VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10356CVEs
CVE-2023-25883
ZDI-CAN-19386: Adobe Dimension FBX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-03-28 · Modified
7.8EPSS 0.004
CVE-2023-25882
ZDI-CAN-19385: Adobe Dimension OBJ File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-03-28 · Modified
7.8EPSS 0.004
CVE-2024-34117
Adobe Photoshop 2024 MPO File Parsing Use-After-Free vulnerability
Published 2024-08-14 · Analyzed
7.8EPSS 0.004
CVE-2021-40683
In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of execution.
Published 2021-10-04 · Modified
7.8EPSS 0.004
CVE-2020-26894
LiveCode v9.6.1 on Windows allows local, low-privileged users to gain privileges by creating a malicious "cmd.exe" in the folder of the vulnerable LiveCode application. If the application is using LiveCode's "shell()" function, it will attempt to search for "cmd.exe" in the folder of the current application and run the malicious "cmd.exe".
Published 2020-10-08 · Modified
7.8EPSS 0.004
CVE-2022-35700
Adobe Bridge SVG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-09-19 · Modified
7.8EPSS 0.004
CVE-2022-35699
Adobe Bridge Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-09-19 · Modified
7.8EPSS 0.004
CVE-2024-52983
Animate | Integer Overflow or Wraparound (CWE-190)
Published 2024-12-10 · Analyzed
7.8EPSS 0.004
CVE-2024-0197
Privilege Escalation in Thales SafeNet Sentinel HASP LDK
Published 2024-02-27 · Analyzed
7.8EPSS 0.004
CVE-2021-42955
Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password reset vulnerability. Because of the designed password reset mechanism, any non-admin Windows user can reset the password of the Remote Access Plus Server Admin account.
Published 2021-11-17 · Modified
7.8EPSS 0.004
CVE-2024-45156
Animate | NULL Pointer Dereference (CWE-476)
Published 2024-12-10 · Analyzed
7.8EPSS 0.004
CVE-2020-9418
An untrusted search path vulnerability in the installer of PDFescape Desktop version 4.0.22 and earlier allows an attacker to gain privileges and execute code via DLL hijacking.
Published 2020-03-05 · Modified
7.8EPSS 0.004
CVE-2024-52990
Animate | Buffer Underwrite ('Buffer Underflow') (CWE-124)
Published 2024-12-10 · Analyzed
7.8EPSS 0.004
CVE-2024-52989
Animate | Integer Underflow (Wrap or Wraparound) (CWE-191)
Published 2024-12-10 · Analyzed
7.8EPSS 0.004
CVE-2024-52987
Animate | Integer Underflow (Wrap or Wraparound) (CWE-191)
Published 2024-12-10 · Analyzed
7.8EPSS 0.004
CVE-2024-52986
Animate | Integer Underflow (Wrap or Wraparound) (CWE-191)
Published 2024-12-10 · Analyzed
7.8EPSS 0.004
CVE-2024-45155
Animate | Access of Uninitialized Pointer (CWE-824)
Published 2024-12-10 · Analyzed
7.8EPSS 0.004
CVE-2024-52985
Animate | Integer Underflow (Wrap or Wraparound) (CWE-191)
Published 2024-12-10 · Analyzed
7.8EPSS 0.004
CVE-2024-52984
Animate | Integer Underflow (Wrap or Wraparound) (CWE-191)
Published 2024-12-10 · Analyzed
7.8EPSS 0.004
CVE-2023-33693
A buffer overflow in EasyPlayerPro-Win v3.2.19.0106 to v3.6.19.0823 allows attackers to cause a Denial of Service (DoS) via a crafted XML file.
Published 2023-06-05 · Modified
7.8EPSS 0.004
CVE-2023-38246
Adobe Acrobat Reader DC ActiveX Control (AxAcroPDFLib.AxAcroPDF) stack-based stale pointer vulnerability
Published 2023-08-10 · Modified
7.8EPSS 0.004
CVE-2020-28572
A vulnerability in Trend Micro Apex One could allow an unprivileged user to abuse the product installer to reinstall the agent with additional malicious code in the context of a higher privilege.
Published 2020-11-18 · Modified
7.8EPSS 0.004
CVE-2021-25249
An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Published 2021-02-04 · Modified
7.8EPSS 0.004
CVE-2019-5539
VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to insecure loading of a DLL by Cortado Thinprint. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a Windows machine where Workstation or View Agent is installed.
Published 2019-12-23 · Modified
7.8EPSS 0.004
CVE-2024-49526
Animate | Use After Free (CWE-416)
Published 2024-11-12 · Analyzed
7.8EPSS 0.004
CVE-2026-45490
.NET SDK Elevation of Privilege Vulnerability
Published 2026-06-09 · Modified
7.8EPSS 0.004
CVE-2019-4606
IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 could allow a local attacker to execute arbitrary code on the system, caused by an untrusted search path vulnerability. By using a executable file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 168298.
Published 2019-12-12 · Modified
7.8EPSS 0.004
CVE-2024-30293
Adobe Animate 2024 AI File parsing Stack base buffer overflow Remote Code execution Vulnerability
Published 2024-05-16 · Analyzed
7.8EPSS 0.004
CVE-2024-30294
Adobe Animate OGG File Parsing Heap Memory Corruption remote code execution Vulnerability
Published 2024-05-16 · Analyzed
7.8EPSS 0.004
CVE-2019-18232
SafeNet Sentinel LDK License Manager, all versions prior to 7.101(only Microsoft Windows versions are affected) is vulnerable when configured as a service. This vulnerability may allow an attacker with local access to create, write, and/or delete files in system folder using symbolic links, leading to a privilege escalation. This vulnerability could also be used by an attacker to execute a malicious DLL, which could impact the integrity and availability of the system.
Published 2019-12-11 · Modified
7.8EPSS 0.004
CVE-2020-15593
SteelCentral Aternity Agent 11.0.0.120 on Windows mishandles IPC. It uses an executable running as a high privileged Windows service to perform administrative tasks and collect data from other processes. It distributes functionality among different processes and uses IPC (Inter-Process Communication) primitives to enable the processes to cooperate. Any user in the system is allowed to access the interprocess communication channel AternityAgentAssistantIpc, retrieve a serialized object and call object methods remotely. Among others, the methods allow any user to: (1) Create and/or overwrite arbitrary XML files across the system; (2) Create arbitrary directories across the system; and (3) Load arbitrary plugins (i.e., C# assemblies) from the "%PROGRAMFILES(X86)/Aternity Information Systems/Assistant/plugins” directory and execute code contained in them.
Published 2020-07-27 · Modified
7.8EPSS 0.004
CVE-2023-51556
Foxit PDF Reader AcroForm Doc Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2021-36376
dandavison delta before 0.8.3 on Windows resolves an executable's pathname as a relative path from the current directory.
Published 2021-07-13 · Modified
7.8EPSS 0.004
CVE-2023-51557
Foxit PDF Reader AcroForm Doc Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2023-51552
Foxit PDF Reader AcroForm Signature Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2023-51551
Foxit PDF Reader AcroForm Signature Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2023-29308
[FG-VD-23-009] Adobe InDesign 2023 Arbitrary Code Execution Vulnerability Notification
Published 2023-07-12 · Modified
7.8EPSS 0.004
CVE-2023-26337
ZDI-CAN-20285: Adobe Dimension USDA File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-03-28 · Modified
7.8EPSS 0.004
CVE-2023-25890
ZDI-CAN-19493: Adobe Dimension USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-03-28 · Modified
7.8EPSS 0.004
CVE-2023-25895
ZDI-CAN-19540: Adobe Dimension USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-03-28 · Modified
7.8EPSS 0.004
← Prev131 / 259Next →