VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10356CVEs
CVE-2021-43753
Adobe Lightroom TIF File Parsing Use-After-Free Information Disclosure Vulnerability
Published 2023-09-07 · Modified
7.8EPSS 0.004
CVE-2022-37173
An issue in the installer of gvim 9.0.0000 allows authenticated attackers to execute arbitrary code via a binary hijacking attack on C:\Program.exe.
Published 2022-08-30 · Modified
7.8EPSS 0.004
CVE-2022-38445
Adobe Dimension SKP File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
7.8EPSS 0.004
CVE-2016-7381
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a user input to index an array is not bounds checked, leading to denial of service or potential escalation of privileges.
Published 2016-11-08 · Modified
7.8EPSS 0.004
CVE-2016-7388
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where a NULL pointer dereference caused by invalid user input may lead to denial of service or potential escalation of privileges.
Published 2016-11-08 · Modified
7.8EPSS 0.004
CVE-2023-21594
Adobe InCopy Font Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-01-13 · Modified
7.8EPSS 0.004
CVE-2017-7760
The Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it. The location of the original file can be altered by a malicious user by passing a special path to the callback parameter through the Mozilla Maintenance Service, allowing the manipulation of files in the installation directory and privilege escalation by manipulating the Mozilla Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.
Published 2018-06-11 · Modified
7.8EPSS 0.004
CVE-2020-0561
Improper initialization in the Intel(R) SGX SDK before v2.6.100.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
Published 2020-02-13 · Modified
7.8EPSS 0.004
CVE-2017-11158
Multiple untrusted search path vulnerabilities in the installer in Synology Cloud Station Drive before 4.2.5-4396 on Windows allow local attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current working directory.
Published 2017-08-31 · Modified
7.8EPSS 0.004
CVE-2024-49545
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
Published 2024-12-10 · Analyzed
7.8EPSS 0.004
CVE-2024-47414
Animate | Use After Free (CWE-416)
Published 2024-10-09 · Analyzed
7.8EPSS 0.004
CVE-2025-27199
Animate | Heap-based Buffer Overflow (CWE-122)
Published 2025-04-08 · Analyzed
7.8EPSS 0.004
CVE-2025-27198
Photoshop Desktop | Heap-based Buffer Overflow (CWE-122)
Published 2025-04-08 · Analyzed
7.8EPSS 0.004
CVE-2024-4712
Arbitrary File Creation in PaperCut NG/MF Web Print Image Handler
Published 2024-05-14 · Analyzed
7.8EPSS 0.004
CVE-2024-47413
Animate | Use After Free (CWE-416)
Published 2024-10-09 · Analyzed
7.8EPSS 0.004
CVE-2024-47412
Animate | Use After Free (CWE-416)
Published 2024-10-09 · Analyzed
7.8EPSS 0.004
CVE-2025-27195
Media Encoder | Heap-based Buffer Overflow (CWE-122)
Published 2025-04-08 · Analyzed
7.8EPSS 0.004
CVE-2024-47418
Animate | Use After Free (CWE-416)
Published 2024-10-09 · Analyzed
7.8EPSS 0.004
CVE-2024-49543
InDesign Desktop | Stack-based Buffer Overflow (CWE-121)
Published 2024-12-10 · Analyzed
7.8EPSS 0.004
CVE-2024-47415
Animate | Use After Free (CWE-416)
Published 2024-10-09 · Analyzed
7.8EPSS 0.004
CVE-2016-7383
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in a memory mapping API in the kernel mode layer (nvlddmkm.sys) handler, leading to denial of service or potential escalation of privileges.
Published 2016-11-08 · Modified
7.8EPSS 0.004
CVE-2025-21159
Illustrator | Use After Free (CWE-416)
Published 2025-02-11 · Analyzed
7.8EPSS 0.004
CVE-2024-4454
WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability
Published 2024-05-22 · Analyzed
7.8EPSS 0.004
CVE-2017-10741
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlpWaitOnCriticalSection+0x0000000000000121."
Published 2017-07-05 · Modified
7.8EPSS 0.004
CVE-2020-8601
Trend Micro Vulnerability Protection 2.0 is affected by a vulnerability that could allow an attack to use the product installer to load other DLL files located in the same directory.
Published 2020-02-20 · Modified
7.8EPSS 0.004
CVE-2022-30643
Adobe Illustrator Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-09-07 · Modified
7.8EPSS 0.004
CVE-2020-5180
Viscosity 1.8.2 on Windows and macOS allows an unprivileged user to set a subset of OpenVPN parameters, which can be used to load a malicious library into the memory of the OpenVPN process, leading to limited local privilege escalation. (When a VPN connection is initiated using a TLS/SSL client profile, the privileges are dropped, and the library will be loaded, resulting in arbitrary code execution as a user with limited privileges. This greatly reduces the impact of the vulnerability.)
Published 2020-01-14 · Modified
7.8EPSS 0.004
CVE-2022-28831
Adobe InDesign Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-09-11 · Modified
7.8EPSS 0.004
CVE-2022-30638
Adobe Illustrator Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-09-07 · Modified
7.8EPSS 0.004
CVE-2021-28644
Adobe Acrobat SpellDictionaryCreate Path Traversal Remote Code Execution Vulnerability
Published 2023-09-06 · Modified
7.8EPSS 0.004
CVE-2022-30645
Adobe Illustrator SVG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-09-07 · Modified
7.8EPSS 0.004
CVE-2022-30640
Adobe Illustrator Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-09-07 · Modified
7.8EPSS 0.004
CVE-2022-30639
Adobe Illustrator Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-09-07 · Modified
7.8EPSS 0.004
CVE-2022-30646
Adobe Illustrator Font Parsing Out-of-bounds Write Remote Code Execution Vulnerability
Published 2023-09-07 · Modified
7.8EPSS 0.004
CVE-2022-30637
Adobe Illustrator Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-09-07 · Modified
7.8EPSS 0.004
CVE-2022-28836
Adobe InCopy Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-09-11 · Modified
7.8EPSS 0.004
CVE-2022-28833
Adobe InDesign Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-09-11 · Modified
7.8EPSS 0.004
CVE-2022-28834
Adobe InCopy Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-09-11 · Modified
7.8EPSS 0.004
CVE-2021-35980
Adobe Acrobat Reader SpellDictionaryExport Path Traversal Remote Code Execution Vulnerability
Published 2023-09-06 · Modified
7.8EPSS 0.004
CVE-2022-30642
Adobe Illustrator Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-09-07 · Modified
7.8EPSS 0.004
← Prev133 / 259Next →