VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10350CVEs
CVE-2022-22317
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281.
Published 2022-06-20 · Modified
9.8EPSS 0.005
CVE-2024-25140
A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under Trusted Root Certification Authorities with Enhanced Key Usage of Code Signing (1.3.6.1.5.5.7.3.3), valid from 2023 until 2033. This is potentially unwanted, e.g., because there is no public documentation of security measures for the private key, and arbitrary software could be signed if the private key were to be compromised. NOTE: the vendor's position is "we do not have EV cert, so we use test cert as a workaround." Insertion into Trusted Root Certification Authorities was the originally intended behavior, and the UI ensured that the certificate installation step (checked by default) was visible to the user before proceeding with the product installation.
Published 2024-02-06 · Modified
9.8EPSS 0.005
CVE-2026-9258
Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Published 2026-06-15 · Analyzed
9.8EPSS 0.005
CVE-2026-33519
Incorrect privilege assignment in Portal for ArcGIS
Published 2026-04-21 · Analyzed
9.8EPSS 0.005
CVE-2025-34196
Vasion Print (formerly PrinterLogic) Hardcoded PrinterLogic CA Private Key and Hardcoded Password
Published 2025-09-29 · Analyzed
9.8EPSS 0.005
CVE-2026-13020
Weak Password Recovery Mechanism in Portal for ArcGIS
Published 2026-07-07 · Analyzed
9.8EPSS 0.005
CVE-2026-33518
Incorrect privilege assignment in Portal for ArcGIS
Published 2026-04-21 · Analyzed
9.8EPSS 0.005
CVE-2025-3500
Integer Overflow in Avast Antiviurs 25.1.981.6 on Windows may result in privilege escalation
Published 2025-12-01 · Analyzed
9.8EPSS 0.005
CVE-2024-0715
EL Injection Vulnerability in Hitachi Global Link Manager
Published 2024-02-20 · Analyzed
9.8EPSS 0.005
CVE-2026-30783
RustDesk Client Can Orphan API Channel to Ignore All Admin Commands and ACL Policies
Published 2026-03-05 · Modified
9.8EPSS 0.005
CVE-2022-22318
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
Published 2022-06-20 · Modified
9.8EPSS 0.004
CVE-2024-9194
SQL Injection in the Octopus Server REST API
Published 2024-09-30 · Analyzed
9.8EPSS 0.004
CVE-2024-51736
Command execution hijack on Windows with Process class in symfony/process
Published 2024-11-06 · Analyzed
9.8EPSS 0.004
CVE-2026-9260
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Published 2026-06-15 · Analyzed
9.8EPSS 0.004
CVE-2025-14917
IBM WebSphere Application Server Liberty could provide weaker than expected security
Published 2026-03-25 · Analyzed
9.8EPSS 0.004
CVE-2025-3936
Incorrect Permission Assignment for Critical Resource
Published 2025-05-22 · Analyzed
9.8EPSS 0.004
CVE-2026-13446
Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
Published 2026-07-17 · Analyzed
9.8EPSS 0.004
CVE-2026-3062
Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Published 2026-02-23 · Modified
9.8EPSS 0.004
CVE-2024-5828
EL Injection Vulnerability in Hitachi Tuning Manager
Published 2024-08-06 · Analyzed
9.8EPSS 0.004
CVE-2025-3940
Improper Use of Validation Framework
Published 2025-05-22 · Analyzed
9.8EPSS 0.004
CVE-2025-3937
Use of Password Hash with Insufficient Computational Effort
Published 2025-05-22 · Analyzed
9.8EPSS 0.004
CVE-2025-11719
Use-after-free caused by the native messaging web extension API on Windows
Published 2025-10-14 · Modified
9.8EPSS 0.004
CVE-2025-3938
Missing Cryptographic Step
Published 2025-05-22 · Analyzed
9.8EPSS 0.003
CVE-2026-13776
Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-30 · Modified
9.8EPSS 0.003
CVE-2026-0906
Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
Published 2026-01-20 · Analyzed
9.8EPSS 0.003
CVE-2026-9259
Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Published 2026-06-15 · Analyzed
9.8EPSS 0.003
CVE-2026-30793
RustDesk Flutter URI Handler Sets Permanent Password Without Privilege Check or User Confirmation
Published 2026-03-05 · Analyzed
9.8EPSS 0.003
CVE-2026-5902
Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media stream metadata via a crafted HTML page. (Chromium security severity: Low)
Published 2026-04-08 · Analyzed
9.8EPSS 0.003
CVE-2026-42248
Missing Signature Verification for Updates in Ollama
Published 2026-04-29 · Analyzed
9.8EPSS 0.003
CVE-2026-30789
RustDesk Auth Proof Uses Server-Controlled Salt/Challenge and Fast Double-SHA256, Enabling Offline Brute-Force
Published 2026-03-05 · Modified
9.8EPSS 0.003
CVE-2026-9261
Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Published 2026-06-15 · Analyzed
9.8EPSS 0.003
CVE-2025-69270
Spectrum session token in URL
Published 2026-01-12 · Analyzed
9.8EPSS 0.003
CVE-2026-13775
Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-30 · Modified
9.8EPSS 0.003
CVE-2026-47304
.NET Security Feature Bypass Vulnerability
Published 2026-07-14 · Analyzed
9.8EPSS 0.003
CVE-2025-43491
Poly Lens Desktop Application – Privilege Escalation
Published 2025-09-09 · Analyzed
9.8EPSS 0.003
CVE-2026-0905
Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a network log file to potentially obtain potentially sensitive information via a network log file. (Chromium security severity: Medium)
Published 2026-01-20 · Analyzed
9.8EPSS 0.002
CVE-2021-28550
Adobe Acrobat Reader use after free vulnerability could lead to arbitrary code execution
Published 2021-09-02 · Analyzed
9.6KEVEPSS 0.520
CVE-2024-12108
WhatsUp Gold - Public API signing key rotation issue
Published 2024-12-31 · Analyzed
9.6EPSS 0.068
CVE-2026-10886
Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-04 · Analyzed
9.6EPSS 0.062
CVE-2023-28347
An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a proof-of-concept script that functions similarly to a Student Console, providing unauthenticated attackers with the ability to exploit XSS vulnerabilities within the Teacher Console application and achieve remote code execution as NT AUTHORITY/SYSTEM on all connected Student Consoles and the Teacher Console in a Zero Click manner.
Published 2023-05-30 · Modified
9.6EPSS 0.028
← Prev36 / 259Next →