VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10350CVEs
CVE-2020-35712
Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.
Published 2020-12-25 · Modified
9.8EPSS 0.017
CVE-2019-17067
PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal an incoming connection.
Published 2019-10-01 · Modified
9.8EPSS 0.016
CVE-2020-7820
Tobesoft NEXACRO14/17 ExCommonApiV13 Arbitrary Code Execution Vulnerability
Published 2020-07-02 · Modified
9.8EPSS 0.016
CVE-2020-7821
Tobesoft NEXACRO14/17 ExCommonApiV13 Arbitrary Code Execution Vulnerability
Published 2020-07-02 · Modified
9.8EPSS 0.016
CVE-2025-23319
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds write by sending a request. A successful exploit of this vulnerability might lead to remote code execution, denial of service, data tampering, or information disclosure.
Published 2025-08-06 · Analyzed
9.8EPSS 0.016
CVE-2022-28331
Apache Portable Runtime (APR): Windows out-of-bounds write in apr_socket_sendv function
Published 2023-01-31 · Modified
9.8EPSS 0.016
CVE-2017-14397
AnyDesk before 3.6.1 on Windows has a DLL injection vulnerability.
Published 2017-09-12 · Modified
9.8EPSS 0.015
CVE-2018-4147
In iCloud for Windows before 7.3, Safari before 11.0.3, iTunes before 12.7.3 for Windows, and iOS before 11.2.5, multiple memory corruption issues exist and were addressed with improved memory handling.
Published 2019-01-11 · Modified
9.8EPSS 0.015
CVE-2021-37595
In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a FILECONTENTS_RANGE File Contents Request PDU.
Published 2021-07-27 · Modified
9.8EPSS 0.015
CVE-2020-4879
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of authentication cookies. IBM X-Force ID: 190847.
Published 2022-01-21 · Modified
9.8EPSS 0.015
CVE-2021-27193
Incorrect default permissions vulnerability in the API of Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to read and write files on the remote machine with system privileges resulting in a privilege escalation.
Published 2021-03-25 · Modified
9.8EPSS 0.015
CVE-2024-37385
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.
Published 2024-06-07 · Analyzed
9.8EPSS 0.015
CVE-2022-22487
An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker could exploit this vulnerability using brute force techniques to gain unauthorized administrative access to both the IBM Spectrum Protect storage agent and the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 with which it communicates. IBM X-Force ID: 226326.
Published 2022-06-30 · Modified
9.8EPSS 0.015
CVE-2020-19510
Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.
Published 2021-06-21 · Modified
9.8EPSS 0.015
CVE-2018-6634
A vulnerability in Parsec Windows 142-0 and Parsec 'Linux Ubuntu 16.04 LTS Desktop' Build 142-1 allows unauthorized users to maintain access to an account.
Published 2019-05-07 · Modified
9.8EPSS 0.015
CVE-2020-7861
AnySupport directory traversing vulnerability
Published 2021-04-22 · Modified
9.8EPSS 0.015
CVE-2025-49219
An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method.
Published 2025-06-17 · Analyzed
9.8EPSS 0.014
CVE-2021-37594
In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a FILECONTENTS_SIZE File Contents Request PDU.
Published 2021-07-27 · Modified
9.8EPSS 0.014
CVE-2023-32336
IBM InfoSphere Information Server code execution
Published 2023-05-22 · Modified
9.8EPSS 0.014
CVE-2022-31179
Insufficient escaping of line feeds for CMD in shescape
Published 2022-08-01 · Modified
9.8EPSS 0.014
CVE-2023-44324
ZDI-CAN-21344: Adobe FrameMaker Publishing Server Authentication Bypass Vulnerability
Published 2023-11-17 · Modified
9.8EPSS 0.014
CVE-2023-26512
Apache EventMesh RabbitMQ-Connector plugin allows RCE through deserialization of untrusted data
Published 2023-07-17 · Analyzed
9.8EPSS 0.013
CVE-2022-31657
VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect an authenticated user to an arbitrary domain.
Published 2022-08-05 · Modified
9.8EPSS 0.013
CVE-2023-41748
Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203.
Published 2023-08-31 · Modified
9.8EPSS 0.013
CVE-2023-41746
Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203.
Published 2023-08-31 · Modified
9.8EPSS 0.013
CVE-2021-26617
Gabia Firstmall remote code execution vulnerability
Published 2022-02-25 · Modified
9.8EPSS 0.013
CVE-2021-34690
iDrive RemotePC before 7.6.48 on Windows allows authentication bypass. A remote and unauthenticated attacker can bypass cloud authentication to connect and control a system via TCP port 5970 and 5980.
Published 2021-07-15 · Modified
9.8EPSS 0.012
CVE-2023-32557
A path traversal vulnerability in the Trend Micro Apex One and Apex One as a Service could allow an unauthenticated attacker to upload an arbitrary file to the Management Server which could lead to remote code execution with system privileges.
Published 2023-06-26 · Modified
9.8EPSS 0.012
CVE-2026-9181
Directory Traversal in ArcGIS Server
Published 2026-07-06 · Modified
9.8EPSS 0.012
CVE-2021-26612
tobesoft Nexacro platform arbitrary file creation vulnerability
Published 2021-11-30 · Modified
9.8EPSS 0.012
CVE-2023-5174
If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash. *This bug only affects Firefox on Windows when run in non-standard configurations (such as using `runas`). Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
Published 2023-09-27 · Modified
9.8EPSS 0.012
CVE-2020-7815
XPLATFORM v9.2.260 and eariler versions contain a vulnerability that could allow remote files to be downloaded by setting the arguments to the vulnerable method. this can be leveraged for code execution. File download vulnerability in ____COMPONENT____ of TOBESOFT XPLATFORM allows ____ATTACKER/ATTACK____ to cause ____IMPACT____. This issue affects: TOBESOFT XPLATFORM 9.2.250 versions prior to 9.2.260 on Windows.
Published 2020-07-10 · Modified
9.8EPSS 0.012
CVE-2024-50919
Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to arbitrary command execution
Published 2024-11-18 · Analyzed
9.8EPSS 0.012
CVE-2021-26642
XpressEngine file upload vulnerability
Published 2023-01-20 · Modified
9.8EPSS 0.012
CVE-2024-24482
Aprktool before 2.9.3 on Windows allows ../ and /.. directory traversal.
Published 2024-02-02 · Modified
9.8EPSS 0.012
CVE-2022-22425
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598."
Published 2022-11-03 · Modified
9.8EPSS 0.012
CVE-2020-7814
RAONWIZ v2018.0.2.50 and eariler versions contains a vulnerability that could allow remote files to be downloaded and excuted by lack of validation to file extension, witch can used as remote-code-excution attacks by hackers File download & execution vulnerability in ____COMPONENT____ of RAONWIZ RAON KUpload allows ____ATTACKER/ATTACK____ to cause ____IMPACT____. This issue affects: RAONWIZ RAON KUpload 2018.0.2.50 versions prior to 2018.0.2.51 on Windows.
Published 2020-07-10 · Modified
9.8EPSS 0.012
CVE-2019-20822
An issue was discovered in the 3D Plugin Beta for Foxit Reader and PhantomPDF before 9.7.0.29430. It has an out-of-bounds write via incorrect image data.
Published 2020-06-04 · Modified
9.8EPSS 0.011
CVE-2020-26944
An issue was discovered in Aptean Product Configurator 4.61.0000 on Windows. A Time based SQL injection affects the nameTxt parameter on the main login page (aka cse?cmd=LOGIN). This can be exploited directly, and remotely.
Published 2020-10-16 · Modified
9.8EPSS 0.011
CVE-2025-4660
Remote Code Execution in Windows Secure Connector/ HPS Inspection Engine via Insecure Named Pipe Access
Published 2025-05-13 · Analyzed
9.8EPSS 0.011
← Prev33 / 259Next →