VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10355CVEs
CVE-2026-11111
Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Modified
8.1EPSS 0.002
CVE-2026-12012
Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileged network position to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)
Published 2026-06-11 · Analyzed
8.1EPSS 0.002
CVE-2026-11689
Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-08 · Analyzed
8.1EPSS 0.002
CVE-2026-23568
Out-of-bounds read vulnerability in Content Distribution Service
Published 2026-01-29 · Analyzed
8.1EPSS 0.002
CVE-2026-11169
Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted XML file. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.1EPSS 0.002
CVE-2026-11185
Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.1EPSS 0.002
CVE-2026-11693
Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-08 · Analyzed
8.1EPSS 0.002
CVE-2026-87530
Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
Published 2026-09-09 · Analyzed
8.1EPSS 0.001
CVE-2026-84334
Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
Published 2026-09-01 · Analyzed
8.1EPSS 0.001
CVE-2026-87509
Incorrect authorization in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Low)
Published 2026-09-09 · Analyzed
8.1EPSS 0.001
CVE-2026-93375
Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
Published 2026-09-17 · Analyzed
8.1EPSS 0.001
CVE-2026-87554
Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
Published 2026-09-09 · Analyzed
8.1EPSS 0.001
CVE-2026-87467
Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
Published 2026-09-09 · Analyzed
8.1EPSS 0.001
CVE-2026-87457
Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
Published 2026-09-09 · Analyzed
8.1EPSS 0.001
CVE-2020-15261
Unquoted service path vulnerability on Veyon
Published 2020-10-19 · Modified
8.01 PoCEPSS 0.113
CVE-2018-3964
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Published 2018-10-03 · Modified
8.0EPSS 0.095
CVE-2018-3966
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Published 2018-10-03 · Modified
8.0EPSS 0.062
CVE-2018-3967
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Published 2018-10-03 · Modified
8.0EPSS 0.062
CVE-2018-3965
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Published 2018-10-03 · Modified
8.0EPSS 0.060
CVE-2018-3957
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Keywords property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Published 2018-10-02 · Modified
8.0EPSS 0.029
CVE-2018-3958
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Subject property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Published 2018-10-02 · Modified
8.0EPSS 0.029
CVE-2018-3962
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the CreationDate property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Published 2018-10-02 · Modified
8.0EPSS 0.025
CVE-2018-3959
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Author property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Published 2018-10-02 · Modified
8.0EPSS 0.024
CVE-2018-3960
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Producer property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Published 2018-10-02 · Modified
8.0EPSS 0.024
CVE-2018-3961
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Creator property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Published 2018-10-02 · Modified
8.0EPSS 0.024
CVE-2025-26646
.NET, Visual Studio, and Build Tools for Visual Studio Spoofing Vulnerability
Published 2025-05-13 · Analyzed
8.0EPSS 0.012
CVE-2017-5074
A use after free in Chrome Apps in Google Chrome prior to 59.0.3071.86 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page, related to Bluetooth.
Published 2017-10-27 · Modified
8.0EPSS 0.009
CVE-2021-38963
IBM Aspera Console CSV injection
Published 2024-09-24 · Analyzed
8.0EPSS 0.006
CVE-2026-34693
Adobe Experience Manager Forms JEE | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2026-06-09 · Analyzed
8.0EPSS 0.006
CVE-2024-45731
Potential Remote Command Execution (RCE) through arbitrary file write to Windows system root directory when Splunk Enterprise for Windows is installed on a separate disk
Published 2024-10-14 · Analyzed
8.0EPSS 0.006
CVE-2025-20386
Incorrect permission assignment on Splunk Enterprise for Windows during new installation or upgrade
Published 2025-12-03 · Analyzed
8.0EPSS 0.005
CVE-2025-15558
Docker Desktop Docker Plugins Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
Published 2026-03-04 · Modified
8.0EPSS 0.005
CVE-2024-45084
IBM Cognos Controller CSV injection
Published 2025-02-19 · Modified
8.0EPSS 0.004
CVE-2026-8834
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
8.0EPSS 0.003
CVE-2025-20298
Incorrect permission assignment on Universal Forwarder for Windows during new installation or upgrade
Published 2025-06-02 · Analyzed
8.0EPSS 0.003
CVE-2025-52446
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc api modules) allows Interface Manipulation (data access to the production database cluster).This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Published 2025-07-25 · Analyzed
8.0EPSS 0.002
CVE-2026-11241
Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.0EPSS 0.001
CVE-2012-5459
Untrusted search path vulnerability in VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows allows host OS users to gain host OS privileges via a Trojan horse DLL in a "system folder."
Published 2012-11-14 · Modified
7.9EPSS 0.006
CVE-2026-48346
Animate | Untrusted Search Path (CWE-426)
Published 2026-07-14 · Analyzed
7.9EPSS 0.003
CVE-2023-46691
Use after free in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
Published 2024-05-16 · Analyzed
7.9EPSS 0.002
← Prev109 / 259Next →