VendorsMicrosoftwindowsany version
Vulnerabilities

Microsoft Windows any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10344CVEs
CVE-2009-4741
Unspecified vulnerability in the Extras Manager before 2.0.0.67 in Skype before 4.1.0.179 on Windows has unknown impact and attack vectors.
Published 2010-03-26 · Modified
10.0EPSS 0.020
CVE-2021-26607
TOBESOFT NEXACRO17 arbitrary command execution vulnerability
Published 2021-10-26 · Modified
10.0EPSS 0.019
CVE-2022-1884
Remote Command Execution in gogs/gogs
Published 2024-11-15 · Analyzed
10.0EPSS 0.018
CVE-2011-4743
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving smb/user/create and certain other files. NOTE: it is possible that only clients, not the Plesk product, could be affected by this issue.
Published 2011-12-16 · Modified
10.0EPSS 0.018
CVE-2011-4744
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving smb/admin-home/featured-applications/ and certain other files. NOTE: it is possible that only clients, not the Plesk product, could be affected by this issue.
Published 2011-12-16 · Modified
10.0EPSS 0.018
CVE-2011-4727
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not properly validate string data that is intended for storage in an XML document, which allows remote attackers to cause a denial of service (parsing error) or possibly have unspecified other impact via a crafted REST URL parameter, as demonstrated by parameters to admin/ and certain other files.
Published 2011-12-16 · Modified
10.0EPSS 0.018
CVE-2011-4732
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving account/power-mode-logout and certain other files. NOTE: it is possible that only clients, not the Plesk product, could be affected by this issue.
Published 2011-12-16 · Modified
10.0EPSS 0.018
CVE-2011-4733
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving smb/admin-home/disable-featured-applications-promo and certain other files. NOTE: it is possible that only clients, not the Plesk product, could be affected by this issue.
Published 2011-12-16 · Modified
10.0EPSS 0.018
CVE-2016-2077
VMware Workstation 11.x before 11.1.3 and VMware Player 7.x before 7.1.3 on Windows incorrectly access an executable file, which allows host OS users to gain host OS privileges via unspecified vectors.
Published 2016-05-18 · Modified
10.0EPSS 0.018
CVE-2008-6820
The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impact and attack vectors, a different vulnerability than CVE-2008-3856.
Published 2009-06-03 · Modified
10.0EPSS 0.018
CVE-2007-6045
Unspecified vulnerability in (1) DB2WATCH and (2) DB2FREEZE in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors.
Published 2007-11-20 · Modified
10.0EPSS 0.018
CVE-2007-6048
IBM DB2 UDB 9.1 before Fixpak 4 uses incorrect permissions on ACLs for DB2NODES.CFG, which has unknown impact and attack vectors. NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
Published 2007-11-20 · Modified
10.0EPSS 0.018
CVE-2020-12389
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.
Published 2020-05-26 · Modified
10.0EPSS 0.017
CVE-2007-6051
IBM DB2 UDB 9.1 before Fixpak 4 assigns incorrect privileges to the (1) DB2ADMNS and (2) DB2USERS alternative groups, which has unknown impact. NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
Published 2007-11-20 · Modified
10.0EPSS 0.015
CVE-2026-48323
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
Published 2026-08-03 · Analyzed
10.0EPSS 0.014
CVE-2026-76193
Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-08-25 · Analyzed
10.0EPSS 0.013
CVE-2026-89275
Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Published 2026-09-22 · Analyzed
10.0EPSS 0.012
CVE-2026-84412
Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Published 2026-09-22 · Analyzed
10.0EPSS 0.012
CVE-2026-75721
Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Published 2026-09-22 · Analyzed
10.0EPSS 0.012
CVE-2026-75703
Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Published 2026-09-22 · Analyzed
10.0EPSS 0.012
CVE-2026-75699
Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Published 2026-09-22 · Analyzed
10.0EPSS 0.012
CVE-2026-73369
Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Published 2026-09-22 · Analyzed
10.0EPSS 0.012
CVE-2026-75723
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
Published 2026-09-22 · Analyzed
10.0EPSS 0.012
CVE-2026-48286
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
Published 2026-06-30 · Analyzed
10.0EPSS 0.012
CVE-2026-48449
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
Published 2026-07-30 · Analyzed
10.0EPSS 0.012
CVE-2026-48303
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
Published 2026-06-09 · Analyzed
10.0EPSS 0.012
CVE-2026-48330
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2026-08-03 · Analyzed
10.0EPSS 0.010
CVE-2026-48331
Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-08-03 · Analyzed
10.0EPSS 0.009
CVE-2026-47938
Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-06-09 · Analyzed
10.0EPSS 0.009
CVE-2011-2822
Google Chrome before 13.0.782.215 on Windows does not properly parse URLs located on the command line, which has unspecified impact and attack vectors.
Published 2011-08-29 · Modified
10.0EPSS 0.009
CVE-2025-30411
Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.
Published 2026-02-20 · Analyzed
10.0EPSS 0.008
CVE-2023-27497
Multiple vulnerabilities in SAP Diagnostics Agent (EventLogServiceCollector)
Published 2023-04-11 · Modified
10.0EPSS 0.008
CVE-2025-30412
Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.
Published 2026-02-20 · Analyzed
10.0EPSS 0.007
CVE-2026-57211
RabbitMQ: UNC SSRF affecting the management UI on Windows
Published 2026-07-10 · Analyzed
10.0EPSS 0.006
CVE-2025-57870
BUG-000179884 - There is a security vulnerability in ArcGIS Server Feature Services.
Published 2025-10-22 · Analyzed
10.0EPSS 0.005
CVE-2025-30416
Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.
Published 2026-02-20 · Analyzed
10.0EPSS 0.005
CVE-2026-83660
Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-09-22 · Analyzed
10.0EPSS 0.003
CVE-2026-13782
Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-30 · Modified
10.0EPSS 0.003
CVE-2024-25693
Portal for ArcGIS has a directory traversal vulnerability.
Published 2024-04-04 · Analyzed
9.9EPSS 0.013
CVE-2021-26334
AMD Chipset Driver Information Disclosure Vulnerability
Published 2021-12-01 · Modified
9.9EPSS 0.012
← Prev27 / 259Next →