VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10351CVEs
CVE-2021-40727
Adobe InDesign crashes when parsing the TIF file
Published 2022-06-15 · Modified
9.3EPSS 0.015
CVE-2020-7819
nTracker USB Enterprise SQL-Injection vulnerability
Published 2021-09-07 · Modified
9.3EPSS 0.015
CVE-2019-15286
Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerabilities
Published 2019-11-26 · Modified
9.3EPSS 0.014
CVE-2019-15284
Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerabilities
Published 2019-11-26 · Modified
9.3EPSS 0.014
CVE-2024-6913
Execution with Unnecessary Privileges
Published 2024-07-22 · Modified
9.3EPSS 0.014
CVE-2017-7127
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. iCloud before 7.0 on Windows is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "SQLite" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
Published 2017-10-23 · Modified
9.3EPSS 0.014
CVE-2020-16087
An issue was discovered in Zalo.exe in VNG Zalo Desktop 19.8.1.0. An attacker can run arbitrary commands on a remote Windows machine running the Zalo client by sending the user of the device a crafted file.
Published 2020-08-13 · Modified
9.3EPSS 0.013
CVE-2007-6053
IBM DB2 UDB 9.1 before Fixpak 4 does not properly handle use of large numbers of file descriptors, which might allow attackers to have an unknown impact involving "memory corruption." NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
Published 2007-11-20 · Modified
9.3EPSS 0.013
CVE-2019-13404
The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for local users to deploy Trojan horse code. (This also affects old 3.x releases before 3.5.) NOTE: the vendor's position is that it is the user's responsibility to ensure C:\Python27 access control or choose a different directory, because backwards compatibility requires that C:\Python27 remain the default for 2.7.x
Published 2019-07-08 · Modified
9.3EPSS 0.013
CVE-2017-7053
An issue was discovered in certain Apple products. iTunes before 12.6.2 on Windows is affected. The issue involves the "iTunes" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app.
Published 2017-07-20 · Modified
9.3EPSS 0.013
CVE-2017-10851
Untrusted search path vulnerability in Installer for ContentsBridge Utility for Windows 7.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published 2017-09-01 · Modified
9.3EPSS 0.011
CVE-2017-10887
Untrusted search path vulnerability in BOOK WALKER for Windows Ver.1.2.9 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published 2017-11-17 · Modified
9.3EPSS 0.011
CVE-2026-48334
Illustrator | Improper Input Validation (CWE-20)
Published 2026-07-14 · Analyzed
9.3EPSS 0.010
CVE-2026-27245
Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2026-04-14 · Analyzed
9.3EPSS 0.007
CVE-2026-34691
Adobe Experience Manager Forms JEE | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-06-09 · Analyzed
9.3EPSS 0.007
CVE-2026-27246
Adobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79)
Published 2026-04-14 · Analyzed
9.3EPSS 0.007
CVE-2026-27243
Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2026-04-14 · Analyzed
9.3EPSS 0.007
CVE-2026-75686
Adobe Connect | Improper Input Validation (CWE-20)
Published 2026-09-22 · Analyzed
9.3EPSS 0.006
CVE-2018-3990
An exploitable pool corruption vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTEMS WibuKey.sys Version 6.40 (Build 2400). A specially crafted IRP request can cause a buffer overflow, resulting in kernel memory corruption and, potentially, privilege escalation. An attacker can send an IRP request to trigger this vulnerability.
Published 2019-02-05 · Modified
9.3EPSS 0.006
CVE-2026-30797
RustDesk rustdesk://config/ URI Silently Re-homes Client to Attacker-Controlled Server
Published 2026-03-05 · Analyzed
9.3EPSS 0.006
CVE-2025-49553
Adobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79)
Published 2025-10-14 · Analyzed
9.3EPSS 0.005
CVE-2026-14973
Path Traversal in IBM Desktop App
Published 2026-07-28 · Analyzed
9.3EPSS 0.005
CVE-2020-36169
An issue was discovered in Veritas NetBackup through 8.3.0.1 and OpsCenter through 8.3.0.1. Processes using OpenSSL attempt to load and execute libraries from paths that do not exist by default on the Windows operating system. By default, on Windows systems, users can create directories under the top level of any drive. If a low privileged user creates an affected path with a library that the Veritas product attempts to load, they can execute arbitrary code as SYSTEM or Administrator. This gives the attacker administrator access on the system, allowing the attacker (by default) to access all data, access all installed applications, etc. This vulnerability affects master servers, media servers, clients, and OpsCenter servers on the Windows platform. The system is vulnerable during an install or upgrade and post-install during normal operations.
Published 2021-01-06 · Modified
9.3EPSS 0.004
CVE-2020-36160
An issue was discovered in Veritas System Recovery before 21.2. On start-up, it loads the OpenSSL library from \usr\local\ssl. This library attempts to load the from \usr\local\ssl\openssl.cnf configuration file, which does not exist. By default, on Windows systems, users can create directories under C:\. A low privileged user can create a C:\usr\local\ssl\openssl.cnf configuration file to load a malicious OpenSSL engine, resulting in arbitrary code execution as SYSTEM when the service starts. This gives the attacker administrator access on the system, allowing the attacker (by default) to access all data and installed applications, etc. If the system is also an Active Directory domain controller, then this can affect the entire domain.
Published 2021-01-06 · Modified
9.3EPSS 0.004
CVE-2020-36165
An issue was discovered in Veritas Desktop and Laptop Option (DLO) before 9.4. On start-up, it loads the OpenSSL library from /ReleaseX64/ssl. This library attempts to load the /ReleaseX64/ssl/openssl.cnf configuration file, which does not exist. By default, on Windows systems, users can create directories under C:\. A low privileged user can create a C:/ReleaseX64/ssl/openssl.cnf configuration file to load a malicious OpenSSL engine, resulting in arbitrary code execution as SYSTEM when the service starts. This gives the attacker administrator access on the system, allowing the attacker (by default) to access all data, access all installed applications, etc. This impacts DLO server and client installations.
Published 2021-01-06 · Modified
9.3EPSS 0.004
CVE-2020-36166
An issue was discovered in Veritas InfoScale 7.x through 7.4.2 on Windows, Storage Foundation through 6.1 on Windows, Storage Foundation HA through 6.1 on Windows, and InfoScale Operations Manager (aka VIOM) Windows Management Server 7.x through 7.4.2. On start-up, it loads the OpenSSL library from \usr\local\ssl. This library attempts to load the \usr\local\ssl\openssl.cnf configuration file, which may not exist. On Windows systems, this path could translate to <drive>:\usr\local\ssl\openssl.cnf, where <drive> could be the default Windows installation drive such as C:\ or the drive where a Veritas product is installed. By default, on Windows systems, users can create directories under any top-level directory. A low privileged user can create a <drive>:\usr\local\ssl\openssl.cnf configuration file to load a malicious OpenSSL engine, resulting in arbitrary code execution as SYSTEM when the service starts. This gives the attacker administrator access on the system, allowing the attacker (by default) to access all data, access all installed applications, etc.
Published 2021-01-06 · Modified
9.3EPSS 0.004
CVE-2020-36162
An issue was discovered in Veritas CloudPoint before 8.3.0.1+hotfix. The CloudPoint Windows Agent leverages OpenSSL. This OpenSSL library attempts to load the \usr\local\ssl\openssl.cnf configuration file, which does not exist. By default, on Windows systems users can create directories under <drive>:\. A low privileged user can create a <drive>:\usr\local\ssl\openssl.cnf configuration file to load a malicious OpenSSL engine, which may result in arbitrary code execution. This would give the attacker administrator access on the system, allowing the attacker (by default) to access all data, access all installed applications, etc.
Published 2021-01-06 · Modified
9.3EPSS 0.004
CVE-2020-36164
An issue was discovered in Veritas Enterprise Vault through 14.0. On start-up, it loads the OpenSSL library. The OpenSSL library then attempts to load the openssl.cnf configuration file (which does not exist) at the following locations in both the System drive (typically C:\) and the product's installation drive (typically not C:\): \Isode\etc\ssl\openssl.cnf (on SMTP Server) or \user\ssl\openssl.cnf (on other affected components). By default, on Windows systems, users can create directories under C:\. A low privileged user can create a openssl.cnf configuration file to load a malicious OpenSSL engine, resulting in arbitrary code execution as SYSTEM when the service starts. This gives the attacker administrator access on the system, allowing the attacker (by default) to access all data, access all installed applications, etc. This vulnerability only affects a server with MTP Server, SMTP Archiving IMAP Server, IMAP Archiving, Vault Cloud Adapter, NetApp File server, or File System Archiving for NetApp as File Server.
Published 2021-01-06 · Modified
9.3EPSS 0.004
CVE-2020-36163
An issue was discovered in Veritas NetBackup and OpsCenter through 8.3.0.1. NetBackup processes using Strawberry Perl attempt to load and execute libraries from paths that do not exist by default on the Windows operating system. By default, on Windows systems, users can create directories under C:\. If a low privileged user on the Windows system creates an affected path with a library that NetBackup attempts to load, they can execute arbitrary code as SYSTEM or Administrator. This gives the attacker administrator access on the system, allowing the attacker (by default) to access all data, access all installed applications, etc. This affects NetBackup master servers, media servers, clients, and OpsCenter servers on the Windows platform. The system is vulnerable during an install or upgrade on all systems and post-install on Master, Media, and OpsCenter servers during normal operations.
Published 2021-01-06 · Modified
9.3EPSS 0.004
CVE-2024-7263
Arbitrary Code Execution in WPS Office
Published 2024-08-15 · Analyzed
9.3EPSS 0.004
CVE-2026-11707
Multiple vulnerabilities have been identified in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager
Published 2026-07-30 · Analyzed
9.3EPSS 0.004
CVE-2026-75698
Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2026-09-22 · Analyzed
9.3EPSS 0.003
CVE-2026-75697
Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-09-22 · Analyzed
9.3EPSS 0.003
CVE-2026-75689
Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-09-22 · Analyzed
9.3EPSS 0.003
CVE-2026-75684
Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-09-22 · Analyzed
9.3EPSS 0.003
CVE-2022-22951
VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network access to the VMware App Control administration interface may be able to execute commands on the server due to improper input validation leading to remote code execution.
Published 2022-03-23 · Modified
9.1EPSS 0.203
CVE-2020-4006
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
Published 2020-11-23 · Analyzed
9.1KEVEPSS 0.173
CVE-2020-7061
heap-buffer-overflow in phar_extract_file
Published 2020-02-27 · Modified
9.1EPSS 0.041
CVE-2022-26629
An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function.
Published 2022-03-24 · Modified
9.1EPSS 0.028
CVE-2018-1426
IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) duplicates the PRNG state across fork() system calls when multiple ICC instances are loaded which could result in duplicate Session IDs and a risk of duplicate key material. IBM X-Force ID: 139071.
Published 2018-03-22 · Modified
9.1EPSS 0.024
← Prev67 / 259Next →