microsoft / windows
990 known vulnerabilities in microsoft windows.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-5858 | Medium | 0.6% | 8.8 | Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a … | |
| CVE-2026-33414 | Medium | 0.6% | 7.8 | Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.… | |
| CVE-2026-50525 | Medium | 0.6% | 7.5 | Allocation of resources without limits or throttling in .NET allows an unauthori… | |
| CVE-2026-48448 | Medium | 0.6% | 8.6 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia… | |
| CVE-2026-63093 | Medium | 0.6% | 8.8 | Cursor for Windows version 3.2.16 contains a binary planting vulnerability that … | |
| CVE-2026-71328 | Medium | 0.6% | 8.8 | Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to e… | |
| CVE-2026-8505 | Medium | 0.6% | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook … | |
| CVE-2026-56623 | Medium | 0.6% | 7.1 | Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SS… | |
| CVE-2026-8992 | Medium | 0.6% | 8.8 | An improper certificate validation vulnerability in Ivanti Secure Access Client … | |
| CVE-2026-50528 | Medium | 0.6% | 8.2 | Incorrect authorization in .NET allows an unauthorized attacker to bypass a secu… | |
| CVE-2026-7667 | Medium | 0.6% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create… | |
| CVE-2026-8859 | Medium | 0.6% | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write … | |
| CVE-2026-48303 | Medium | 0.6% | 10.0 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected … | |
| CVE-2026-3087 | Medium | 0.6% | 7.5 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows pat… | |
| CVE-2026-48397 | Medium | 0.5% | 8.6 | Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerabili… | |
| CVE-2026-78989 | Medium | 0.5% | 9.6 | Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.6… | |
| CVE-2026-79048 | Medium | 0.5% | 8.8 | Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.… | |
| CVE-2026-9119 | Medium | 0.5% | 8.8 | Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allow… | |
| CVE-2026-8056 | Medium | 0.5% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override com… | |
| CVE-2026-8635 | Medium | 0.5% | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate pri… | |
| CVE-2026-47300 | Medium | 0.5% | 8.8 | Incorrect implementation of authentication algorithm in ASP.NET Core allows an a… | |
| CVE-2026-34690 | Medium | 0.5% | 7.8 | After Effects is affected by a Stack-based Buffer Overflow vulnerability that co… | |
| CVE-2026-79194 | Medium | 0.5% | 8.1 | Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.… | |
| CVE-2026-5865 | Medium | 0.5% | 8.8 | Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote at… | |
| CVE-2026-9120 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remo… | |
| CVE-2026-48326 | Medium | 0.5% | 9.9 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia… | |
| CVE-2026-87512 | Medium | 0.5% | 9.6 | Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 al… | |
| CVE-2026-10903 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-10943 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-10947 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-10948 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-19298 | Medium | 0.5% | 8.8 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacke… | |
| CVE-2026-17692 | Medium | 0.5% | 9.6 | Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.7… | |
| CVE-2026-48317 | Medium | 0.5% | 9.6 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Direct… | |
| CVE-2026-48333 | Medium | 0.5% | 9.8 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi… | |
| CVE-2026-5860 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remot… | |
| CVE-2026-17691 | Medium | 0.5% | 9.6 | Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 … | |
| CVE-2026-48331 | Medium | 0.5% | 10.0 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF)… | |
| CVE-2026-35561 | Medium | 0.5% | 7.4 | Insufficient authentication security controls in the browser-based authenticatio… | |
| CVE-2026-13473 | Medium | 0.5% | 8.1 | IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 throu… | |
| CVE-2026-10882 | Medium | 0.5% | 8.8 | Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remo… | |
| CVE-2026-79019 | Medium | 0.5% | 9.6 | Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.… | |
| CVE-2026-48399 | Medium | 0.5% | 7.5 | Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Princip… | |
| CVE-2026-7347 | Medium | 0.5% | 8.1 | Use after free in Chromoting in Google Chrome prior to 147.0.7727.138 allowed a … | |
| CVE-2026-10939 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-10975 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-10982 | Medium | 0.5% | 8.8 | Use after free in WebXR in Google Chrome prior to 149.0.7827.53 allowed a remote… | |
| CVE-2026-11003 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-8855 | Medium | 0.5% | 8.1 | IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial o… | |
| CVE-2026-47938 | Medium | 0.4% | 10.0 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected … |