11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-28184
NVIDIA GPU Display Driver Windows
7.1
HIGH
EPSS
0.1%
2022 CWE-284 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an unprivileged regular user can access administrator- privileged registers, which may lead to denial of service, information disclosure, and data tampering.

CVE-2022-4294
Norton Antivirus Windows Eraser Engine Windows
7.1
HIGH
EPSS
0.1%
2022 CWE-269 1 PoC

Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

CVE-2024-13878
SpotBot Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The SpotBot WordPress plugin through 0.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2020-7332
Endpoint Security for Windows Networking Windows
7.0
HIGH
EPSS
0.2%
2020 CWE-352 1 PoC

Cross Site Request Forgery vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows an attacker to execute arbitrary HTML code due to incorrect security configuration.

CVE-2020-1473
Windows 10 Version 1803 Windows
7.0
HIGH
EPSS
6.0%
2020 1 PoC

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory.

CVE-2010-5181
Software Genérico Windows
7.0
HIGH
EPSS
0.0%
2010 3 PoCs

Race condition in VIPRE Antivirus Premium 4.0.3272 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute

CVE-2022-42267
NVIDIA GPU Display Driver for Windows Windows
7.0
HIGH
EPSS
0.1%
2022 CWE-345 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability where a regular user can cause an out-of-bounds read, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

CVE-2025-59282
Windows 10 Version 1507 Windows
7.0
HIGH
EPSS
0.4%
2025 CWE-362 2 PoCs

Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.

CVE-2025-34501
Deck Mate 2 Web Networking Windows
7.0
HIGH
EPSS
0.0%
2025 CWE-798 1 PoC

Deck Mate 2 is distributed with static, hard-coded credentials for the root shell and web user interface, while multiple management services (SSH, HTTP, Telnet, SMB, X11) are enabled by default. If an attacker can reach these interfaces - most often through local or near-local access such as connecting to the USB or Ethernet ports beneath the table - the built-in credentials permit administrative login and full control of the system. Once authenticated, an attacker can access firmware utilities, modify controller software, and establish persistent compromise. Remote attack paths via network, c

CVE-2010-5159
Software Genérico Windows
7.0
HIGH
EPSS
0.1%
2010 3 PoCs

Race condition in Dr.Web Security Space Pro 6.0.0.03100 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute

CVE-2022-21881
Windows 10 Version 1809 Windows
7.0
HIGH
EPSS
6.7%
2022 2 PoCs

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-21253
Windows 10 Version 1607 Windows
7.0
HIGH
EPSS
0.1%
2026 CWE-416 2 PoCs

Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.

CVE-2018-8120
🔥 KEV Windows Server 2008 Windows
7.0
HIGH
EPSS
94.1%
2018 14 PoCs

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166.

CVE-2024-12310
Enterprise Access Management Windows
7.0
HIGH
EPSS
0.0%
2024 CWE-287 1 PoC

A vulnerability in Imprivata Enterprise Access Management (formerly Imprivata OneSign) allows bypassing the login screen of the shared kiosk workstation and allows unauthorized access to the underlying Windows system through the already logged-in autologon account due to insufficient handling of keyboard shortcuts. This issue affects Imprivata Enterprise Access Management versions 5.3 through 24.2.

CVE-2023-28229
🔥 KEV Windows 10 Version 1809 Windows
7.0
HIGH
EPSS
8.6%
2023 CWE-591 1 PoC

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

CVE-2010-5169
Software Genérico Windows
7.0
HIGH
EPSS
0.1%
2010 3 PoCs

Race condition in Online Armor Premium 4.0.0.35 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute

CVE-2019-16784
PyInstaller Windows
7.0
HIGH
EPSS
3.2%
2019 CWE-250 1 PoC

In PyInstaller before version 3.6, only on Windows, a local privilege escalation vulnerability is present in this particular case: If a software using PyInstaller in "onefile" mode is launched by a privileged user (at least more than the current one) which have his "TempPath" resolving to a world writable directory. This is the case for example if the software is launched as a service or as a scheduled task using a system account (TempPath will be C:\Windows\Temp). In order to be exploitable the software has to be (re)started after the attacker launch the exploit program, so for a service laun

CVE-2024-39708
Software Genérico Windows
7.0
HIGH
EPSS
0.0%
2024 1 PoC

An issue was discovered in the Agent in Delinea Privilege Manager (formerly Thycotic Privilege Manager) before 12.0.1096 on Windows. Sometimes, a non-administrator user can copy a crafted DLL file to a temporary directory (used by .NET Shadow Copies) such that privilege escalation can occur if the core agent service loads that file.