vulnerable to a memory protection bypass through a specific operation. A remote unauthenticated attacker with network access to port 102/tcp could potentially write arbitrary data and code to protected memory areas or read sensitive data to launch further attacks.
Published May 28, 2021 · Updated Jun 2, 2026
A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-400 CPU family (incl. SIPLUS variants) (All versions), SIMATIC WinAC RTX (F) 2010 (All versions), SINUMERIK 840D sl (All versions). The authentication protocol between a client and a PLC via port 102/tcp (ISO-TSAP) insufficiently protects the transmitted password. This could allow an attacker that is able to intercept the network traffic to obtain valid PLC credentials.
Published Sep 9, 2020 · Updated Jun 2, 2026
A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC TDC CPU555 (All versions), SINUMERIK 840D sl (All versions). Sending multiple specially crafted packets to the affected devices could cause a Denial-of-Service on port 102. A cold restart is required to recover the service.
Published Nov 12, 2020 · Updated Jun 2, 2026
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.
Published May 11, 2021 · Updated Jun 2, 2026
As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Services, Pods, Nodes, or StorageClass service providers. As part of this mitigation Kubernetes does a DNS name resolution check and validates that response IPs are not in the link-local (169.254.0.0/16) or localhost (127.0.0.0/8) range. Kubernetes then performs a second DNS resolution without validation for the actual connection. If a non-standard DNS server returns different non-cached responses, a user may be able to bypass the proxy IP restriction and access private networks on the control plane.
Published Feb 1, 2022 · Updated Jun 1, 2026
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs.
Published Sep 20, 2021 · Updated Jun 1, 2026