VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10355CVEs
CVE-2023-28741
Buffer overflow in some Intel(R) QAT drivers for Windows - HW Version 1.0 before version 1.10 may allow an authenticated user to potentially enable escalation of privilege via local access.
Published 2023-11-14 · Modified
7.9EPSS 0.002
CVE-2021-34833
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14023.
Published 2021-08-04 · Modified
7.8EPSS 0.957
CVE-2025-6218
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
Published 2025-06-21 · Analyzed
7.8KEVEPSS 0.905
CVE-2018-4878
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.
Published 2018-02-06 · Analyzed
7.8KEV3 PoCEPSS 0.895
CVE-2021-39843
Adobe Acrobat Reader XObject Out-of-Bound Write Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.767
CVE-2021-39836
Adobe Acrobat Reader DC AcroForm buttonGetIcon Use-After-Free Remote Code Execution Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.695
CVE-2021-39837
Adobe Acrobat Reader DC AcroForm deleteItemAt Use-After-Free Remote Code Execution Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.652
CVE-2021-39839
Adobe Acrobat Reader DC AcroForm getItemAt Use-After-Free Remote Code Execution Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.652
CVE-2021-39838
Adobe Acrobat Reader DC AcroForm buttonGetCaption Use-After-Free Remote Code Execution Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.652
CVE-2021-34847
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14270.
Published 2021-08-04 · Modified
7.8EPSS 0.616
CVE-2023-21608
Adobe Acrobat Reader DC resetForm Use-After-Free Remote Code Execution Vulnerability
Published 2023-01-18 · Analyzed
7.8KEVEPSS 0.615
CVE-2021-40728
Adobe Acrobat Reader DC Use After Free Arbitrary Code Execution
Published 2021-10-15 · Modified
7.8EPSS 0.546
CVE-2020-24435
Acrobat Reader DC Heap-based Buffer Overflow Could Lead to Arbitrary Code Execution
Published 2020-11-05 · Modified
7.8EPSS 0.527
CVE-2016-0957
Dispatcher before 4.1.5 in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 does not properly implement a URL filter, which allows remote attackers to bypass dispatcher rules via unspecified vectors.
Published 2016-02-10 · Modified
7.8EPSS 0.520
CVE-2016-0956
The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sensitive information via unspecified vectors.
Published 2016-02-10 · Modified
7.81 PoCEPSS 0.512
CVE-2021-39840
Adobe Acrobat Reader DC AcroForm Field Use-After-Free Remote Code Execution Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.506
CVE-2023-27363
Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.470
CVE-2020-24437
Acrobat Reader DC Use-After-Free Vulnerability Could Lead to Arbitrary Code Execution
Published 2020-11-05 · Modified
7.8EPSS 0.465
CVE-2021-28554
Adobe Acrobat Reader DC Path Parsing Out-Of-Bounds Read could lead to arbitrary code execution
Published 2021-08-24 · Modified
7.8EPSS 0.460
CVE-2019-7089
Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have a data leakage (sensitive) vulnerability. Successful exploitation could lead to information disclosure.
Published 2019-05-24 · Modified
7.8EPSS 0.448
CVE-2021-34850
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14529.
Published 2021-08-04 · Modified
7.8EPSS 0.383
CVE-2025-11001
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
Published 2025-11-19 · Analyzed
7.81 PoCEPSS 0.270
CVE-2020-8844
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPEG files within CovertToPDF. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9102.
Published 2020-02-13 · Modified
7.8EPSS 0.237
CVE-2021-44701
Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2022-01-14 · Modified
7.8EPSS 0.209
CVE-2020-8846
This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of text field objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9400.
Published 2020-02-13 · Modified
7.8EPSS 0.198
CVE-2020-8856
This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25608. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of watermarks. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9640.
Published 2020-02-13 · Modified
7.8EPSS 0.198
CVE-2020-8845
This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of watermarks in AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9358.
Published 2020-02-13 · Modified
7.8EPSS 0.195
CVE-2020-24430
Acrobat Pro DC Use-After-Free vulnerability Could Lead to Arbitrary Code Execution
Published 2020-11-05 · Modified
7.8EPSS 0.187
CVE-2016-5330
Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware Workstation Pro 12.1.x before 12.1.1, VMware Workstation Player 12.1.x before 12.1.1, and VMware Fusion 8.1.x before 8.1.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
Published 2016-08-08 · Modified
7.81 PoCEPSS 0.180
CVE-2021-39842
Adobe Acrobat Reader DC messageHandler.OnMessage Use-After-Free Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.174
CVE-2020-24436
Acrobat Pro DC PDF Export Out-Of-Bounds Write Vulnerability Could Lead to Arbitrary Code Execution
Published 2020-11-05 · Modified
7.8EPSS 0.170
CVE-2021-34842
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14024.
Published 2021-08-04 · Modified
7.8EPSS 0.133
CVE-2021-39863
Adobe Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution
Published 2021-09-29 · Modified
7.8EPSS 0.132
CVE-2019-9491
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed.
Published 2019-10-21 · Modified
7.81 PoCEPSS 0.129
CVE-2021-45068
Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-01-14 · Modified
7.8EPSS 0.123
CVE-2021-39841
Adobe Acrobat Pro DC DocMedia Type Confusion Remote Code Execution Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.117
CVE-2021-45064
Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2022-01-14 · Modified
7.8EPSS 0.115
CVE-2008-6194
Memory leak in the DNS server in Microsoft Windows allows remote attackers to cause a denial of service (memory consumption) via DNS packets. NOTE: this issue reportedly exists because of an incorrect fix for CVE-2007-3898.
Published 2009-02-19 · Modified
7.8EPSS 0.114
CVE-2022-34221
Adobe Acrobat Reader Type Confusion vulnerability could lead to Arbitrary code execution
Published 2022-07-15 · Modified
7.8EPSS 0.111
CVE-2020-24432
Acrobat Reader DC Arbitrary JavaScript Execution in PDF Documents
Published 2020-11-05 · Modified
7.8EPSS 0.111
← Prev110 / 259Next →