VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10350CVEs
CVE-2022-35280
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 230634.
Published 2022-08-10 · Modified
9.8EPSS 0.008
CVE-2019-19167
Tobesoft Nexacro14 ActiveX File Download Vulnerability
Published 2020-05-06 · Modified
9.8EPSS 0.007
CVE-2020-7812
Kaoni ezHTTPTrans Active-X File Download and Execution Vulnerability
Published 2020-05-28 · Modified
9.8EPSS 0.007
CVE-2020-7806
Tobesoft Xplatform ActiveX File Download Vulnerability
Published 2020-05-06 · Modified
9.8EPSS 0.007
CVE-2026-13019
Missing Authentication
Published 2026-07-07 · Analyzed
9.8EPSS 0.007
CVE-2026-35561
Insufficient authentication security controls in browser-based authentication components in Amazon Athena ODBC driver
Published 2026-04-03 · Analyzed
9.8EPSS 0.007
CVE-2025-23318
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.
Published 2025-08-06 · Analyzed
9.8EPSS 0.007
CVE-2025-23316
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause a remote code execution by manipulating the model name parameter in the model control APIs. A successful exploit of this vulnerability might lead to remote code execution, denial of service, information disclosure, and data tampering.
Published 2025-09-17 · Analyzed
9.8EPSS 0.007
CVE-2023-38734
IBM Robotic Process Automation privilege escalation
Published 2023-08-22 · Modified
9.8EPSS 0.007
CVE-2020-7878
An arbitrary file download and execution vulnerability was found in the VideoOffice X2.9 and earlier versions (CVE-2020-7878). This issue is due to missing support for integrity check.
Published 2021-12-28 · Modified
9.8EPSS 0.007
CVE-2025-23251
NVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.
Published 2025-04-22 · Analyzed
9.8EPSS 0.007
CVE-2025-23249
NVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.
Published 2025-04-22 · Analyzed
9.8EPSS 0.007
CVE-2022-47984
IBM InfoSphere Information Server SQL injection
Published 2023-05-19 · Modified
9.8EPSS 0.007
CVE-2026-13473
IBM Storage Protect Client is vulnerable to Heap-Based Buffer Overflow
Published 2026-07-17 · Analyzed
9.8EPSS 0.007
CVE-2026-13448
Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
Published 2026-07-17 · Modified
9.8EPSS 0.007
CVE-2022-41552
Server-Side Request Forgery Vulnerability in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzer
Published 2022-11-01 · Modified
9.8EPSS 0.007
CVE-2023-45188
IBM Engineering Lifecycle Optimization Publishing file upload
Published 2024-06-09 · Analyzed
9.8EPSS 0.007
CVE-2022-23764
TERUTEN WebCube update remote code execution vulnerability
Published 2022-08-17 · Modified
9.8EPSS 0.007
CVE-2025-53378
A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attacker to remotely take control of the agent on affected installations. Also note: this vulnerability only affected the SaaS client version of WFBSS only, meaning the on-premise version of Worry-Free Business Security was not affected, and this issue was addressed in a WFBSS monthly maintenance update. Therefore no other customer action is required to mitigate if the WFBSS agents are on the regular SaaS maintenance deployment schedule and this disclosure is for informational purposes only.
Published 2025-07-10 · Analyzed
9.8EPSS 0.006
CVE-2022-3734
Redis on Windows dbghelp.dll uncontrolled search path
Published 2022-10-28 · Modified
9.8EPSS 0.006
CVE-2025-23250
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a restricted directory by an arbitrary file write. A successful exploit of this vulnerability might lead to code execution and data tampering.
Published 2025-04-22 · Analyzed
9.8EPSS 0.006
CVE-2023-4601
Stack-based Buffer Overflow in NI System Configuration Software
Published 2023-10-18 · Modified
9.8EPSS 0.006
CVE-2022-4126
Use of Default Password
Published 2023-03-27 · Modified
9.8EPSS 0.006
CVE-2026-9182
Unvalidated File Upload vulnerability in ArcGIS Server.
Published 2026-07-06 · Modified
9.8EPSS 0.006
CVE-2025-65115
Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 and JP1/NETM/DM
Published 2026-04-07 · Analyzed
9.8EPSS 0.006
CVE-2023-5765
Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to bypass permissions via data source switching.
Published 2023-11-01 · Modified
9.8EPSS 0.006
CVE-2026-28710
Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
Published 2026-03-05 · Analyzed
9.8EPSS 0.006
CVE-2025-10226
PostgreSQL Upgrade from v10 to v17.4 in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier to Address Multiple Vulnerabilities
Published 2025-09-10 · Analyzed
9.8EPSS 0.006
CVE-2024-33863
An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/Cdn/GetFile local file inclusion.
Published 2024-05-14 · Analyzed
9.8EPSS 0.006
CVE-2021-26608
handysoft groupware arbitrary file download and execution vulnerability
Published 2021-09-09 · Modified
9.8EPSS 0.006
CVE-2023-5766
A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute code from another windows user session on the same host via a specially crafted TCP packet.
Published 2023-11-01 · Modified
9.8EPSS 0.006
CVE-2025-23303
NVIDIA NeMo Framework for all platforms contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.
Published 2025-08-13 · Analyzed
9.8EPSS 0.006
CVE-2022-41157
ERP solution Remote Code Execution Vulnerability
Published 2022-11-25 · Modified
9.8EPSS 0.006
CVE-2025-49216
An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.
Published 2025-06-17 · Analyzed
9.8EPSS 0.005
CVE-2022-4146
EL Injection Vulnerability in Hitachi Replication Manager
Published 2023-07-18 · Modified
9.8EPSS 0.005
CVE-2025-3941
Improper Handling of Windows: DATA Alternate Data Stream
Published 2025-05-22 · Analyzed
9.8EPSS 0.005
CVE-2025-3944
Incorrect Permission Assignment for Critical Resource
Published 2025-05-22 · Analyzed
9.8EPSS 0.005
CVE-2019-4640
IBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code which could result in an attacker executing malicious code. IBM X-Force ID: 170046.
Published 2020-02-19 · Modified
9.8EPSS 0.005
CVE-2026-42249
Remote Code Execution in Ollama via Update Mechanism
Published 2026-04-29 · Analyzed
9.8EPSS 0.005
CVE-2025-23360
NVIDIA Nemo Framework contains a vulnerability where a user could cause a relative path traversal issue by arbitrary file write. A successful exploit of this vulnerability may lead to code execution and data tampering.
Published 2025-03-11 · Analyzed
9.8EPSS 0.005
← Prev35 / 259Next →