VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10356CVEs
CVE-2022-35702
Adobe Bridge SVG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-09-19 · Modified
7.8EPSS 0.006
CVE-2024-20739
ZDI-CAN-22647: Adobe Audition AVI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2024-02-15 · Analyzed
7.8EPSS 0.006
CVE-2024-20772
Adobe Media Encoder 2024 AI file parsing Stack based buffer overflow
Published 2024-04-10 · Analyzed
7.8EPSS 0.006
CVE-2021-22117
RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.
Published 2021-05-18 · Modified
7.8EPSS 0.006
CVE-2024-34097
ZDI-CAN-23473: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-15 · Analyzed
7.8EPSS 0.006
CVE-2024-34096
ZDI-CAN-23472: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-15 · Analyzed
7.8EPSS 0.006
CVE-2024-34095
ZDI-CAN-23475: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-15 · Analyzed
7.8EPSS 0.006
CVE-2019-9492
A DLL side-loading vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow an authenticated attacker to gain code execution and terminate the product's process - disabling endpoint protection. The attacker must have already gained authentication and have local access to the vulnerable system.
Published 2019-07-26 · Modified
7.8EPSS 0.006
CVE-2019-14685
A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would allow an attacker to manipulate a specific product feature to load a malicious service.
Published 2019-08-21 · Modified
7.8EPSS 0.006
CVE-2022-39959
Panini Everest Engine 2.0.4 allows unprivileged users to create a file named Everest.exe in the %PROGRAMDATA%\Panini folder. This leads to privilege escalation because a service, running as SYSTEM, uses the unquoted path of %PROGRAMDATA%\Panini\Everest Engine\EverestEngine.exe and therefore a Trojan horse %PROGRAMDATA%\Panini\Everest.exe may be executed instead of the intended vendor-supplied EverestEngine.exe file.
Published 2022-10-07 · Modified
7.8EPSS 0.006
CVE-2022-35717
"IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-"Force ID: 231361.
Published 2022-11-03 · Modified
7.8EPSS 0.006
CVE-2015-7359
The (1) IsVolumeAccessibleByCurrentUser and (2) MountDevice methods in Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, do not check the impersonation level of impersonation tokens, which allows local users to impersonate a user at SecurityIdentify level and gain access to other users' mounted encrypted volumes.
Published 2017-10-02 · Modified
7.8EPSS 0.006
CVE-2021-21384
Null characters not escaped in shescape
Published 2021-03-18 · Modified
7.8EPSS 0.006
CVE-2022-24960
Use after free vulnerability in PDFTron SDK
Published 2022-03-09 · Modified
7.8EPSS 0.006
CVE-2020-24562
A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This CVE is similar, but not identical to CVE-2020-24556.
Published 2020-09-28 · Modified
7.8EPSS 0.006
CVE-2022-38434
Adobe Photoshop SVG File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-09-16 · Modified
7.8EPSS 0.006
CVE-2020-27697
Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a non-protected location with high privileges (symlink attack) which can lead to obtaining administrative privileges during the installation of the product.
Published 2020-11-18 · Modified
7.8EPSS 0.006
CVE-2023-1048
TechPowerUp Ryzen DRAM Calculator WinRing0x64.sys initialization
Published 2023-02-26 · Modified
7.8EPSS 0.006
CVE-2022-36336
A link following vulnerability in the scanning function of Trend Micro Apex One and Worry-Free Business Security agents could allow a local attacker to escalate privileges on affected installations. The resolution for this issue has been deployed automatically via ActiveUpdate to customers in an updated Spyware pattern. Customers who are up-to-date on detection patterns are not required to take any additional steps to mitigate this issue.
Published 2022-07-29 · Modified
7.8EPSS 0.006
CVE-2019-17388
Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute arbitrary code by gaining elevated privileges through file modifications.
Published 2019-12-05 · Modified
7.8EPSS 0.006
CVE-2019-11396
An issue was discovered in Avira Free Security Suite 10. The permissive access rights on the SoftwareUpdater folder (files / folders and configuration) are incompatible with the privileged file manipulation performed by the product. Files can be created that can be used by an unprivileged user to obtain SYSTEM privileges. Arbitrary file creation can be achieved by abusing the SwuConfig.json file creation: an unprivileged user can replace these files by pseudo-symbolic links to arbitrary files. When an update occurs, a privileged service creates a file and sets its access rights, offering write access to the Everyone group in any directory.
Published 2019-08-29 · Modified
7.8EPSS 0.006
CVE-2023-48633
ZDI-CAN-22173: Adobe After Effects AEP File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2023-12-13 · Modified
7.8EPSS 0.006
CVE-2024-30301
ZDI-CAN-23042: Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-02 · Analyzed
7.8EPSS 0.006
CVE-2024-30305
ZDI-CAN-23043: Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-02 · Analyzed
7.8EPSS 0.006
CVE-2024-30304
ZDI-CAN-23040: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-02 · Analyzed
7.8EPSS 0.006
CVE-2022-38436
Adobe Illustrator CDR File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-10-25 · Modified
7.8EPSS 0.006
CVE-2024-20765
ZDI-CAN-22674: Adobe Acrobat Reader DC PDF File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2024-02-29 · Analyzed
7.8EPSS 0.006
CVE-2019-5683
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in the user mode video driver trace logger component. When an attacker has access to the system and creates a hard link, the software does not check for hard link attacks. This behavior may lead to code execution, denial of service, or escalation of privileges.
Published 2019-08-06 · Modified
7.8EPSS 0.006
CVE-2019-19689
Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited via a DLL Hijack related to a vulnerability on the packer that the program uses.
Published 2019-12-18 · Modified
7.8EPSS 0.006
CVE-2023-26078
Privilege escalation vulnerability was discovered in Atera Agent 1.8.4.4 and prior on Windows due to mishandling of privileged APIs.
Published 2023-07-24 · Modified
7.8EPSS 0.006
CVE-2025-30330
Illustrator | Heap-based Buffer Overflow (CWE-122)
Published 2025-05-13 · Analyzed
7.8EPSS 0.006
CVE-2019-5665
NVIDIA Windows GPU Display driver contains a vulnerability in the 3D vision component in which the stereo service software, when opening a file, does not check for hard links. This behavior may lead to code execution, denial of service or escalation of privileges.
Published 2019-02-27 · Modified
7.8EPSS 0.006
CVE-2024-30303
ZDI-CAN-23044: Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-02 · Analyzed
7.8EPSS 0.006
CVE-2025-43576
Acrobat Reader | Use After Free (CWE-416)
Published 2025-06-10 · Analyzed
7.8EPSS 0.005
CVE-2024-20745
ZDI-CAN-22671: Adobe Premiere Pro AVI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2024-03-18 · Analyzed
7.8EPSS 0.005
CVE-2021-38571
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows DLL hijacking, aka CNVD-C-2021-68000 and CNVD-C-2021-68502.
Published 2021-08-11 · Modified
7.8EPSS 0.005
CVE-2024-52997
Photoshop Desktop | Use After Free (CWE-416)
Published 2024-12-10 · Analyzed
7.8EPSS 0.005
CVE-2024-53953
Animate | Use After Free (CWE-416)
Published 2024-12-10 · Analyzed
7.8EPSS 0.005
CVE-2023-38112
Foxit PDF Reader XFA Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.005
CVE-2023-27364
Foxit PDF Editor XLS File Parsing Exposed Dangerous Method Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.005
← Prev127 / 259Next →