VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10356CVEs
CVE-2024-52988
Animate | Out-of-bounds Write (CWE-787)
Published 2024-12-10 · Analyzed
7.8EPSS 0.004
CVE-2020-3961
VMware Horizon Client for Windows (prior to 5.4.3) contains a privilege escalation vulnerability due to folder permission configuration and unsafe loading of libraries. A local user on the system where the software is installed may exploit this issue to run commands as any user.
Published 2020-06-15 · Modified
7.8EPSS 0.004
CVE-2023-26336
ZDI-CAN-20275: Adobe Dimension USD File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2023-03-28 · Modified
7.8EPSS 0.004
CVE-2023-25899
ZDI-CAN-19522: Adobe Dimension USD File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2023-03-28 · Modified
7.8EPSS 0.004
CVE-2023-25893
ZDI-CAN-19539: Adobe Dimension USD File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2023-03-28 · Modified
7.8EPSS 0.004
CVE-2016-2408
Pulse Secure Desktop before 5.2R2 and Pulse Secure Installer Service before 8.2R2 and below for Windows allow restricted users to gain privileges via unspecified vectors.
Published 2016-08-02 · Modified
7.8EPSS 0.004
CVE-2023-25894
ZDI-CAN-19543: Adobe Dimension USD File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2023-03-28 · Modified
7.8EPSS 0.004
CVE-2023-25896
ZDI-CAN-19541: Adobe Dimension USD File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2023-03-28 · Modified
7.8EPSS 0.004
CVE-2022-28128
Untrusted search path vulnerability in AttacheCase ver.3.6.1.0 and earlier allows an attacker to gain privileges and execute arbitrary code via a Trojan horse DLL in an unspecified directory.
Published 2022-03-31 · Modified
7.8EPSS 0.004
CVE-2019-5666
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) create context command DDI DxgkDdiCreateContext in which the product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array, which may lead to denial of service or escalation of privileges.
Published 2019-02-27 · Modified
7.8EPSS 0.004
CVE-2021-34971
Foxit PDF Reader JPG2000 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2024-05-07 · Analyzed
7.8EPSS 0.004
CVE-2025-27196
Premiere Pro | Heap-based Buffer Overflow (CWE-122)
Published 2025-04-08 · Analyzed
7.8EPSS 0.004
CVE-2025-27193
Bridge | Heap-based Buffer Overflow (CWE-122)
Published 2025-04-08 · Analyzed
7.8EPSS 0.004
CVE-2017-6268
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed from a user to the driver is not correctly validated and used as the index to an array which may lead to denial of service or possible escalation of privileges.
Published 2017-09-22 · Modified
7.8EPSS 0.004
CVE-2016-7082
VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enabled, allow guest OS users to execute arbitrary code on the host OS or cause a denial of service (host OS memory corruption) via an EMF file.
Published 2016-12-29 · Modified
7.8EPSS 0.004
CVE-2018-6251
NVIDIA Windows GPU Display Driver contains a vulnerability in the DirectX 10 Usermode driver, where a specially crafted pixel shader can cause writing to unallocated memory, leading to denial of service or potential code execution.
Published 2018-04-02 · Modified
7.8EPSS 0.004
CVE-2017-7766
An attack using manipulation of "updater.ini" contents, used by the Mozilla Windows Updater, and privilege escalation through the Mozilla Maintenance Service to allow for arbitrary file execution and deletion by the Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.
Published 2018-06-11 · Modified
7.8EPSS 0.004
CVE-2023-47056
ZDI-CAN-21763: Adobe Premiere Pro MP4 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-11-16 · Modified
7.8EPSS 0.004
CVE-2017-0351
All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a NULL pointer dereference caused by invalid user input may lead to denial of service or potential escalation of privileges.
Published 2017-05-09 · Modified
7.8EPSS 0.004
CVE-2022-30701
An uncontrolled search path element vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to craft a special configuration file to load an untrusted library with escalated privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Published 2022-05-26 · Modified
7.8EPSS 0.004
CVE-2023-26077
Atera Agent through 1.8.3.6 on Windows Creates a Temporary File in a Directory with Insecure Permissions.
Published 2023-07-24 · Modified
7.8EPSS 0.004
CVE-2023-47051
ZDI-CAN-21683: Adobe Audition MP4 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-11-16 · Modified
7.8EPSS 0.004
CVE-2026-27220
Acrobat Reader | Use After Free (CWE-416)
Published 2026-03-10 · Analyzed
7.8EPSS 0.004
CVE-2023-25871
Adobe Substance 3D Stager SVG File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2023-03-27 · Modified
7.8EPSS 0.004
CVE-2023-26392
ZDI-CAN-20235: Adobe Substance 3D Stager USD File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2023-04-12 · Modified
7.8EPSS 0.004
CVE-2023-26384
ZDI-CAN-20279: Adobe Substance 3D Stager USD File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2023-04-12 · Modified
7.8EPSS 0.004
CVE-2020-24088
An issue was discovered in MmMapIoSpace routine in Foxconn Live Update Utility 2.1.6.26, allows local attackers to escalate privileges.
Published 2023-09-11 · Modified
7.8EPSS 0.004
CVE-2023-38211
ZDI-CAN-21078: Adobe Dimension GLB File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2023-08-09 · Modified
7.8EPSS 0.004
CVE-2016-0226
The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly restrict access to the (1) nsrd, (2) nsrexecd, and (3) portmap executable files, which allows local users to gain privileges via a Trojan horse file.
Published 2016-03-28 · Modified
7.8EPSS 0.004
CVE-2024-41856
Illustrator | Improper Input Validation (CWE-20)
Published 2024-08-14 · Modified
7.8EPSS 0.004
CVE-2023-26414
ZDI-CAN-20316: Adobe Substance 3D Designer USD File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2023-04-13 · Modified
7.8EPSS 0.004
CVE-2023-26410
ZDI-CAN-20309: Adobe Substance 3D Designer USD File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2023-04-13 · Modified
7.8EPSS 0.004
CVE-2019-5702
NVIDIA GeForce Experience, all versions prior to 3.20.2, contains a vulnerability when GameStream is enabled in which an attacker with local system access can corrupt a system file, which may lead to denial of service or escalation of privileges.
Published 2019-12-24 · Modified
7.8EPSS 0.004
CVE-2022-25348
Untrusted search path vulnerability in AttacheCase ver.4.0.2.7 and earlier allows an attacker to gain privileges and execute arbitrary code via a Trojan horse DLL in an unspecified directory.
Published 2022-03-31 · Modified
7.8EPSS 0.004
CVE-2021-42106
Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar to but not identical to CVE-2021-42104, 42105 and 42107.
Published 2021-10-21 · Modified
7.8EPSS 0.004
CVE-2021-42105
Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar to but not identical to CVE-2021-42104, 42106 and 42107.
Published 2021-10-21 · Modified
7.8EPSS 0.004
CVE-2021-42104
Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar to but not identical to CVE-2021-42105, 42106 and 42107.
Published 2021-10-21 · Modified
7.8EPSS 0.004
CVE-2024-39392
Adobe Indesign 2024 EPS File Parsing Heap Memory Corruption Remote Code Execution Vulnerability
Published 2024-08-02 · Analyzed
7.8EPSS 0.004
CVE-2021-42107
Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar to but not identical to CVE-2021-42104, 42105 and 42106.
Published 2021-10-21 · Modified
7.8EPSS 0.004
CVE-2023-24671
VX Search v13.8 and v14.7 was discovered to contain an unquoted service path vulnerability which allows attackers to execute arbitrary commands at elevated privileges via a crafted executable file.
Published 2023-03-16 · Modified
7.8EPSS 0.004
← Prev135 / 259Next →