microsoft / windows
990 known vulnerabilities in microsoft windows.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-76259 | Medium | 0.1% | 8.8 | In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, … | |
| CVE-2026-0294 | Medium | 0.1% | 7.8 | A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Acce… | |
| CVE-2026-78915 | Medium | 0.1% | 7.5 | Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.… | |
| CVE-2026-11241 | Medium | 0.1% | 8.0 | Insufficient validation of untrusted input in Cast in Google Chrome prior to 149… | |
| CVE-2026-17862 | Medium | 0.1% | 7.8 | Use after free in Tracing in Google Chrome on Windows prior to 151.0.7922.72 all… | |
| CVE-2026-17863 | Medium | 0.1% | 7.8 | Inappropriate implementation in Browser in Google Chrome on Windows prior to 151… | |
| CVE-2026-8036 | Medium | 0.1% | 7.1 | Improper input validation in NI-PAL may allow a local authenticated user to acce… | |
| CVE-2026-87509 | Medium | 0.1% | 8.1 | Incorrect authorization in Updater in Google Chrome on on Windows prior to 153.0… | |
| CVE-2026-11269 | Medium | 0.1% | 7.1 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.… | |
| CVE-2026-2123 | Medium | 0.1% | 7.8 | A security audit identified a privilege escalation vulnerability in Operations A… | |
| CVE-2026-8035 | Medium | 0.1% | 7.1 | Improper input validation in the NI-PAL kernel driver may allow a local authenti… | |
| CVE-2026-87554 | Medium | 0.1% | 8.1 | Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.… | |
| CVE-2026-78892 | Medium | 0.1% | 7.1 | Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 15… | |
| CVE-2026-84334 | Medium | 0.1% | 8.1 | Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 15… | |
| CVE-2026-11103 | Medium | 0.1% | 7.8 | Inappropriate implementation in Installer in Google Chrome on Windows prior to 1… | |
| CVE-2026-11115 | Medium | 0.1% | 7.3 | Use after free in Updater in Google Chrome on Windows prior to 149.0.7827.53 all… | |
| CVE-2026-87457 | Medium | 0.1% | 8.1 | Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 … | |
| CVE-2026-87467 | Medium | 0.1% | 8.1 | Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 … | |
| CVE-2019-11049 | Low | 4.2% | 6.5 | In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom h… | |
| CVE-2020-9666 | Low | 2.4% | 5.5 | Adobe Campaign Classic before 20.2 have an out-of-bounds read vulnerability. Suc… | |
| CVE-2022-42343 | Low | 1.4% | 6.5 | Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected … | |
| CVE-2026-62902 | Low | 0.8% | 6.5 | Inclusion of functionality from untrusted control sphere in .NET allows an unaut… | |
| CVE-2026-62899 | Low | 0.7% | 5.9 | Inconsistent interpretation of http requests ('http request/response smuggling')… | |
| CVE-2026-50659 | Low | 0.6% | 6.5 | Improper encoding or escaping of output in .NET allows an authorized attacker to… | |
| CVE-2026-62900 | Low | 0.5% | 5.9 | Improper removal of sensitive information before storage or transfer in .NET all… | |
| CVE-2026-17707 | Low | 0.5% | 6.5 | Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72 al… | |
| CVE-2026-17622 | Low | 0.5% | 6.5 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacke… | |
| CVE-2026-19299 | Low | 0.5% | 6.5 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacke… | |
| CVE-2026-19302 | Low | 0.5% | 6.5 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacke… | |
| CVE-2026-3482 | Low | 0.5% | 5.3 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.… | |
| CVE-2026-79285 | Low | 0.4% | 6.5 | Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 152.0.79… | |
| CVE-2026-17706 | Low | 0.4% | 4.3 | Insufficient validation of untrusted input in Media in Google Chrome on Windows … | |
| CVE-2026-45491 | Low | 0.4% | 6.2 | Improper link resolution before file access ('link following') in .NET allows an… | |
| CVE-2026-17790 | Low | 0.4% | 4.3 | Uninitialized Use in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 al… | |
| CVE-2026-39844 | Low | 0.4% | 5.9 | NiceGUI is a Python-based UI framework. Prior to 3.10.0, Since PurePosixPath onl… | |
| CVE-2026-2812 | Low | 0.4% | 5.3 | ArcGIS Server contains an improper authentication vulnerability in an undocument… | |
| CVE-2026-34626 | Low | 0.3% | 6.3 | Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are… | |
| CVE-2026-9110 | Low | 0.3% | 4.2 | Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.77… | |
| CVE-2026-14470 | Low | 0.3% | 6.5 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to t… | |
| CVE-2026-11006 | Low | 0.3% | 6.5 | Out of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-11008 | Low | 0.3% | 6.5 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome pr… | |
| CVE-2026-11013 | Low | 0.3% | 6.5 | Insufficient validation of untrusted input in Network in Google Chrome prior to … | |
| CVE-2026-2813 | Low | 0.3% | 4.7 | ArcGIS Server contains an input validation weakness in the login redirection wor… | |
| CVE-2026-9138 | Low | 0.3% | 6.5 | IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated atta… | |
| CVE-2026-17621 | Low | 0.3% | 5.4 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse … | |
| CVE-2026-47924 | Low | 0.3% | 5.5 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a… | |
| CVE-2026-48354 | Low | 0.3% | 6.2 | CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnera… | |
| CVE-2026-19301 | Low | 0.3% | 5.0 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacke… | |
| CVE-2026-5867 | Low | 0.3% | 4.3 | Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a … | |
| CVE-2026-11027 | Low | 0.3% | 6.5 | Insufficient validation of untrusted input in Glic in Google Chrome prior to 149… |