VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10356CVEs
CVE-2020-5991
NVIDIA CUDA Toolkit, all versions prior to 11.1.1, contains a vulnerability in the NVJPEG library in which an out-of-bounds read or write operation may lead to code execution, denial of service, or information disclosure.
Published 2020-10-30 · Modified
7.8EPSS 0.005
CVE-2023-38119
Foxit PDF Reader AcroForm signature Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.005
CVE-2023-38118
Foxit PDF Reader AcroForm Doc Object Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.005
CVE-2025-64899
Acrobat Reader | Out-of-bounds Read (CWE-125)
Published 2025-12-09 · Analyzed
7.8EPSS 0.005
CVE-2022-38408
Adobe Illustrator Improper Input Validation Arbitrary code execution
Published 2022-09-16 · Modified
7.8EPSS 0.005
CVE-2022-34249
Adobe InCopy Font Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-07-15 · Modified
7.8EPSS 0.005
CVE-2022-34245
Adobe InDesign Font Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-07-15 · Modified
7.8EPSS 0.005
CVE-2022-34250
Adobe InCopy Font Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-07-15 · Modified
7.8EPSS 0.005
CVE-2022-34246
Adobe InDesign Font Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-07-15 · Modified
7.8EPSS 0.005
CVE-2020-18169
A vulnerability in the Windows installer XML (WiX) toolset of TechSmith Snagit 19.1.1.2860 allows attackers to escalate privileges. NOTE: Exploit of the Snagit installer would require the end user to ignore other safety mechanisms provided by the Host OS. See reference document for more details.
Published 2021-07-26 · Modified
7.8EPSS 0.005
CVE-2018-6232
A buffer overflow privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x22205C by the tmnciesc.sys driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Published 2018-05-25 · Modified
7.8EPSS 0.005
CVE-2018-6233
A buffer overflow privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x222060 by the tmnciesc.sys driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Published 2018-05-25 · Modified
7.8EPSS 0.005
CVE-2020-24563
A vulnerability in Trend Micro Apex One may allow a local attacker to manipulate the process of the security agent unload option (if configured), which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute low-privileged code on the target in order to exploit this vulnerability.
Published 2020-09-28 · Modified
7.8EPSS 0.005
CVE-2025-64785
Acrobat Reader | Untrusted Search Path (CWE-426)
Published 2025-12-09 · Analyzed
7.8EPSS 0.005
CVE-2019-20406
The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path environmental variable variable to inject code & escalate their privileges via a DLL hijacking vulnerability.
Published 2020-02-06 · Modified
7.8EPSS 0.005
CVE-2024-49508
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
Published 2024-11-12 · Analyzed
7.8EPSS 0.005
CVE-2024-49507
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
Published 2024-11-12 · Analyzed
7.8EPSS 0.005
CVE-2020-5992
NVIDIA GeForce NOW application software on Windows, all versions prior to 2.0.25.119, contains a vulnerability in its open-source software dependency in which the OpenSSL library is vulnerable to binary planting attacks by a local user, which may lead to code execution or escalation of privileges.
Published 2020-11-11 · Modified
7.8EPSS 0.005
CVE-2022-24680
A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1 and Trend Micro Worry-Free Business Security Services agents could allow a local attacker to create a mount point and leverage this for arbitrary folder deletion, leading to escalated privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Published 2022-02-24 · Modified
7.8EPSS 0.005
CVE-2022-24679
A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1 and Trend Micro Worry-Free Business Security Services agents could allow a local attacker to create an writable folder in an arbitrary location and escalate privileges affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Published 2022-02-24 · Modified
7.8EPSS 0.005
CVE-2022-34263
Adobe Illustrator Font Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-08-11 · Modified
7.8EPSS 0.005
CVE-2024-49537
After Effects | Stack-based Buffer Overflow (CWE-121)
Published 2024-12-10 · Analyzed
7.8EPSS 0.005
CVE-2024-53955
Bridge | Integer Underflow (Wrap or Wraparound) (CWE-191)
Published 2024-12-10 · Analyzed
7.8EPSS 0.005
CVE-2022-34241
Adobe Character Animator SVG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-07-15 · Modified
7.8EPSS 0.005
CVE-2019-16470
CoolType.dll crash - Tianfu Cup
Published 2023-09-11 · Modified
7.8EPSS 0.005
CVE-2022-38440
Adobe Dimension SKP File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
7.8EPSS 0.005
CVE-2022-38441
Adobe Dimension GLB File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
7.8EPSS 0.005
CVE-2020-27695
Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a local directory which can lead to obtaining administrative privileges during the installation of the product.
Published 2020-11-18 · Modified
7.8EPSS 0.005
CVE-2020-27696
Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a specific Windows system directory which can lead to obtaining administrative privileges during the installation of the product.
Published 2020-11-18 · Modified
7.8EPSS 0.005
CVE-2022-38412
Adobe Animate SVG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-09-16 · Modified
7.8EPSS 0.005
CVE-2021-36744
Trend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an attacker to exploit the system to escalate privileges and create a denial of service.
Published 2021-09-06 · Modified
7.8EPSS 0.005
CVE-2018-15363
An Out-of-Bounds Read Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability.
Published 2018-08-30 · Modified
7.8EPSS 0.005
CVE-2021-34803
TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations.
Published 2021-06-16 · Modified
7.8EPSS 0.005
CVE-2020-4739
IBM DB2 Accessories Suite for Linux, UNIX, and Windows, DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 188149.
Published 2020-11-20 · Modified
7.8EPSS 0.005
CVE-2018-1780
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local db2 instance owner to obtain root access by exploiting a symbolic link attack to read/write/corrupt a file that they originally did not have permission to access. IBM X-Force ID: 148803.
Published 2018-11-09 · Modified
7.8EPSS 0.005
CVE-2026-58641
.NET Elevation of Privilege Vulnerability
Published 2026-08-11 · Analyzed
7.8EPSS 0.005
CVE-2026-62886
.NET Elevation of Privilege Vulnerability
Published 2026-08-11 · Analyzed
7.8EPSS 0.005
CVE-2022-28225
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.684 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process.
Published 2022-06-15 · Modified
7.8EPSS 0.005
CVE-2021-25261
Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process.
Published 2022-06-15 · Modified
7.8EPSS 0.005
CVE-2026-62871
.NET Elevation of Privilege Vulnerability
Published 2026-08-11 · Analyzed
7.8EPSS 0.005
← Prev129 / 259Next →