VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10355CVEs
CVE-2017-5049
An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.
Published 2017-04-25 · Modified
8.8EPSS 0.009
CVE-2017-5050
An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.
Published 2017-04-25 · Modified
8.8EPSS 0.009
CVE-2023-2984
Path Traversal: '\..\filename' in pimcore/pimcore
Published 2023-05-30 · Modified
8.8EPSS 0.009
CVE-2023-31036
CVE
Published 2024-01-12 · Modified
8.8EPSS 0.009
CVE-2017-5051
An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.
Published 2017-04-25 · Modified
8.8EPSS 0.009
CVE-2026-63093
Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace
Published 2026-07-17 · Analyzed
8.8EPSS 0.008
CVE-2023-47706
IBM Security Guardium Key Lifecycle Manager file upload
Published 2023-12-20 · Modified
8.8EPSS 0.008
CVE-2026-47303
ASP.NET Core Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
8.8EPSS 0.008
CVE-2026-69439
.NET and Visual Studio Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
8.8EPSS 0.008
CVE-2025-49214
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code execution on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
Published 2025-06-17 · Analyzed
8.8EPSS 0.008
CVE-2021-1257
Cisco DNA Center Cross-Site Request Forgery Vulnerability
Published 2021-01-20 · Modified
8.8EPSS 0.008
CVE-2020-16022
Insufficient policy enforcement in networking in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially bypass firewall controls via a crafted HTML page.
Published 2021-01-08 · Modified
8.8EPSS 0.008
CVE-2020-7877
ZOOK solution(remote administration tool) buffer overflow vulnerability
Published 2021-09-07 · Modified
8.8EPSS 0.008
CVE-2021-29686
IBM Security Identity Manager 7.0.2 could allow an authenticated user to bypass security and perform actions that they should not have access to. IBM X-Force ID: 200015
Published 2021-05-20 · Modified
8.8EPSS 0.008
CVE-2024-5495
Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2024-05-30 · Analyzed
8.8EPSS 0.008
CVE-2026-47300
ASP.NET Core Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
8.8EPSS 0.008
CVE-2024-5494
Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2024-05-30 · Analyzed
8.8EPSS 0.008
CVE-2024-22014
An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated privileges via Symbolic Link Follow to Arbitrary File Delete.
Published 2024-04-15 · Analyzed
8.8EPSS 0.008
CVE-2026-71328
.NET and Visual Studio Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
8.8EPSS 0.008
CVE-2026-7755
MCP Server Configuration Validator Bypass via File Upload API
Published 2026-07-17 · Modified
8.8EPSS 0.007
CVE-2021-29754
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006.
Published 2021-06-11 · Modified
8.8EPSS 0.007
CVE-2019-18568
Avira Free Antivirus is proned to a local privilege escalation through the execution of kernel code from a restricted user.
Published 2019-12-31 · Modified
8.8EPSS 0.007
CVE-2022-45052
Local File Inclusion in Axiell Iguana CMS
Published 2023-01-04 · Modified
8.8EPSS 0.007
CVE-2023-0882
Authorization Bypass Through User-Controlled Key on Single Connect
Published 2023-02-17 · Modified
8.8EPSS 0.007
CVE-2023-35080
A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, denial of service, or information disclosure.
Published 2023-11-14 · Modified
8.8EPSS 0.007
CVE-2018-6664
SB10233 - Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint before 11.0.400 - Application Protections Bypass vulnerability
Published 2018-05-25 · Modified
8.8EPSS 0.007
CVE-2026-3909
Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Published 2026-03-12 · Analyzed
8.8KEVEPSS 0.007
CVE-2026-5281
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Published 2026-04-01 · Analyzed
8.8KEVEPSS 0.007
CVE-2023-40683
IBM OpenPages with Watson privilege escalation
Published 2024-01-19 · Modified
8.8EPSS 0.007
CVE-2022-0798
Use after free in MediaStream in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
Published 2022-04-05 · Modified
8.8EPSS 0.007
CVE-2022-48199
SoftPerfect NetWorx 7.1.1 on Windows allows an attacker to execute a malicious binary with potentially higher privileges via a low-privileged user account that abuses the Notifications function. The Notifications function allows for arbitrary binary execution and can be modified by any user. The resulting binary execution will occur in the context of any user running NetWorx. If an attacker modifies the Notifications function to execute a malicious binary, the binary will be executed by every user running NetWorx on that system.
Published 2023-01-24 · Modified
8.8EPSS 0.007
CVE-2026-33414
PowerShell Command Injection in Podman HyperV Machine
Published 2026-04-14 · Modified
8.8EPSS 0.007
CVE-2026-14499
Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
Published 2026-07-17 · Analyzed
8.8EPSS 0.007
CVE-2021-42956
Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclosure vulnerability. Due to improper privilege management, the process launches as the logged in user, so memory dump can be done by non-admin also. Remotely, an attacker can dump all sensitive information including DB Connection string, entire IT infrastructure details, commands executed by IT admin including credentials, secrets, private keys and more.
Published 2021-11-17 · Modified
8.8EPSS 0.007
CVE-2022-31739
When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
Published 2022-12-22 · Modified
8.8EPSS 0.007
CVE-2023-2313
Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a malicious file. (Chromium security severity: High)
Published 2023-07-28 · Modified
8.8EPSS 0.007
CVE-2023-36860
Improper input validation for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access.
Published 2023-11-14 · Modified
8.8EPSS 0.007
CVE-2025-36049
IBM webMethods Integration Sever XML external entity injection
Published 2025-06-18 · Analyzed
8.8EPSS 0.006
CVE-2021-26625
tobesoft Nexacro arbitrary file download vulnerability
Published 2022-04-19 · Modified
8.8EPSS 0.006
CVE-2020-7875
RAONWIZ DEXT5 Upload ActiveX remote file execution vulnerability
Published 2021-10-28 · Modified
8.8EPSS 0.006
← Prev87 / 259Next →