11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2016-0151
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
32.4%
2016 1 PoC

The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka "Windows CSRSS Security Feature Bypass Vulnerability."

CVE-2025-21420
Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
41.5%
2025 CWE-59 2 PoCs

Windows Disk Cleanup Tool Elevation of Privilege Vulnerability

CVE-2024-56179
Software Genérico Windows
7.8
HIGH
EPSS
0.1%
2024 1 PoC

In MindManager Windows versions prior to 24.1.150, attackers could potentially write to unexpected directories in victims' machines via directory traversal if victims opened file attachments located in malicious mmap files.

CVE-2016-7255
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
89.4%
2016 10 PoCs

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

CVE-2021-31165
Windows 10 Version 2004 DevOps Windows
7.8
HIGH
EPSS
0.3%
2021 1 PoC

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2023-35358
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.2%
2023 CWE-125 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-43630
Windows Server 2022 Windows
7.8
HIGH
EPSS
3.6%
2024 CWE-121 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2015-5123
🔥 KEV Software Genérico Cloud Windows
7.8
HIGH
EPSS
41.0%
2015 2 PoCs

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

CVE-2023-3514
Razer Central Windows
7.8
HIGH
EPSS
0.1%
2023 CWE-269 1 PoC

Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access to gain SYSTEM privilege via communicating with the named pipe as a low-privilege user and calling "AddModule" or "UninstallModules" command to execute arbitrary executable file.

CVE-2021-31954
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
1.3%
2021 1 PoC

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2024-0121
GPU, vGPU, and Cloud Gaming Cloud Windows
7.8
HIGH
EPSS
0.1%
2024 CWE-125 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2024-26230
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
46.7%
2024 CWE-416 2 PoCs

Windows Telephony Server Elevation of Privilege Vulnerability

CVE-2020-17136
Windows 10 Version 20H2 Cloud Windows
7.8
HIGH
EPSS
85.6%
2020 2 PoCs

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2023-36407
Windows Server 2022 Windows
7.8
HIGH
EPSS
15.2%
2023 CWE-20 2 PoCs

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2016-0165
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
6.2%
2016 1 PoC

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0143 and CVE-2016-0167.

CVE-2025-55314
Software Genérico Web Windows
7.8
HIGH
EPSS
0.0%
2025 1 PoC

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations assume these states are valid, causing dereference of invalid or released memory. This can lead to memory corruption, application crashes, and potentially allow an attacker to execute arbitrary code.

CVE-2023-41772
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
19.5%
2023 CWE-284 1 PoC

Win32k Elevation of Privilege Vulnerability

CVE-2025-59512
Windows 10 Version 1607 Windows
7.8
HIGH
EPSS
0.3%
2025 CWE-284 2 PoCs

Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally.

CVE-2023-7016
SafeNet Authentication Client Windows
7.8
HIGH
EPSS
0.1%
2023 CWE-269 1 PoC

A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local access.