NO CVE Microsoft Windows EVILent ![]()
EVILent Coerced Authentication
vendor won't fix it
CVE-2025-50154 Microsoft Windows
![]()
File Explorer Spoofing
CVE-2025-48799 Microsoft Windows
![]()
Windows Update Service Elevation of Privilege
CVE-2025-21420 Microsoft Windows
![]()
Windows Disk Cleanup Tool Elevation of Privilege
NO CVE Microsoft Windows WSPCoerce
![]()
WSPCoerce Coerced Authentication via Windows Search Protocol
CVE-2025-26651 Microsoft Windows
![]()
Local Session Manager (LSM) Denial of Service
CVE-2025-24054 Microsoft Windows
![]()
NTLM Hash Disclosure Spoofing
CVE UNKNOWN Microsoft Windows
![]()
URL File NTLM Hash Disclosure
CVE-2023-29324 Microsoft Windows
![]()
Windows MSHTML Platform Security Feature Bypass
CVE-2024-49019 Microsoft Windows
![]()
Active Directory Certificate Services Elevation of Privilege
CVE-2024-38217 Microsoft Windows
![]()
LNK Stomping Windows Mark of the Web Security Feature
CVE-2024-38077 Microsoft Windows MadLicense
![]()
MadLicense Windows Remote Desktop Licensing Service RCE
CVE-2024-30103 Microsoft Outlook
![]()
Microsoft Outlook Remote Code Execution
CVE-2024-38100 Microsoft Windows
![]()
FakePotato Local Privilege Escalation
CVE-2024-30051 Microsoft Windows
![]()
DWM Core Library Elevation of Privilege
CVE-2024-30080 Microsoft Windows
![]()
Message Queuing (MSMQ) Remote Code Execution
CVE-2024-29050 Microsoft Windows
![]()
Cryptographic Services Remote Code Execution
CVE-2024-26230 Microsoft Windows
![]()
Telephony Server Elevation of Privilege
CVE-2024-21378 Microsoft Outlook
![]()
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2023-36047 Microsoft Windows
![]()
Windows Authentication Elevation of Privilege Vulnerability
CVE-2023-35628 Microsoft Windows
![]()
MSHTML Platform Remote Code Execution Vulnerability
CVE-2022-38034, CVE-2022-38045 Microsoft Windows
![]()
Windows Workstation and Server Service Elevation of Privilege Vulnerability
CVE-2024-21320 Microsoft Windows
![]()
Leaking NTLM Credentials Through Windows Themes
CVE-2024-21413 Microsoft Outlook
![]()
Microsoft Outlook "MonikerLink" Remote Code Execution Vulnerability
CVE-2023-35636 Microsoft Outlook
![]()
Microsoft Outlook Information Disclosure Vulnerability
CVE-2023-36003 Microsoft Windows
![]()
Microsoft Windows XAML diagnostics API Elevation of Privilege
CVE-2023-36874 Microsoft Windows
![]()
Windows Error Reporting Service Elevation of Privilege
CVE-2023-36884 Microsoft Windows and Microsoft Office
![]()
Windows Search Remote Code Execution
CVE-2023-36884 mitigation Microsoft Windows and Microsoft Office
![]()
Office and Windows HTML Remote Code Execution
CVE-2023-28231 Microsoft Windows
![]()
DHCP Server Service Remote Code Execution
CVE-2023-21554 Microsoft Windows QueueJumper
![]()
Message Queuing Remote Code Execution
CVE-2023-23397, CVE-2023-29324, CVE-2023-35384, CVE-2024-20652 Microsoft Office
![]()
Notification File NTLM Hash Theft
CVE-2022-41033 Microsoft Windows
![]()
COM+ Event System Service Elevation of Privilege
CVE-2022-44666 Microsoft Windows malcontact ![]()
Contacts Arbitrary Code Execution
CVE-2022-37973 Microsoft Windows
![]()
Local Session Manager (LSM) Denial of Service Vulnerability
CVE-2022-37998 Microsoft Windows
![]()
Local Session Manager (LSM) Denial of Service
CVE-2022-41128 Internet Explorer
![]()
Type confusion in Internet Explorer's JScript9 engine
CVE-2022-35841 Microsoft Windows
![]()
Enterprise App Management Service Remote Code Execution
CVE-2022-44698, CVE-2023-24880 Microsoft Windows
![]()
Bypassing MotW Security Warning with Invalid Signature
CVE-2022-33647, CVE-2022-33679, CVE-2023-28244 Microsoft Windows
![]()
Elevation of Privilege in Kerberos
CVE-2022-34721 Microsoft Windows
![]()
RCE in Internet Key Exchange (IKE) Protocol Extensions
CVE-2022-35742 Microsoft Outlook
![]()
Microsoft Outlook Content-Type Denial of Service
No CVE Microsoft Windows
![]()
Print Spooler SplEnumForms Elevation of Privilege
CVE-2022-30166 Microsoft Windows
![]()
Local Security Authority Subsystem Service LPE
revoked
No CVE Microsoft Windows KrbRelay
![]()
KrbRelay Local Privilege Escalation
No CVE Microsoft Windows DFSCoerce
![]()
Distributed File System "DFSCoerce" Privilege Escalation
Vendor decided not to fix it
No CVE Microsoft Windows PrinterBug/SpoolSample
![]()
Print Spooler "PrinterBug/SpoolSample" Privilege Escalation
Vendor decided not to fix it
CVE-2022-34713 Microsoft Windows DogWalk
![]()
Microsoft Diagnostic Tools "DogWalk" Package File Traversal
Vendor decided not to fix it
CVE-2022-30190 Microsoft Windows Follina
![]()
ms-msdt URL Protocol "Follina" PowerShell RCE
Follina
CVE-2022-26809, CVE-2022-22019 Microsoft Windows
![]()
Remote Procedure Call Runtime Integer Overflow
CVE-2022-21974 Microsoft Windows
![]()
Windows Runtime Remote Code Execution Vulnerability
CVE-2022-21971 Microsoft Windows
![]()
Windows Runtime Remote Code Execution Vulnerability
CVE-2022-21999 Microsoft Windows SpoolFool
![]()
Windows Print Spooler Elevation of Privilege
SpoolFool
CVE-2021-42278 Microsoft Windows
![]()
Active Directory Domain Services Elevation of Privilege
CVE-2021-43883 Microsoft Windows
![]()
Windows InstallerFileTakeOver Local Privilege Escalation
CVE-2021-24084 Microsoft Windows
![]()
Mobile Device Management Local Privilege Escalation
CVE-2021-34484 Microsoft Windows
![]()
Windows User Profile Service Elevation of Privilege
CVE-2021-36942 Microsoft Windows PetitPotam
![]()
PetitPotam NTLM Relay Attack
PetitPotam
CVE-2021-36958 Microsoft Windows
![]()
Malicious printer driver local privilege escalation
CVE-2020-0787 Microsoft Windows
![]()
Background Intelligent Transfer Service Elevation of Privilege
CVE-2021-34527 Microsoft Windows PrintNightmare
![]()
Print Spooler Remote Code Execution
PrintNightmare
CVE-2021-26897 Microsoft Windows Server
![]()
Windows DNS Server SIG Record Buffer Overflow
CVE-2021-26877 Microsoft Windows Server
![]()
Windows DNS Server TXT Record Out-Of-Bounds Read
CVE-2021-1727 Microsoft Windows
![]()
Windows Installer config.msi Local Privilege Escalation
CVE-2020-17001 Microsoft Windows
![]()
Print Spooler Elevation of Privilege
CVE-2021-27091 Microsoft Windows
![]()
Windows RpcEptMapper and Dnscache Service Insecure Registry Permissions EoP
CVE-2021-1640 Microsoft Windows
![]()
Print Spooler Arbitrary File Creation
CVE-2020-0968 Microsoft Windows
![]()
Scripting Engine Memory Corruption
CVE-2020-1472 Microsoft Windows Zerologon
![]()
Netlogon Elevation of Privilege
Zerologon
CVE-2020-1530 Microsoft Windows
![]()
Remote Access Phonebook Use-After-Free
CVE-2020-1337 Microsoft Windows
![]()
Elevation of Privilege in Print Spooler
CVE-2020-1350 Microsoft Windows SIGRed
![]()
DNS Server Remote Code Execution
SIGRed
CVE-2017-8570 Microsoft Office
![]()
Microsoft Office Remote Code Execution Vulnerability
CVE-2020-1048 Microsoft Windows PrintDemon
![]()
Print Spooler Elevation of Privilege
PrintDemon
CVE-2020-0938, CVE-2020-1020 Microsoft Windows ![]()
Microsoft Type 1 Font Parsing Remote Code Execution
workaround
CVE-2020-0668 Microsoft Windows
![]()
Windows Service Tracing Elevation of Privilege
CVE-2012-0158 Microsoft Office
![]()
MSCOMCTL ActiveX Buffer Overflow
CVE-2017-11774 Microsoft Outlook
![]()
Arbitrary Code Execution Via Home Page
a fix for an old but still exploited vulnerability used by Iranian-sponsored groups
CVE-2020-0674 Internet Explorer ![]()
Scripting Engine Memory Corruption
workaround
Unkonwn CVE Dropbox ![]()
Updater Arbitrary File Overwrite
CVE-2019-1429 Internet Explorer
![]()
Microsoft Scripting Engine Memory Corruption
CVE-2019-5047 NitroPDF
![]()
CharProcs Remote Code Execution
CVE-2019-5048 NitroPDF
![]()
ICCBased Color Space Remote Code Execution
CVE-2019-5053 NitroPDF
![]()
Stream Length Memory Corruption
CVE-2019-1069 Microsoft Windows BearLPE
![]()
Local Privilege Escalation in Task Scheduler
BearLPE
CVE-2019-0708 Microsoft Windows BlueKeep
![]()
Remote Code Execution in Remote Desktop Services
BlueKeep
CVE-2017-0176 Microsoft Windows XP/Server 2003 EsteemAudit
![]()
Microsoft Windows XP SP3/Server 2003 SP2 RDP privilege escalation
EsteemAudit
Unknown CVE Oracle Java
![]()
Oracle Java RE out-of-bounds read during TTF font rendering in ExtractBitMap_blocClass
CVE-2019-1054 Microsoft Internet Explorer ![]()
Missing Error Check on Reading Mark-Of-The-Web
Microsoft Edge uses a secret trick and breaks Internet Explorer's security
Unknown CVE Oracle Java
![]()
Oracle Java RE out-of-bounds read in AlternateSubstitutionSubtable::process
Unknown CVE Oracle Java
![]()
Oracle Java RE out-of-bounds read in OpenTypeLayoutEngine::adjustGlyphPositions
CVE-2018-16858 LibreOffice ![]()
LibreOffice Python Script Handler Directory Traversal
No CVE Microsoft Windows ![]()
Microsoft Windows Contacts Arbitrary Code Execution
CVE-2019-0636 Microsoft Windows readfile ![]()
MsiAdvertiseProduct Unauthorized File Read
readfile
CVE-2019-0863 Microsoft Windows AngryPolarBearBug
![]()
Error Reporting Local Privilege Escalation
AngryPolarBearBug
CVE-2018-0952 Microsoft Windows ![]()
Microsoft Diagnostic Hub Standard Collector Elevation Of Privilege
CVE-2018-8584 Microsoft Windows deletebug ![]()
Microsoft Data Sharing Service Arbitrary File Delete
deletebug
CVE-2018-8423 Microsoft Windows ![]()
Out-Of-Bounds Write in Microsoft Jet Database Engine
Outrunning Attackers On The Jet Database Engine 0day
CVE-2017-16720 Advantech WebAccess ![]()
Advantech WebAccess webvrpcs "Draw" Remote Code Execution
No CVE Advantech WebAccess ![]()
Advantech WebAccess webvrpcs "View" Remote Code Execution
CVE-2018-8440 Microsoft Windows ![]()
Microsoft Windows Task Scheduler ALPC Local Privilege Escalation
Publicly Dropped 0day in Task Scheduler
CVE-2018-8414 Microsoft Windows ![]()
Microsoft Windows "SettingContent-ms" Remote Code Execution
Initially rejected for patching by Microsoft
CVE-2018-12815 Adobe Acrobat Reader DC ![]()
Adobe Acrobat Reader DC JSON Stringify Remote Code Execution
CVE-2018-12756 Adobe Acrobat Reader DC ![]()
Adobe Acrobat Reader Use-After-Free memory corruption
CVE-2018-8174 Microsoft Windows ![]()
Microsoft Windows VBScript Engine Remote Code Execution
A micropatch instead of the official update that probably broke your network
CVE-2017-7269 Microsoft Windows Immortal ![]()
Buffer overflow in WebDAV service ScStoragePathFromUrl
Heavily exploited in the wild for 9 months
CVE-2018-0802 Microsoft Windows Office ![]()
Microsoft Office Equation Editor Memory Corruption
The Bug That Killed Equation Editor
CVE-2018-0798 Microsoft Windows Office ![]()
Microsoft Equation Editor Memory Corruption
Bringing back abandoned MS Equation Editor
CVE-2017-11882 Microsoft Windows ![]()
MS Office Equation Editor Memory Corruption
CVE-2017-11826 Microsoft Windows ![]()
Microsoft Word OOXML Parser Memory Corruption
No CVE Microsoft Windows ![]()
Microsoft Office DDE/DDEAUTO Remote Code Execution
It's a feature, not a bug
CVE-2017-4924 VMware Workstation ![]()
VMware Workstation Shader Out-Of-Bounds Write
Micropatching a hypervisor with running virtual machines
CVE-2017-11281 Adobe Flash Player ![]()
Adobe Flash Player Remote Memory Corruption
CVE-2017-0022 Microsoft Windows ![]()
Microsoft XML Core Services Information Disclosure
Exploit kit rendezvous
CVE-2017-8464 Microsoft Windows ![]()
Microsoft LNK Remote Code Execution
The New Stuxnet Windows LNK Vulnerability
CVE-2017-2779 National Instruments LabVIEW ![]()
LabVIEW RSRC Arbitrary Null Write Code Execution
CVE-2017-10952 Foxit Reader ![]()
Foxit Reader saveAs Arbitrary File Write
A logical bug patched
CVE-2013-2472 Oracle Java ![]()
Oracle Java ShortComponentRaster.verify() Memory Corruption
CVE-2017-0290 Microsoft Windows ![]()
Microsoft Malware Protection Engine Type Confusion
Worst windows remote code execution
CVE-2013-2473 Oracle Java ![]()
Oracle Java Blit function heap buffer overflow
CVE-2013-2471 Oracle Java ![]()
Oracle Java IntegerInterleavedRaster.verify() Signed Integer Overflow
CVE-2013-2470 Oracle Java ![]()
Oracle Java lookupByteBI function heap buffer overflow
CVE-2017-0037 Microsoft Windows ![]()
Internet Explorer 11 Type confusion in HandleColumnBreakOnColumnSpanningElement
CVE-2017-0038 Microsoft Windows ![]()
Microsoft Windows gdi32.dll EMF file information disclosure
No CVE 0patch Agent ![]()
Module loading logical error in 0patch Loader (functional flaw)
Patch to self, functional flaw
CVE-2016-3740 Foxit Reader ![]()
Foxit Reader ConvertToPDF TIFF SamplesPerPixel Parsing Heap Buffer Overflow
CVE-2015-6130 Microsoft Windows ![]()
Integer Underflow in Unicode Script Processor
CVE-2014-6321 Microsoft Windows ![]()
Windows schannel remote code execution (MS14-066)
First micropatch released on Twitter
CVE-2013-7409 AllPlayer ![]()
AllPlayer 5.8 Buffer Overflow In .M3u File
CVE-2013-6877 RealPlayer ![]()
RealPlayer 16.0.2.32 Buffer Overflow In .rmp File
CVE-2011-1260 Microsoft Windows ![]()
Internet Explorer 8 MS11-050 MSHTML use-after-free
CVE-2011-2371 Mozilla Firefox ![]()
Firefox 3.6.16 ReduceRight() Integer Overflow
No CVE Foxit Reader ![]()
Foxit Reader 4.1.1 Stack Buffer Overflow
CVE-2008-2992 Adobe Acrobat Reader ![]()
Adobe util.printf() Buffer Overflow
CVE-2009-0927 Adobe Acrobat Reader ![]()
Adobe Collab.getIcon() Buffer Overflow
CVE-2013-2463 Oracle Java ![]()
Oracle Java BytePackedRaster.verify() Signed Integer Overflow
CVE-2013-2465 Oracle Java ![]()
Oracle Java storeImageArray function heap buffer overflow
CVE-2014-0160 OpenSSL ![]()
OpenSSL Heartbeat (Heartbleed) Information Leak
Our first public micropatch