VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10351CVEs
CVE-2020-20907
MetInfo 7.0 beta is affected by a file modification vulnerability. Attackers can delete and modify ini files in app/system/language/admin/language_general.class.php and app/system/include/function/file.func.php.
Published 2021-05-24 · Modified
9.1EPSS 0.022
CVE-2021-38948
IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 211402.
Published 2021-11-02 · Modified
9.1EPSS 0.020
CVE-2017-8989
A security vulnerability in HPE IceWall SSO Dfw 10.0 and 11.0 on RHEL, HP-UX, and Windows could be exploited remotely to allow URL Redirection.
Published 2018-08-06 · Modified
9.1EPSS 0.018
CVE-2022-22489
IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 226339.
Published 2022-08-19 · Modified
9.1EPSS 0.017
CVE-2024-40898
Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows
Published 2024-07-18 · Modified
9.1EPSS 0.015
CVE-2022-22952
VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload vulnerability. A malicious actor with administrative access to the VMware App Control administration interface may be able to execute code on the Windows instance where AppC Server is installed by uploading a specially crafted file.
Published 2022-03-23 · Modified
9.1EPSS 0.015
CVE-2020-7882
anySign directory traversal vulnerability
Published 2021-11-22 · Modified
9.1EPSS 0.013
CVE-2024-2362
Path Traversal in parisneo/lollms-webui
Published 2024-06-06 · Analyzed
9.1EPSS 0.012
CVE-2022-41746
A forced browsing vulnerability in Trend Micro Apex One could allow an attacker with access to the Apex One console on affected installations to escalate privileges and modify certain agent groupings. Please note: an attacker must first obtain the ability to log onto the Apex One web console in order to exploit this vulnerability.
Published 2022-10-10 · Modified
9.1EPSS 0.011
CVE-2026-75728
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
Published 2026-09-22 · Analyzed
9.1EPSS 0.010
CVE-2023-44206
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
Published 2023-09-27 · Modified
9.1EPSS 0.010
CVE-2022-40747
"IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 236584."
Published 2022-11-03 · Modified
9.1EPSS 0.010
CVE-2026-82009
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2026-09-22 · Analyzed
9.1EPSS 0.010
CVE-2023-47702
IBM Security Guardium Key Lifecycle Manager directory traversal
Published 2023-12-20 · Modified
9.1EPSS 0.010
CVE-2021-26619
BigFileAgent arbitrary file Deleting vulnerability
Published 2022-02-18 · Modified
9.1EPSS 0.009
CVE-2023-44152
Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.
Published 2023-09-27 · Modified
9.1EPSS 0.009
CVE-2016-5202
browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which causes the erase operation to access data that that erase operation will destroy.
Published 2019-10-25 · Modified
9.1EPSS 0.008
CVE-2024-41783
IBM Sterling Secure Proxy improper input validation
Published 2025-01-19 · Analyzed
9.1EPSS 0.007
CVE-2023-29487
An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to cause a denial of service (DoS) via the Threat To Process Correlation threat prevention module. NOTE: Heimdal asserts this is not a valid vulnerability. Their DNS Security for Endpoint solution includes an optional feature to provide extra information on the originating process that made a DNS request. The lack of process identification in DNS logs is therefore falsely categorized as a DoS issue.
Published 2023-12-21 · Modified
9.1EPSS 0.007
CVE-2026-19297
Insufficient Authentication Brute Force Protection on Login Endpoint
Published 2026-08-13 · Analyzed
9.1EPSS 0.006
CVE-2026-8646
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
Published 2026-06-22 · Analyzed
9.1EPSS 0.006
CVE-2026-82011
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2026-09-22 · Analyzed
9.1EPSS 0.006
CVE-2022-43842
IBM Aspera Console SQL injection
Published 2024-02-23 · Analyzed
9.1EPSS 0.005
CVE-2025-23327
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer overflow through specially crafted inputs. A successful exploit of this vulnerability might lead to denial of service and data tampering.
Published 2025-08-06 · Analyzed
9.1EPSS 0.005
CVE-2024-38337
IBM Sterling Secure Proxy improper input validation
Published 2025-01-19 · Analyzed
9.1EPSS 0.005
CVE-2025-0502
Transmission of Private Resources into a New Sphere in Crafter Engine
Published 2025-01-15 · Analyzed
9.1EPSS 0.004
CVE-2026-9006
IBM WebSphere Application Server is affected by server-side request forgery
Published 2026-06-22 · Analyzed
9.1EPSS 0.004
CVE-2026-35560
Improper certificate validation in identity provider connection components in Amazon Athena ODBC driver
Published 2026-04-03 · Analyzed
9.1EPSS 0.004
CVE-2026-3061
Out of bounds read in Media in Google Chrome prior to 145.0.7632.116 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Published 2026-02-23 · Modified
9.1EPSS 0.003
CVE-2026-8856
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
9.1EPSS 0.003
CVE-2026-0704
In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.
Published 2026-02-25 · Modified
9.1EPSS 0.003
CVE-2026-8673
Password re-initialization mechanism sends passwords in plain text
Published 2026-05-22 · Analyzed
9.1EPSS 0.003
CVE-2023-44208
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40713, Acronis True Image OEM (Windows) before build 42575.
Published 2023-10-04 · Modified
9.1EPSS 0.003
CVE-2025-10890
Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Published 2025-09-24 · Analyzed
9.1EPSS 0.003
CVE-2024-49388
Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
Published 2024-10-15 · Analyzed
9.1EPSS 0.003
CVE-2026-11153
Side-channel information leakage in Forms in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
9.1EPSS 0.003
CVE-2021-20081
Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges.
Published 2021-06-10 · Modified
9.0EPSS 0.524
CVE-2015-4796
Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2, when running on Windows, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2015-4888.
Published 2015-10-21 · Modified
9.0EPSS 0.179
CVE-2011-3310
The Home Page component in Cisco CiscoWorks Common Services before 4.1 on Windows, as used in CiscoWorks LAN Management Solution, Cisco Security Manager, Cisco Unified Service Monitor, Cisco Unified Operations Manager, CiscoWorks QoS Policy Manager, and CiscoWorks Voice Manager, allows remote authenticated users to execute arbitrary commands via a crafted URL, aka Bug IDs CSCtq48990, CSCtq63992, CSCtq64011, CSCtq64019, CSCtr23090, and CSCtt25535.
Published 2011-10-20 · Modified
9.0EPSS 0.152
CVE-2009-4653
Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to cause a denial of service (dhost.exe crash) and possibly execute arbitrary code via a long string to /dhost/modules?I:.
Published 2010-02-26 · Modified
9.01 PoCEPSS 0.129
← Prev68 / 259Next →