microsoft / windows
990 known vulnerabilities in microsoft windows.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2017-12615 | Act now | 99.6% | 8.1 | ● | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.… |
| CVE-2025-8088 | Act now | 94.1% | 8.8 | ● | A path traversal vulnerability affecting the Windows version of WinRAR allows th… |
| CVE-2018-15982 | Act now | 89.1% | 7.8 | ● | Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a … |
| CVE-2021-20021 | Act now | 83.4% | 9.8 | ● | A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attac… |
| CVE-2021-20023 | Act now | 51.4% | 4.9 | ● | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a… |
| CVE-2016-1019 | Act now | 22.3% | 9.8 | ● | Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a den… |
| CVE-2021-20022 | Act now | 16.5% | 7.2 | ● | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a… |
| CVE-2015-2291 | Act now | 9.0% | 7.8 | ● | (1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Eth… |
| CVE-2026-34621 | Act now | 7.1% | 8.6 | ● | Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by a… |
| CVE-2026-5281 | Act now | 4.9% | 8.8 | ● | Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote… |
| CVE-2026-11645 | Act now | 2.2% | 8.8 | ● | Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allo… |
| CVE-2026-28373 | High | 0.4% | 9.6 | The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path t… | |
| CVE-2026-87528 | High | 0.3% | 9.6 | Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 all… | |
| CVE-2021-36958 | Medium | 30.6% | 7.8 | A remote code execution vulnerability exists when the Windows Print Spooler serv… | |
| CVE-2021-21009 | Medium | 3.2% | 8.6 | Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.… | |
| CVE-2026-45591 | Medium | 2.5% | 7.5 | Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacke… | |
| CVE-2026-33116 | Medium | 2.1% | 7.5 | Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, … | |
| CVE-2026-76195 | Medium | 1.6% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia… | |
| CVE-2026-76197 | Medium | 1.6% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia… | |
| CVE-2026-48286 | Medium | 1.2% | 10.0 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected … | |
| CVE-2026-57108 | Medium | 1.1% | 7.5 | Access of resource using incompatible type ('type confusion') in .NET Core allow… | |
| CVE-2026-62901 | Medium | 1.1% | 7.5 | Unchecked input for loop condition in .NET allows an unauthorized attacker to de… | |
| CVE-2026-47302 | Medium | 1.0% | 7.5 | Allocation of resources without limits or throttling in .NET allows an unauthori… | |
| CVE-2026-56170 | Medium | 1.0% | 7.5 | Allocation of resources without limits or throttling in ASP.NET Core allows an u… | |
| CVE-2026-8476 | Medium | 1.0% | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution v… | |
| CVE-2026-50646 | Medium | 1.0% | 7.8 | Protection mechanism failure in .NET Framework allows an unauthorized attacker t… | |
| CVE-2026-48449 | Medium | 1.0% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi… | |
| CVE-2026-50649 | Medium | 0.9% | 7.8 | Deserialization of untrusted data in .NET allows an unauthorized attacker to exe… | |
| CVE-2026-48351 | Medium | 0.9% | 7.5 | CAI Content Credentials is affected by an Improper Input Validation vulnerabilit… | |
| CVE-2026-48352 | Medium | 0.9% | 7.5 | CAI Content Credentials is affected by an Improper Input Validation vulnerabilit… | |
| CVE-2026-48345 | Medium | 0.9% | 8.2 | Animate is affected by an Improper Neutralization of Special Elements used in an… | |
| CVE-2026-9135 | Medium | 0.8% | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 9498… | |
| CVE-2026-50527 | Medium | 0.8% | 7.5 | Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to… | |
| CVE-2026-50648 | Medium | 0.8% | 7.5 | Allocation of resources without limits or throttling in .NET Framework allows an… | |
| CVE-2026-50651 | Medium | 0.8% | 7.5 | Allocation of resources without limits or throttling in .NET allows an unauthori… | |
| CVE-2026-21267 | Medium | 0.8% | 8.6 | Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutra… | |
| CVE-2026-48295 | Medium | 0.8% | 7.5 | CAI Content Credentials is affected by an Insufficiently Protected Credentials v… | |
| CVE-2026-8481 | Medium | 0.8% | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution v… | |
| CVE-2026-7755 | Medium | 0.7% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution… | |
| CVE-2026-47303 | Medium | 0.7% | 8.8 | Authentication bypass by assumed-immutable data in ASP.NET Core allows an author… | |
| CVE-2026-9103 | Medium | 0.7% | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unau… | |
| CVE-2026-48347 | Medium | 0.7% | 7.7 | Animate is affected by an Improper Neutralization of Special Elements used in an… | |
| CVE-2026-48323 | Medium | 0.7% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia… | |
| CVE-2026-48330 | Medium | 0.7% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia… | |
| CVE-2026-76193 | Medium | 0.7% | 10.0 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF)… | |
| CVE-2026-13448 | Medium | 0.7% | 8.1 | IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated re… | |
| CVE-2026-14499 | Medium | 0.7% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user… | |
| CVE-2026-50524 | Medium | 0.6% | 7.5 | Improper validation of specified type of input in .NET Framework allows an unaut… | |
| CVE-2026-34615 | Medium | 0.6% | 9.3 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserializati… | |
| CVE-2026-27303 | Medium | 0.6% | 9.6 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserializati… |
Page 1 of 20
Next →