VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10356CVEs
CVE-2019-5668
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiSubmitCommandVirtual in which the application dereferences a pointer that it expects to be valid, but is NULL, which may lead to denial of service or escalation of privileges.
Published 2019-02-27 · Modified
7.8EPSS 0.004
CVE-2026-81989
Acrobat Reader | Use After Free (CWE-416)
Published 2026-09-08 · Analyzed
7.8EPSS 0.004
CVE-2026-81990
Acrobat Reader | Use After Free (CWE-416)
Published 2026-09-08 · Analyzed
7.8EPSS 0.004
CVE-2026-27278
Acrobat Reader | Use After Free (CWE-416)
Published 2026-03-10 · Analyzed
7.8EPSS 0.004
CVE-2026-47921
Acrobat Reader | Use After Free (CWE-416)
Published 2026-06-09 · Analyzed
7.8EPSS 0.004
CVE-2020-3979
InstallBuilder for Qt Windows (versions prior to 20.7.0) installers look for plugins at a predictable location at initialization time, writable by non-admin users. While those plugins are not required, they are loaded if present, which could allow an attacker to plant a malicious library which could result in code execution with the security scope of the installer.
Published 2020-09-18 · Modified
7.8EPSS 0.004
CVE-2026-27276
Substance3D - Stager | Use After Free (CWE-416)
Published 2026-03-10 · Analyzed
7.8EPSS 0.004
CVE-2026-47915
Acrobat Reader | Use After Free (CWE-416)
Published 2026-06-09 · Analyzed
7.8EPSS 0.004
CVE-2026-47955
Acrobat Reader | Use After Free (CWE-416)
Published 2026-06-09 · Analyzed
7.8EPSS 0.004
CVE-2026-27309
Substance3D - Stager | Use After Free (CWE-416)
Published 2026-03-27 · Analyzed
7.8EPSS 0.004
CVE-2026-27283
InDesign Desktop | Use After Free (CWE-416)
Published 2026-04-14 · Analyzed
7.8EPSS 0.004
CVE-2026-27292
Adobe Framemaker | Use After Free (CWE-416)
Published 2026-04-14 · Analyzed
7.8EPSS 0.004
CVE-2026-27277
Substance3D - Stager | Use After Free (CWE-416)
Published 2026-03-10 · Analyzed
7.8EPSS 0.004
CVE-2026-47912
Acrobat Reader | Use After Free (CWE-416)
Published 2026-06-09 · Analyzed
7.8EPSS 0.004
CVE-2026-47914
Acrobat Reader | Use After Free (CWE-416)
Published 2026-06-09 · Analyzed
7.8EPSS 0.004
CVE-2026-47916
Acrobat Reader | Use After Free (CWE-416)
Published 2026-06-09 · Analyzed
7.8EPSS 0.004
CVE-2026-81988
Acrobat Reader | Use After Free (CWE-416)
Published 2026-09-08 · Analyzed
7.8EPSS 0.004
CVE-2026-81986
Acrobat Reader | Use After Free (CWE-416)
Published 2026-09-08 · Analyzed
7.8EPSS 0.004
CVE-2026-81985
Acrobat Reader | Use After Free (CWE-416)
Published 2026-09-08 · Analyzed
7.8EPSS 0.004
CVE-2026-81976
Acrobat Reader | Use After Free (CWE-416)
Published 2026-09-08 · Analyzed
7.8EPSS 0.004
CVE-2026-81975
Acrobat Reader | Use After Free (CWE-416)
Published 2026-09-08 · Analyzed
7.8EPSS 0.004
CVE-2026-81973
Acrobat Reader | Use After Free (CWE-416)
Published 2026-09-08 · Analyzed
7.8EPSS 0.004
CVE-2026-79909
Acrobat Reader | Use After Free (CWE-416)
Published 2026-09-08 · Analyzed
7.8EPSS 0.004
CVE-2026-7432
A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM
Published 2026-05-12 · Analyzed
7.8EPSS 0.004
CVE-2026-34638
Premiere Pro | Use After Free (CWE-416)
Published 2026-05-12 · Analyzed
7.8EPSS 0.004
CVE-2026-47919
Acrobat Reader | Use After Free (CWE-416)
Published 2026-06-09 · Analyzed
7.8EPSS 0.004
CVE-2026-47918
Acrobat Reader | Use After Free (CWE-416)
Published 2026-06-09 · Analyzed
7.8EPSS 0.004
CVE-2023-1004
MarkText WSH JScript code injection
Published 2023-02-24 · Modified
7.8EPSS 0.004
CVE-2026-47917
Acrobat Reader | Use After Free (CWE-416)
Published 2026-06-09 · Analyzed
7.8EPSS 0.004
CVE-2026-34696
InDesign Desktop | Use After Free (CWE-416)
Published 2026-06-09 · Analyzed
7.8EPSS 0.004
CVE-2026-47920
Acrobat Reader | Use After Free (CWE-416)
Published 2026-06-09 · Analyzed
7.8EPSS 0.004
CVE-2026-47913
Acrobat Reader | Use After Free (CWE-416)
Published 2026-06-09 · Analyzed
7.8EPSS 0.004
CVE-2022-34260
Adobe Illustrator Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-08-11 · Modified
7.8EPSS 0.004
CVE-2022-28226
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating temporary files in directory with insecure permissions during Yandex Browser update process.
Published 2022-06-15 · Modified
7.8EPSS 0.004
CVE-2025-21163
Illustrator | Stack-based Buffer Overflow (CWE-121)
Published 2025-02-11 · Analyzed
7.8EPSS 0.004
CVE-2016-8822
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x600000E, 0x600000F, and 0x6000010 where a value passed from a user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.
Published 2016-12-16 · Modified
7.8EPSS 0.004
CVE-2016-8825
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.
Published 2016-12-16 · Modified
7.8EPSS 0.004
CVE-2017-0346
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.
Published 2017-05-09 · Modified
7.8EPSS 0.004
CVE-2017-10740
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlRbInsertNodeEx+0x000000000000002d."
Published 2017-07-05 · Modified
7.8EPSS 0.004
CVE-2017-10746
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlEnterCriticalSection+0x0000000000000012."
Published 2017-07-05 · Modified
7.8EPSS 0.004
← Prev136 / 259Next →