VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10355CVEs
CVE-2021-26613
tobesoft nexacro arbitrary file creation vulnerability
Published 2022-02-09 · Modified
8.1EPSS 0.008
CVE-2021-29968
When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.0.1.
Published 2021-06-24 · Modified
8.1EPSS 0.008
CVE-2017-5035
Google Chrome prior to 57.0.2987.98 for Windows and Mac had a race condition, which could cause Chrome to display incorrect certificate information for a site.
Published 2017-04-24 · Modified
8.1EPSS 0.008
CVE-2023-25734
After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Published 2023-06-02 · Modified
8.1EPSS 0.008
CVE-2023-44154
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
Published 2023-09-27 · Modified
8.1EPSS 0.008
CVE-2023-40363
IBM InfoSphere Information Server privilege escalation
Published 2023-11-18 · Modified
8.1EPSS 0.006
CVE-2016-1203
Improper file verification vulnerability in SaAT Netizen installer ver.1.2.0.424 and earlier, and SaAT Netizen ver.1.2.0.8 (Build427) and earlier allows a remote unauthenticated attacker to conduct a man-in-the-middle attack. A successful exploitation may result in a malicious file being downloaded and executed.
Published 2023-10-31 · Modified
8.1EPSS 0.006
CVE-2026-7872
Path Traversal Vulnerability in File Component Leading to Arbitrary File Read and Authentication Bypass
Published 2026-07-17 · Analyzed
8.1EPSS 0.006
CVE-2026-79194
Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)
Published 2026-08-25 · Analyzed
8.1EPSS 0.006
CVE-2023-38738
IBM OpenPages with Watson information disclosure
Published 2024-01-19 · Modified
8.1EPSS 0.005
CVE-2026-49402
Deno: Command Injection via spawnSync & spawn on Windows
Published 2026-06-23 · Analyzed
8.1EPSS 0.004
CVE-2023-31167
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Published 2023-08-31 · Modified
8.1EPSS 0.004
CVE-2026-13787
Use after free in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
Published 2026-06-30 · Analyzed
8.1EPSS 0.004
CVE-2025-1915
Improper Limitation of a Pathname to a Restricted Directory in DevTools in Google Chrome on Windows prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)
Published 2025-03-05 · Analyzed
8.1EPSS 0.004
CVE-2026-19303
Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing components
Published 2026-09-04 · Analyzed
8.1EPSS 0.004
CVE-2026-7347
Use after free in Chromoting in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)
Published 2026-04-28 · Analyzed
8.1EPSS 0.004
CVE-2025-49552
Adobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79)
Published 2025-10-14 · Analyzed
8.1EPSS 0.004
CVE-2026-14111
Use after free in WebProtect in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Low)
Published 2026-06-30 · Analyzed
8.1EPSS 0.004
CVE-2024-45761
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. A remote low-privileged malicious user could potentially exploit this vulnerability to load any web plugins or Java class leading to the possibility of altering the behavior of certain apps/OS or Denial of Service.
Published 2024-12-09 · Analyzed
8.1EPSS 0.004
CVE-2025-52447
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initial-sql tabdoc command modules) allows Interface Manipulation (data access to the production database cluster). This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Published 2025-07-25 · Analyzed
8.1EPSS 0.004
CVE-2025-52448
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modules) allows Interface Manipulation (data access to the production database cluster). This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Published 2025-07-25 · Analyzed
8.1EPSS 0.004
CVE-2026-13445
Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
Published 2026-07-17 · Analyzed
8.1EPSS 0.004
CVE-2026-13791
Insufficient validation of untrusted input in Downloads in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High)
Published 2026-06-30 · Analyzed
8.1EPSS 0.003
CVE-2026-8018
Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Low)
Published 2026-05-06 · Modified
8.1EPSS 0.003
CVE-2026-5913
Out of bounds read in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)
Published 2026-04-08 · Modified
8.1EPSS 0.003
CVE-2026-13799
Use after free in QUIC in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)
Published 2026-06-30 · Analyzed
8.1EPSS 0.003
CVE-2026-7346
Inappropriate implementation in Tint in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Published 2026-04-28 · Analyzed
8.1EPSS 0.003
CVE-2026-11015
Out of bounds read in WebGPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.1EPSS 0.003
CVE-2026-5915
Insufficient validation of untrusted input in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low)
Published 2026-04-08 · Modified
8.1EPSS 0.003
CVE-2026-11011
Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.1EPSS 0.003
CVE-2026-13774
Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Critical)
Published 2026-06-30 · Analyzed
8.1EPSS 0.003
CVE-2026-5907
Insufficient data validation in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted video file. (Chromium security severity: Low)
Published 2026-04-08 · Analyzed
8.1EPSS 0.003
CVE-2026-5282
Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Published 2026-04-01 · Analyzed
8.1EPSS 0.003
CVE-2026-14122
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low)
Published 2026-06-30 · Analyzed
8.1EPSS 0.003
CVE-2025-11458
Heap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Published 2025-11-06 · Analyzed
8.1EPSS 0.003
CVE-2026-11643
Use after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
Published 2026-06-08 · Analyzed
8.1EPSS 0.003
CVE-2026-7981
Out of bounds read in Codecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: Medium)
Published 2026-05-06 · Analyzed
8.1EPSS 0.003
CVE-2025-13639
Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low)
Published 2025-12-02 · Modified
8.1EPSS 0.003
CVE-2023-34143
Improper Validation of Certificate Vulnerability in Hitachi Device Manager
Published 2023-07-18 · Modified
8.1EPSS 0.002
CVE-2026-48349
Animate | Incorrect Authorization (CWE-863)
Published 2026-07-14 · Analyzed
8.1EPSS 0.002
← Prev108 / 259Next →