VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10350CVEs
CVE-2022-28181
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the network can cause an out-of-bounds write through a specially crafted shader, which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. The scope of the impact may extend to other components.
Published 2022-05-17 · Modified
9.9EPSS 0.011
CVE-2026-8476
Disk Cache Deserialization Remote Code Execution Vulnerability
Published 2026-07-17 · Analyzed
9.9EPSS 0.010
CVE-2026-48326
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2026-08-03 · Analyzed
9.9EPSS 0.010
CVE-2026-8481
Remote Code Execution via Code Validation Endpoint
Published 2026-07-17 · Analyzed
9.9EPSS 0.009
CVE-2026-9135
Policies Component Dynamic CodeInput Fields Bypass Custom Component Validation
Published 2026-07-17 · Analyzed
9.9EPSS 0.008
CVE-2026-82013
Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-09-22 · Analyzed
9.9EPSS 0.008
CVE-2026-8859
Path Traversal in APIRequest Component via Content-Disposition Header
Published 2026-07-17 · Analyzed
9.9EPSS 0.006
CVE-2026-75682
Adobe Connect | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2026-09-22 · Analyzed
9.9EPSS 0.005
CVE-2026-82008
Adobe Campaign Classic (ACC) | Improper Input Validation (CWE-20)
Published 2026-09-22 · Analyzed
9.9EPSS 0.005
CVE-2026-8635
Arbitrary Code Execution in Python Interpreter Component
Published 2026-07-17 · Analyzed
9.9EPSS 0.005
CVE-2026-89276
Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Published 2026-09-22 · Analyzed
9.9EPSS 0.005
CVE-2026-82010
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2026-09-22 · Analyzed
9.9EPSS 0.004
CVE-2026-82443
Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-09-22 · Analyzed
9.9EPSS 0.004
CVE-2025-13032
Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3  on windows allows local attacker to escalate privelages via pool overflow.
Published 2025-11-11 · Analyzed
9.9EPSS 0.002
CVE-2024-4577
Argument Injection in PHP-CGI
Published 2024-06-09 · Analyzed
9.8KEV1 PoCEPSS 1.000
CVE-2022-47986
IBM Aspera Faspex code execution
Published 2023-02-17 · Analyzed
9.8KEV1 PoCEPSS 1.000
CVE-2013-0625
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January 2013.
Published 2013-01-09 · Analyzed
9.8KEV1 PoCEPSS 0.938
CVE-2023-46264
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.
Published 2023-12-19 · Modified
9.8EPSS 0.902
CVE-2021-20021
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
Published 2021-04-09 · Analyzed
9.8KEVEPSS 0.887
CVE-2017-14491
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
Published 2017-10-02 · Modified
9.81 PoCEPSS 0.849
CVE-2023-46263
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remote code execution.
Published 2023-12-19 · Modified
9.8EPSS 0.819
CVE-2023-39143
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).
Published 2023-08-04 · Modified
9.8EPSS 0.801
CVE-2014-9390
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem.
Published 2020-02-12 · Modified
9.8EPSS 0.756
CVE-2019-13373
An issue was discovered in the D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6. Input does not get validated and arbitrary SQL statements can be executed in the database via the /web/Public/Conn.php parameter dbSQL.
Published 2019-07-06 · Modified
9.8EPSS 0.680
CVE-2022-3229
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this now-unauthenticated access to run code of the attacker's choosing.
Published 2023-02-06 · Modified
9.8EPSS 0.664
CVE-2024-1222
Incorrect authorization controls in PaperCut NG/MF APIs
Published 2024-03-14 · Analyzed
9.8EPSS 0.640
CVE-2019-8050
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
Published 2019-08-20 · Modified
9.81 PoCEPSS 0.406
CVE-2023-46216
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
Published 2023-12-19 · Modified
9.8EPSS 0.364
CVE-2023-46217
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
Published 2023-12-19 · Modified
9.8EPSS 0.364
CVE-2023-41727
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
Published 2023-12-19 · Modified
9.8EPSS 0.364
CVE-2017-11282
Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.
Published 2017-12-01 · Modified
9.81 PoCEPSS 0.348
CVE-2018-12848
Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2018-09-25 · Modified
9.8EPSS 0.347
CVE-2019-8048
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .
Published 2019-08-20 · Modified
9.81 PoCEPSS 0.346
CVE-2017-11281
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.
Published 2017-12-01 · Modified
9.82 PoCEPSS 0.339
CVE-2025-13315
Unauthenticated log access in Twonky Server
Published 2025-11-19 · Analyzed
9.8EPSS 0.323
CVE-2022-28054
Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execute arbitrary code via a crafted value.
Published 2022-05-02 · Modified
9.8EPSS 0.319
CVE-2011-4373
Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-4370 and CVE-2011-4372.
Published 2012-01-10 · Modified
9.8EPSS 0.303
CVE-2022-27115
In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.
Published 2022-04-11 · Modified
9.8EPSS 0.286
CVE-2019-13375
A SQL Injection was discovered in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 in PayAction.class.php with the index.php/Pay/passcodeAuth parameter passcode. The vulnerability does not need any authentication.
Published 2019-07-06 · Modified
9.8EPSS 0.282
CVE-2022-31656
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
Published 2022-08-05 · Modified
9.8EPSS 0.229
← Prev28 / 259Next →