VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10355CVEs
CVE-2024-6293
Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2024-06-24 · Analyzed
8.8EPSS 0.006
CVE-2024-5160
Heap buffer overflow in Dawn in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
Published 2024-05-22 · Analyzed
8.8EPSS 0.006
CVE-2022-4439
Use after free in Aura in Google Chrome on Windows prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. (Chromium security severity: High)
Published 2022-12-14 · Modified
8.8EPSS 0.006
CVE-2024-6292
Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2024-06-24 · Analyzed
8.8EPSS 0.006
CVE-2026-12443
Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-17 · Analyzed
8.8EPSS 0.006
CVE-2022-23766
BigFileAgent arbitrary file execution vulnerability
Published 2022-09-19 · Modified
8.8EPSS 0.006
CVE-2024-28777
IBM Cognos Controller code execution
Published 2025-02-19 · Analyzed
8.8EPSS 0.006
CVE-2026-1862
Type Confusion in V8 in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2026-02-03 · Analyzed
8.8EPSS 0.006
CVE-2025-4613
Client side RCE in Google Web Designer App
Published 2025-06-12 · Analyzed
8.8EPSS 0.006
CVE-2020-7874
NEXACRO14 Runtime arbitrary file download and execution vulnerability
Published 2021-09-09 · Modified
8.8EPSS 0.006
CVE-2023-0932
Use after free in WebRTC in Google Chrome on Windows prior to 110.0.5481.177 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2023-02-22 · Modified
8.8EPSS 0.006
CVE-2024-1545
Fault Injection of RSA encryption in WolfCrypt
Published 2024-08-29 · Modified
8.8EPSS 0.006
CVE-2025-10200
Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Published 2025-09-10 · Analyzed
8.8EPSS 0.006
CVE-2024-26362
HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via creation of crafted note.
Published 2024-04-10 · Analyzed
8.8EPSS 0.006
CVE-2026-9939
Heap buffer overflow in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-28 · Analyzed
8.8EPSS 0.006
CVE-2026-5858
Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-04-08 · Analyzed
8.8EPSS 0.006
CVE-2018-0701
BlueStacks App Player (BlueStacks App Player for Windows 3.0.0 to 4.31.55, BlueStacks App Player for macOS 2.0.0 and later) allows an attacker on the same network segment to bypass access restriction to gain unauthorized access.
Published 2018-11-15 · Modified
8.8EPSS 0.006
CVE-2026-7667
Path Traversal Vulnerability in API Request Component Content-Disposition Header Processing
Published 2026-07-17 · Analyzed
8.8EPSS 0.006
CVE-2026-79048
Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-08-25 · Analyzed
8.8EPSS 0.006
CVE-2023-40250
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Hancom HCell on Windows allows Overflow Buffers.This issue affects HCell: 12.0.0.893.
Published 2024-01-12 · Modified
8.8EPSS 0.006
CVE-2022-40231
IBM Sterling B2B Integrator Standard Edition improper access control
Published 2023-02-17 · Modified
8.8EPSS 0.006
CVE-2023-25922
IBM Security Guardium Key Lifecycle Manager file upload
Published 2024-02-28 · Analyzed
8.8EPSS 0.006
CVE-2026-4443
Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-03-20 · Analyzed
8.8EPSS 0.005
CVE-2016-7461
The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion and Fusion Pro 8.x before 8.5.2 allows guest OS users to execute arbitrary code on the host OS or cause a denial of service (out-of-bounds memory access on the host OS) via unspecified vectors.
Published 2016-12-29 · Modified
8.8EPSS 0.005
CVE-2026-9119
Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-20 · Analyzed
8.8EPSS 0.005
CVE-2026-8509
Heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-05-14 · Analyzed
8.8EPSS 0.005
CVE-2026-8056
Parameter Injection Vulnerability in API Graph Execution Engine
Published 2026-07-17 · Analyzed
8.8EPSS 0.005
CVE-2026-9952
Use after free in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-28 · Analyzed
8.8EPSS 0.005
CVE-2026-5860
Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-04-08 · Modified
8.8EPSS 0.005
CVE-2026-8524
Out of bounds write in WebAudio in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-14 · Analyzed
8.8EPSS 0.005
CVE-2026-8016
Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Published 2026-05-06 · Analyzed
8.8EPSS 0.005
CVE-2026-4678
Use after free in WebGPU in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-03-24 · Analyzed
8.8EPSS 0.005
CVE-2026-7951
Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-05-06 · Analyzed
8.8EPSS 0.005
CVE-2026-8526
Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-14 · Analyzed
8.8EPSS 0.005
CVE-2026-7988
Type Confusion in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-05-06 · Analyzed
8.8EPSS 0.005
CVE-2026-75624
IBM App Connect Enterprise is vulnerable to privilege escalation and Denial of Service
Published 2026-09-10 · Analyzed
8.8EPSS 0.005
CVE-2026-19298
Langflow is vulnerable to remote code execution due to authorization policy bypass in the authenticated flow-build endpoint
Published 2026-09-04 · Analyzed
8.8EPSS 0.005
CVE-2023-22663
Improper authentication for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access.
Published 2023-11-14 · Modified
8.8EPSS 0.005
CVE-2024-9965
Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
Published 2024-10-15 · Modified
8.8EPSS 0.005
CVE-2021-42993
FlexiHub For Windows is affected by Integer Overflow. IOCTL Handler 0x22001B in the FlexiHub For Windows above 2.0.4340 below 5.3.14268 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.
Published 2021-12-07 · Modified
8.8EPSS 0.005
← Prev88 / 259Next →