VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10355CVEs
CVE-2025-52453
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source modules) allows Resource Location Spoofing. This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Published 2025-07-25 · Analyzed
8.2EPSS 0.003
CVE-2025-52454
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector modules) allows Resource Location Spoofing. This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Published 2025-07-25 · Modified
8.2EPSS 0.003
CVE-2026-48290
CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-07-14 · Analyzed
8.2EPSS 0.003
CVE-2024-40702
IBM Cognos Controller improper certificate validation
Published 2025-01-07 · Analyzed
8.2EPSS 0.003
CVE-2022-42291
NVIDIA GeForce Experience contains a vulnerability in the installer, where a user installing the NVIDIA GeForce Experience software may inadvertently delete data from a linked location, which may lead to data tampering. An attacker does not have explicit control over the exploitation of this vulnerability, which requires the user to explicitly launch the installer from the compromised directory.
Published 2023-02-07 · Modified
8.2EPSS 0.002
CVE-2022-36396
Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmiEdit-Linux-5.27.06.0017 may allow a privileged user to potentially enable escalation of privilege via local access.
Published 2023-11-14 · Modified
8.2EPSS 0.002
CVE-2023-31027
CVE
Published 2023-11-02 · Modified
8.2EPSS 0.002
CVE-2024-0082
CVE
Published 2024-04-08 · Analyzed
8.2EPSS 0.002
CVE-2023-28385
Improper authorization in the Intel(R) NUC Pro Software Suite for Windows before version 2.0.0.9 may allow a privileged user to potentially enable escalation of privilage via local access.
Published 2023-08-11 · Modified
8.2EPSS 0.002
CVE-2023-28714
Improper access control in firmware for some Intel(R) PROSet/Wireless WiFi software for Windows before version 22.220 HF (Hot Fix) may allow a privileged user to potentially enable escalation of privilege via local access.
Published 2023-08-11 · Modified
8.2EPSS 0.002
CVE-2026-57239
Foxit PDF Editor/Reader Local Privilege Escalation
Published 2026-07-08 · Analyzed
8.2EPSS 0.002
CVE-2023-0975
A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace one of the Agent’s executables before it can be executed. This allows the user to elevate their permissions.
Published 2023-04-03 · Modified
8.2EPSS 0.002
CVE-2026-30785
RustDesk Encrypts Local Passwords with World-Readable Machine ID and Fixed Zero Nonce (XSalsa20-Poly1305)
Published 2026-03-05 · Analyzed
8.2EPSS 0.001
CVE-2017-12615
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
Published 2017-09-19 · Analyzed
8.1KEV1 PoCEPSS 0.996
CVE-2020-0601
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.
Published 2020-01-14 · Analyzed
8.1KEV1 PoCEPSS 0.894
CVE-2019-15637
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop.
Published 2019-08-26 · Modified
8.11 PoCEPSS 0.143
CVE-2025-68154
Command Injection in fsSize() on Windows
Published 2025-12-16 · Analyzed
8.1EPSS 0.130
CVE-2025-6554
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
Published 2025-06-30 · Analyzed
8.1KEVEPSS 0.126
CVE-2018-18865
The Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13) allow Credentials Disclosure.
Published 2018-11-20 · Modified
8.11 PoCEPSS 0.080
CVE-2018-20506
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.
Published 2019-04-03 · Modified
8.1EPSS 0.076
CVE-2016-1030
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to bypass intended access restrictions via unspecified vectors.
Published 2016-04-09 · Modified
8.1EPSS 0.048
CVE-2016-1006
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to bypass the ASLR protection mechanism via JIT data.
Published 2016-04-09 · Modified
8.1EPSS 0.039
CVE-2017-5556
The ConvertToPDF plugin in Foxit Reader before 8.2 and PhantomPDF before 8.2 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG image. The vulnerability could lead to information disclosure; an attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.
Published 2017-01-23 · Modified
8.1EPSS 0.038
CVE-2021-34551
PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname.
Published 2021-06-16 · Modified
8.1EPSS 0.028
CVE-2020-15605
If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2.0 SP2 could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass manager authentication. Enabling multi-factor authentication prevents this attack. Installations using manager native authentication or SAML authentication are not impacted by this vulnerability.
Published 2020-08-27 · Modified
8.1EPSS 0.026
CVE-2020-15601
If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Deep Security 10.x-12.x could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass manager authentication. Enabling multi-factor authentication prevents this attack. Installations using manager native authentication or SAML authentication are not impacted by this vulnerability.
Published 2020-08-27 · Modified
8.1EPSS 0.026
CVE-2024-20670
Outlook for Windows Spoofing Vulnerability
Published 2024-04-09 · Analyzed
8.1EPSS 0.023
CVE-2019-8162
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a race condition vulnerability. Successful exploitation could lead to arbitrary code execution .
Published 2019-10-17 · Modified
8.1EPSS 0.023
CVE-2021-28545
Acrobat Reader DC Missing Support for Integrity Check
Published 2021-04-01 · Modified
8.1EPSS 0.023
CVE-2023-35077
An out-of-bounds write vulnerability on windows operating systems causes the Ivanti AntiVirus Product to crash. Update to Ivanti AV Product version 7.9.1.285 or above.
Published 2023-07-21 · Modified
8.1EPSS 0.022
CVE-2025-61787
Deno is Vulnerable to Command Injection on Windows During Batch File Execution
Published 2025-10-08 · Analyzed
8.1EPSS 0.021
CVE-2024-38229
.NET and Visual Studio Remote Code Execution Vulnerability
Published 2024-10-08 · Modified
8.1EPSS 0.021
CVE-2018-4311
The issue was addressed by removing origin information. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
Published 2019-04-03 · Modified
8.1EPSS 0.021
CVE-2021-35221
ImportAlert Improper Access Control Tampering Vulnerability
Published 2021-08-31 · Modified
8.1EPSS 0.020
CVE-2018-17341
BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ substring, as demonstrated by a launch.php?bigtree_htaccess_url=admin/images/..\ URI.
Published 2018-09-23 · Modified
8.1EPSS 0.019
CVE-2018-16170
Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 for Windows allows remote authenticated attackers to read arbitrary files via unspecified vectors.
Published 2019-01-09 · Modified
8.1EPSS 0.017
CVE-2021-21172
Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 89.0.4389.72 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
Published 2021-03-09 · Modified
8.1EPSS 0.017
CVE-2016-10086
RESTful web services in CA Service Desk Manager 12.9 and CA Service Desk Management 14.1 might allow remote authenticated users to read or modify task information by leveraging incorrect permissions applied to a RESTful request.
Published 2017-01-18 · Modified
8.1EPSS 0.016
CVE-2016-8980
IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.
Published 2017-02-01 · Modified
8.1EPSS 0.015
CVE-2020-11493
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to Stream without concern for a crafted XObject.
Published 2020-09-04 · Modified
8.1EPSS 0.009
← Prev107 / 259Next →