VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10355CVEs
CVE-2026-30795
RustDesk HTTP Client Silently Accepts Invalid TLS Certificates After Handshake Failure
Published 2026-03-05 · Analyzed
8.7EPSS 0.003
CVE-2026-3598
RustDesk Server Generates Config Strings Using Reversible Encoding (Base64 + Reverse) Instead of Encryption
Published 2026-03-05 · Analyzed
8.7EPSS 0.003
CVE-2023-34120
Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges.
Published 2023-06-13 · Modified
8.7EPSS 0.001
CVE-2025-49154
An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have severe consequences for the security and stability of affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Published 2025-06-17 · Analyzed
8.7EPSS 0.001
CVE-2022-41953
Git clone remote code execution vulnerability in git-for-windows
Published 2023-01-17 · Modified
8.6EPSS 0.068
CVE-2021-21006
Heap buffer overflow when handling crafted font file could lead to arbitrary code execution
Published 2021-01-13 · Modified
8.6EPSS 0.056
CVE-2021-21009
Server-side request forgery (SSRF) in Campaign Classic could lead to sensitive information disclosure
Published 2021-01-13 · Analyzed
8.6EPSS 0.030
CVE-2026-34621
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
Published 2026-04-11 · Analyzed
8.6KEVEPSS 0.022
CVE-2022-28199
NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.
Published 2022-09-01 · Modified
8.6EPSS 0.022
CVE-2021-37712
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links
Published 2021-08-31 · Modified
8.6EPSS 0.019
CVE-2020-3944
vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) has an improper trust store configuration leading to authentication bypass. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to bypass Adapter authentication.
Published 2020-02-19 · Modified
8.6EPSS 0.015
CVE-2021-37713
Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization
Published 2021-08-31 · Modified
8.6EPSS 0.013
CVE-2020-7858
AquaNPlayer directory traversing vulnerability
Published 2021-04-22 · Modified
8.6EPSS 0.011
CVE-2026-48397
Lightroom Classic | Deserialization of Untrusted Data (CWE-502)
Published 2026-08-11 · Analyzed
8.6EPSS 0.010
CVE-2018-4269
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
Published 2019-04-03 · Modified
8.6EPSS 0.010
CVE-2026-21267
Dreamweaver Desktop | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2026-01-13 · Analyzed
8.6EPSS 0.008
CVE-2023-4576
Integer Overflow in RecordedSourceSurfaceCreation
Published 2023-09-11 · Modified
8.6EPSS 0.008
CVE-2026-48448
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2026-07-30 · Analyzed
8.6EPSS 0.008
CVE-2020-11862
Insecure renegotiation in SSL protocol caused Denial of service attack in Privileged Account Manager
Published 2024-03-13 · Analyzed
8.6EPSS 0.007
CVE-2023-40185
Shescape on Windows escaping may be bypassed in threaded context
Published 2023-08-23 · Modified
8.6EPSS 0.007
CVE-2026-34622
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
Published 2026-04-14 · Analyzed
8.6EPSS 0.007
CVE-2019-3654
Client Proxy (MCP) - Authentication Bypass vulnerability
Published 2019-11-22 · Modified
8.6EPSS 0.007
CVE-2021-26603
bandisoft ARK library heap overflow vulnerability
Published 2021-09-09 · Modified
8.6EPSS 0.007
CVE-2026-34689
Adobe Connect | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-09-22 · Analyzed
8.6EPSS 0.007
CVE-2024-4944
Mobile VPN with SSL Local Privilege Escalation Vulnerability
Published 2024-07-09 · Modified
8.6EPSS 0.003
CVE-2026-48350
Animate | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-07-14 · Analyzed
8.6EPSS 0.003
CVE-2026-48441
Lightroom Classic | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-08-11 · Analyzed
8.6EPSS 0.003
CVE-2026-48275
Illustrator | Untrusted Search Path (CWE-426)
Published 2026-07-14 · Analyzed
8.6EPSS 0.003
CVE-2026-27290
Adobe Framemaker | Untrusted Search Path (CWE-426)
Published 2026-04-14 · Analyzed
8.6EPSS 0.003
CVE-2026-47906
Dreamweaver Desktop | Dependency on Vulnerable Third-Party Component (CWE-1395)
Published 2026-06-09 · Analyzed
8.6EPSS 0.003
CVE-2026-76199
Photoshop Desktop | Uncontrolled Search Path Element (CWE-427)
Published 2026-09-08 · Analyzed
8.6EPSS 0.003
CVE-2026-19305
Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components
Published 2026-09-04 · Analyzed
8.6EPSS 0.003
CVE-2026-47907
Dreamweaver Desktop | Improper Access Control (CWE-284)
Published 2026-06-09 · Analyzed
8.6EPSS 0.003
CVE-2026-21280
Illustrator | Untrusted Search Path (CWE-426)
Published 2026-01-13 · Analyzed
8.6EPSS 0.003
CVE-2026-21271
Dreamweaver Desktop | Improper Input Validation (CWE-20)
Published 2026-01-13 · Analyzed
8.6EPSS 0.002
CVE-2026-21268
Dreamweaver Desktop | Improper Input Validation (CWE-20)
Published 2026-01-13 · Analyzed
8.6EPSS 0.002
CVE-2025-64298
Mirion Medical EC2 Software NMIS BioDose Incorrect Permission Assignment for Critical Resource
Published 2025-12-02 · Analyzed
8.6EPSS 0.002
CVE-2026-21272
Dreamweaver Desktop | Improper Input Validation (CWE-20)
Published 2026-01-13 · Analyzed
8.6EPSS 0.002
CVE-2026-23512
SumatraPDF has an Untrusted Search Path in sumatrapdf/src/AppTools.cpp
Published 2026-01-14 · Analyzed
8.6EPSS 0.002
CVE-2025-54256
Dreamweaver Desktop | Cross-Site Request Forgery (CSRF) (CWE-352)
Published 2025-09-09 · Analyzed
8.6EPSS 0.002
← Prev100 / 259Next →