microsoft / windows
990 known vulnerabilities in microsoft windows.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-11631 | Medium | 0.2% | 8.3 | Use after free in Aura in Google Chrome on Windows prior to 149.0.7827.103 allow… | |
| CVE-2026-11636 | Medium | 0.2% | 7.5 | Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.103 a… | |
| CVE-2026-11663 | Medium | 0.2% | 8.3 | Use after free in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote… | |
| CVE-2026-27278 | Medium | 0.2% | 7.8 | Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are… | |
| CVE-2026-9925 | Medium | 0.2% | 8.3 | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remot… | |
| CVE-2026-9931 | Medium | 0.2% | 8.3 | Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote … | |
| CVE-2026-9932 | Medium | 0.2% | 8.3 | Use after free in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allo… | |
| CVE-2026-9933 | Medium | 0.2% | 7.5 | Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remot… | |
| CVE-2026-9937 | Medium | 0.2% | 8.3 | Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed… | |
| CVE-2026-9949 | Medium | 0.2% | 8.3 | Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allow… | |
| CVE-2026-9951 | Medium | 0.2% | 8.3 | Use after free in UI in Google Chrome prior to 148.0.7778.216 allowed a remote a… | |
| CVE-2026-10003 | Medium | 0.2% | 7.5 | Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remot… | |
| CVE-2026-10009 | Medium | 0.2% | 7.5 | Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remo… | |
| CVE-2026-11149 | Medium | 0.2% | 7.5 | Insufficient validation of untrusted input in Extensions in Google Chrome prior … | |
| CVE-2026-11151 | Medium | 0.2% | 7.5 | Insufficient validation of untrusted input in Password Manager in Google Chrome … | |
| CVE-2026-11239 | Medium | 0.2% | 7.5 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.… | |
| CVE-2026-27309 | Medium | 0.2% | 7.8 | Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free… | |
| CVE-2026-21321 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by an Integer Overflow or W… | |
| CVE-2026-21322 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by an out-of-bounds read vu… | |
| CVE-2026-21324 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by an out-of-bounds read vu… | |
| CVE-2026-21325 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by an out-of-bounds read vu… | |
| CVE-2026-21330 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by an Access of Resource Us… | |
| CVE-2026-11689 | Medium | 0.2% | 8.1 | Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.782… | |
| CVE-2026-48348 | Medium | 0.2% | 7.7 | Animate is affected by an Incorrect Authorization vulnerability that could resul… | |
| CVE-2026-9887 | Medium | 0.2% | 8.8 | Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remot… | |
| CVE-2026-11707 | Medium | 0.2% | 9.3 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Applicati… | |
| CVE-2026-11070 | Medium | 0.2% | 9.6 | Insufficient validation of untrusted input in Chromoting in Google Chrome on Win… | |
| CVE-2026-11079 | Medium | 0.2% | 8.8 | Insufficient validation of untrusted input in Codecs in Google Chrome prior to 1… | |
| CVE-2026-11198 | Medium | 0.2% | 9.6 | Insufficient validation of untrusted input in Codecs in Google Chrome prior to 1… | |
| CVE-2026-11207 | Medium | 0.2% | 9.6 | Insufficient validation of untrusted input in Autofill in Google Chrome prior to… | |
| CVE-2026-47304 | Medium | 0.2% | 8.1 | Improper verification of cryptographic signature in .NET allows an unauthorized … | |
| CVE-2026-8670 | Medium | 0.2% | 9.6 | Insufficient session expiration vulnerability in syslink software AG Avantra on … | |
| CVE-2026-8671 | Medium | 0.2% | 7.5 | Insertion of sensitive information into log file vulnerability in syslink softwa… | |
| CVE-2026-11667 | Medium | 0.2% | 7.5 | Out of bounds read in WebRTC in Google Chrome prior to 149.0.7827.103 allowed a … | |
| CVE-2026-5912 | Medium | 0.2% | 8.8 | Integer overflow in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a rem… | |
| CVE-2026-11694 | Medium | 0.2% | 7.5 | Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed… | |
| CVE-2026-9890 | Medium | 0.2% | 8.3 | Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed… | |
| CVE-2026-9905 | Medium | 0.2% | 8.3 | Use after free in Accessibility in Google Chrome on Windows prior to 148.0.7778.… | |
| CVE-2026-9954 | Medium | 0.2% | 7.5 | Use after free in TabStrip in Google Chrome prior to 148.0.7778.216 allowed a re… | |
| CVE-2026-9966 | Medium | 0.2% | 8.3 | Integer overflow in XML in Google Chrome on Windows prior to 148.0.7778.216 allo… | |
| CVE-2026-9970 | Medium | 0.2% | 8.3 | Use after free in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remot… | |
| CVE-2026-9975 | Medium | 0.2% | 8.3 | Out of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.216 a… | |
| CVE-2026-81975 | Medium | 0.2% | 7.8 | Acrobat Reader is affected by a Use After Free vulnerability that could result i… | |
| CVE-2026-11256 | Medium | 0.2% | 8.3 | Integer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote… | |
| CVE-2026-21287 | Medium | 0.2% | 7.8 | Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free… | |
| CVE-2026-5902 | Medium | 0.2% | 9.8 | Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remot… | |
| CVE-2026-11169 | Medium | 0.2% | 8.1 | Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-6406 | Medium | 0.2% | 8.8 | The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI)… | |
| CVE-2026-76199 | Medium | 0.2% | 8.6 | Photoshop Desktop is affected by an Uncontrolled Search Path Element vulnerabili… | |
| CVE-2026-11301 | Medium | 0.2% | 8.8 | Inappropriate implementation in LiveCaption in Google Chrome prior to 149.0.7827… |