VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10355CVEs
CVE-2023-38581
Buffer overflow in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
Published 2024-05-16 · Analyzed
8.8EPSS 0.002
CVE-2026-11306
Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2024-45181
An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70. An improper bounds check allows crafted packets to cause an arbitrary address write, resulting in kernel memory corruption.
Published 2024-09-12 · Analyzed
8.8EPSS 0.002
CVE-2021-28821
TIBCO Enterprise Message Service Windows Platform Installation vulnerability
Published 2021-03-23 · Modified
8.8EPSS 0.002
CVE-2026-11079
Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory write via a crafted video file. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2023-0213
Local Elevation of Privilege in M-Files
Published 2023-03-29 · Modified
8.8EPSS 0.002
CVE-2024-49779
IBM OpenPages cross-site request forgery
Published 2025-02-20 · Analyzed
8.8EPSS 0.002
CVE-2026-11301
Inappropriate implementation in LiveCaption in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via malicious network traffic. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-11201
Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-3063
Inappropriate implementation in DevTools in Google Chrome prior to 145.0.7632.116 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via DevTools. (Chromium security severity: High)
Published 2026-02-23 · Modified
8.8EPSS 0.002
CVE-2026-6406
Docker Desktop Enhanced Container Isolation bypass via --use-api-socket CLI flag
Published 2026-05-22 · Analyzed
8.8EPSS 0.002
CVE-2023-28737
Improper initialization in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable escalation of privilege via local access.
Published 2023-11-14 · Modified
8.8EPSS 0.002
CVE-2023-45217
Improper access control in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
Published 2024-05-16 · Analyzed
8.8EPSS 0.002
CVE-2026-10019
Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-05-28 · Modified
8.8EPSS 0.002
CVE-2025-13941
Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability
Published 2025-12-19 · Analyzed
8.8EPSS 0.002
CVE-2026-10926
Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to execute arbitrary code via malicious network traffic. (Chromium security severity: High)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-11304
Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-12035
Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-11 · Analyzed
8.8EPSS 0.002
CVE-2025-36633
Local Privilege Escalation
Published 2025-06-13 · Analyzed
8.8EPSS 0.002
CVE-2026-10002
Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
Published 2026-05-28 · Modified
8.8EPSS 0.002
CVE-2026-11092
Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-0233
Autonomous Digital Experience Manager: Improper validation of ADEM certificate
Published 2026-04-13 · Analyzed
8.8EPSS 0.002
CVE-2024-4018
Privilege Escalation in U-Series Appliance
Published 2024-04-19 · Analyzed
8.8EPSS 0.002
CVE-2024-4017
Privilege Escalation in U-Series Appliance
Published 2024-04-19 · Analyzed
8.8EPSS 0.002
CVE-2026-76259
Improper Privilege Management on the Management Port in Splunk Enterprise for Windows
Published 2026-08-19 · Analyzed
8.8EPSS 0.002
CVE-2023-40596
Splunk Enterprise on Windows Privilege Escalation due to Insecure OPENSSLDIR Build Definition Reference in DLL
Published 2023-08-30 · Modified
8.8EPSS 0.002
CVE-2026-12018
Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
Published 2026-06-11 · Analyzed
8.8EPSS 0.002
CVE-2020-24681
Automation Studio and PVI Multiple incorrect permission assignments for services
Published 2024-02-02 · Modified
8.8EPSS 0.002
CVE-2025-1095
IBM Personal Communications command execution
Published 2025-04-08 · Modified
8.8EPSS 0.001
CVE-2026-25265
Creation of Temporary File with Insecure Permissions in Qualcomm Software Center
Published 2026-09-22 · Analyzed
8.8EPSS 0.001
CVE-2026-25264
Uncontrolled Search Path Element in Qualcomm Software Center
Published 2026-09-22 · Analyzed
8.8EPSS 0.001
CVE-2021-29678
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access other databases and read or modify files. IBM X-Force ID: 199914.
Published 2021-12-09 · Modified
8.7EPSS 0.011
CVE-2026-34617
Adobe Connect | Cross-site Scripting (XSS) (CWE-79)
Published 2026-04-14 · Analyzed
8.7EPSS 0.007
CVE-2026-35562
Allocation of resources without limits in parsing components in Amazon Athena ODBC driver
Published 2026-04-03 · Analyzed
8.7EPSS 0.007
CVE-2021-42083
Authenticated Stored XSS in OSNEXUS QuantaStor 6.0.0.335
Published 2023-07-10 · Modified
8.7EPSS 0.005
CVE-2026-77103
CommServe Information Disclosure
Published 2026-09-08 · Analyzed
8.7EPSS 0.005
CVE-2026-77102
CommServe Denial of Service
Published 2026-09-08 · Analyzed
8.7EPSS 0.005
CVE-2026-77101
CommServe Stack-based Buffer Overflow
Published 2026-09-08 · Analyzed
8.7EPSS 0.005
CVE-2025-69273
Spectrum broken authentication
Published 2026-01-12 · Analyzed
8.7EPSS 0.004
CVE-2026-30791
RustDesk Client Accepts Pseudo-Encrypted Config Strings Without Cryptographic Validation
Published 2026-03-05 · Analyzed
8.7EPSS 0.003
← Prev99 / 259Next →