972 exploited vulnerabilities in Windows
- Vendors
- Microsoft, Motorola, Alt Linux, Apple, Red Os, Suse
- With known exploits
- 972
- Affected Microsoft Windows 11 23h2 versions
- All versions
- Affected Microsoft Windows 11 24h2 versions
- < 10.0.26100.8390, 10.0.26100.6508, 10.0.26100.2894, 10.0.26100.2605, 10.0.26100.1457
- Affected Microsoft Windows 11 25h2 versions
- < 10.0.26200.8390
- Affected Microsoft Windows 11 26h1 versions
- < 10.0.28000.2113
- Affected Microsoft Windows Server 2022 23h2 versions
- < 10.0.25398.2330, 10.0.25398.1916, 10.0.25398.1849, 10.0.25398.1369, 10.0.25398.1308, 10.0.25398.1085, 10.0.25398.1009, 10.0.25398.830
- Affected Microsoft Windows Server 2025 versions
- < 10.0.26100.32772, 10.0.26100.6905, 10.0.26100.6508, 10.0.26100.2894, 10.0.26100.2605
- Affected Microsoft Windows Server 2012 versions
- All versions
- Affected Microsoft Windows Server 2016 versions
- All versions
Vulnerabilities with exploits
Highest CVSS first β 41 of these already have exploit code on Sploitus
CVE-2026-41096 4 exploits
Exploit for Heap-based Buffer Overflow in MicrosoftExploit for Heap-based Buffer Overflow in Microsoft
CVE-2026-41089 34 exploits
Exploit for Stack-based Buffer Overflow in MicrosoftExploit for Stack-based Buffer Overflow in Microsoft
CVE-2025-59287 23 exploits
Exploit for Deserialization of Untrusted Data in MicrosoftExploit for Deserialization of Untrusted Data in Microsoft
CVE-2025-55234 1 exploit
CVE-2025-54106 1 exploit
CVE-2025-47981
CVE-2024-55414
CVE-2025-21298 6 exploits
CVE-2024-49112 3 exploits
Exploit for Integer Overflow or Wraparound in MicrosoftExploit for Integer Overflow or Wraparound in Microsoft
CVE-2024-38063 24 exploits
Exploit for Integer Underflow (Wrap or Wraparound) in MicrosoftExploit for Integer Underflow (Wrap or Wraparound) in Microsoft
CVE-2024-38077 5 exploits
Exploit for Heap-based Buffer Overflow in MicrosoftExploit for Heap-based Buffer Overflow in Microsoft
CVE-2024-29988 1 exploit
CVE-2023-36025 2 exploits
CVE-2023-38039
CVE-2023-38146 5 exploits
Exploit for Time-of-check Time-of-use (TOCTOU) Race Condition in MicrosoftThemebleed Windows 11 Themes Arbitrary Code Execution Exploit
CVE-2023-21554 7 exploits
Exploit for Improper Input Validation in MicrosoftExploit for Improper Input Validation in Microsoft
CVE-2023-23415
CVE-2022-24760
CVE-2022-35737 1 exploit
CVE-2022-34718 2 exploits
CVE-2022-34715
CVE-2022-30136 2 exploits
CVE-2022-30190 62 exploits
CVE-2022-26937 3 exploits
CVE-2022-24491 1 exploit
CVE-2022-24497 1 exploit
CVE-2022-26809 14 exploits
CVE-2022-24500 2 exploits
CVE-2022-21907 21 exploits
CVE-2021-31166 24 exploits
CVE-2020-11552 3 exploits
ManageEngine ADSelfService Build prior to 6003 - Remote Code Execution (Unauthenticated)ManageEngine ADSelfService Build prior to 6003 - Remote Code Execution (Unauthenticated)
CVE-2019-17015
CVE-2020-16898 12 exploits
CVE-2020-1472 75 exploits
CVE-2020-1350 21 exploits
Exploit for Improper Input Validation in MicrosoftExploit for Improper Input Validation in Microsoft
CVE-2020-0796 127 exploits
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in MicrosoftExploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Microsoft
CVE-2020-0610 10 exploits
CVE-2020-0609 11 exploits
Exploit for CVE-2020-0609Exploit for Insufficiently Protected Credentials in Zyxel Usg20-Vpn_Firmware
CVE-2019-1152 1 exploit
CVE-2019-1150 2 exploits
Microsoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in WriteTableFromStructureMicrosoft Font Subsetting - DLL Heap Corruption in ReadTableIntoStructure
CVE-2019-1145 1 exploit
CVE-2019-1144 2 exploits
Exploit for Unrestricted Upload of File with Dangerous Type in Cutephp CutenewsMicrosoft Font Subsetting - DLL Double Free in MergeFormat12Cmap / MakeFormat12MergedGlyphList
CVE-2019-1170 2 exploits
Windows 10 - SET_REPARSE_POINT_EX Mount Point Security Feature Bypass ExploitMicrosoft Windows 10 - SET_REPARSE_POINT_EX Mount Point Security Feature Bypass
CVE-2019-0881 2 exploits
Microsoft Windows 10 1809 - CmKeyBodyRemapToVirtualForEnum Arbitrary Key EnumerationMicrosoft Windows 10 1809 - 'CmKeyBodyRemapToVirtualForEnum' Arbitrary Key Enumeration Privilege Escalation
CVE-2019-0708 128 exploits
CVE-2017-8543
CVE-2016-7182 1 exploit
CVE-2016-3236 2 exploits
NetBIOS Response BadTunnel Brute Force Spoof (NAT Tunnel)NetBIOS Response "BadTunnel" Brute Force Spoof (NAT Tunnel)
CVE-2015-1635 17 exploits
Exploit for Code Injection in MicrosoftMS15-034 HTTP Protocol Stack Request Handling HTTP.SYS Memory Information Disclosure
CVE-2014-6321