VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10355CVEs
CVE-2026-2321
Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-02-11 · Modified
8.8EPSS 0.003
CVE-2026-10016
Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-28 · Analyzed
8.8EPSS 0.003
CVE-2026-11664
Use after free in Payments in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-08 · Analyzed
8.8EPSS 0.003
CVE-2026-11630
Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-08 · Analyzed
8.8EPSS 0.003
CVE-2026-10007
Use after free in SVG in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-28 · Analyzed
8.8EPSS 0.003
CVE-2026-4458
Use after free in Extensions in Google Chrome prior to 146.0.7680.153 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
Published 2026-03-20 · Analyzed
8.8EPSS 0.003
CVE-2021-28820
TIBCO FTL Windows Platform Artifact Search vulnerability
Published 2021-03-23 · Modified
8.8EPSS 0.003
CVE-2021-28818
TIBCO Rendezvous Windows Platform Artifact Search vulnerability
Published 2021-03-23 · Modified
8.8EPSS 0.003
CVE-2021-28817
TIBCO Rendezvous Windows Platform Installation vulnerability
Published 2021-03-23 · Modified
8.8EPSS 0.003
CVE-2021-3626
Windows version of Multipass unauthenticated localhost tcp control socket can perform mounts
Published 2021-10-01 · Modified
8.8EPSS 0.002
CVE-2025-13227
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2025-11-17 · Analyzed
8.8EPSS 0.002
CVE-2021-28822
TIBCO Enterprise Message Service Windows Platform Artifact Search vulnerability
Published 2021-03-23 · Modified
8.8EPSS 0.002
CVE-2025-13228
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2025-11-17 · Analyzed
8.8EPSS 0.002
CVE-2025-13229
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2025-11-17 · Analyzed
8.8EPSS 0.002
CVE-2025-13226
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2025-11-17 · Analyzed
8.8EPSS 0.002
CVE-2025-13230
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2025-11-17 · Analyzed
8.8EPSS 0.002
CVE-2026-11091
Inappropriate implementation in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2023-49647
Zoom Desktop Client for Windows - Improper Access Control
Published 2024-01-12 · Modified
8.8EPSS 0.002
CVE-2026-11680
Use after free in Media in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-08 · Analyzed
8.8EPSS 0.002
CVE-2026-11674
Use after free in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-08 · Analyzed
8.8EPSS 0.002
CVE-2026-11673
Use after free in InterestGroups in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-08 · Analyzed
8.8EPSS 0.002
CVE-2026-11230
Use after free in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-11235
Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-11248
Inappropriate implementation in Google Lens in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-81996
Acrobat Reader | Incorrect Authorization (CWE-863)
Published 2026-09-08 · Analyzed
8.8EPSS 0.002
CVE-2026-11303
Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-10021
Insufficient validation of untrusted input in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-05-28 · Analyzed
8.8EPSS 0.002
CVE-2026-11041
Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-11124
Integer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-11177
Use after free in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2021-28819
TIBCO FTL Windows Platform Installation vulnerability
Published 2021-03-23 · Modified
8.8EPSS 0.002
CVE-2025-12432
Race in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2025-11-10 · Analyzed
8.8EPSS 0.002
CVE-2021-28826
TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge Windows Platform Installation vulnerability
Published 2021-04-14 · Modified
8.8EPSS 0.002
CVE-2021-28825
TIBCO Messaging - Eclipse Mosquitto Distribution - Core Windows Platform Installation vulnerability
Published 2021-04-14 · Modified
8.8EPSS 0.002
CVE-2026-11307
Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-11305
Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-11179
Inappropriate implementation in ORB in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2021-42743
Local privilege escalation via a default path in Splunk Enterprise Windows
Published 2022-05-06 · Modified
8.8EPSS 0.002
CVE-2023-42773
Improper neutralization in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
Published 2024-05-16 · Analyzed
8.8EPSS 0.002
CVE-2023-38581
Buffer overflow in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
Published 2024-05-16 · Analyzed
8.8EPSS 0.002
← Prev98 / 259Next →