Windows

Vendor:

First CVE: Aug 1, 1997 · Active for 28 years

10,117
Total CVEs
More Total CVEs than 100% of tracked products
389.1
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.9%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Windows over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 1, 1997
28 years ago
Most Recent CVE
Jul 17, 2026
7 days ago

CVE Severity & Scoring

Windows10,117 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local3,942 (39.0%)
Network4,688 (46.3%)
Unknown1,388 (13.7%)
Physical34 (0.3%)
Adjacent Network65 (0.6%)
Attack Complexity
Low8,224 (81.3%)
High505 (5.0%)
Unknown1,388 (13.7%)
User Interaction
None3,243 (32.1%)
Unknown1,388 (13.7%)
Required5,486 (54.2%)
Privileges Required
Low1,558 (15.4%)
High187 (1.8%)
None6,984 (69.0%)
Unknown1,388 (13.7%)

Top CVEs

Signals from CVEs in this product scope (10117 CVEs).

10,117 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows m
Jun 9, 20249.899YESYES
The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vu
Apr 22, 202510.098YESYES
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a special
Feb 17, 20239.898YESYES
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upl
Sep 19, 20178.198YESYES
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 1
Jul 14, 20159.898YESYES
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows
Jul 8, 20159.898YESYES
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attack
Jun 23, 20159.898YESYES
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote atta
Feb 2, 20159.898YESYES
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote atta
Feb 5, 20149.898YESYES
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote att
Dec 7, 20119.898YESYES

Exploit Exposure

Signals from CVEs in this product scope (10117 CVEs).

CISA KEV
93 CVEs
0.9% of CVEs· 96th percentile
Metasploit
76 CVEs
0.8% of CVEs· 96th percentile
Nuclei
21 CVEs
0.2% of CVEs· 96th percentile
ExploitDB
392 CVEs
3.9% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (10117 CVEs).

Media Mentions

Signals from CVEs in this product scope (10117 CVEs).

Top CNAs Publishing CVEs For Windows

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
xp19.359.1%01
server_200328.248.8%02
2003_server29.342.0%01