exposed-win-zero-days
Curated list of publicly exposed Windows zero-day vulnerabilities
Made by Aryan Giri
- CVE-2025-9074 (Docker Desktop Escape) – Container Escape on Windows/macOS, Patched Aug 2025
- CVE-2025-29824 (CLFS Zero-Day) – Elevation of Privilege, Patched April 2025
- CVE-2025-30400 (DWM Core Library) – Elevation of Privilege, Patched May 2025
- CVE-2025-30397 (Microsoft Scripting Engine) – Remote Code Execution, Patched May 2025
- CVE-2025-53779 (Windows Kerberos) – Privilege Escalation, Patched August 2025
- CVE-2024-49039 (Windows Sandbox Escape) – Exploited in Malware Campaigns, 2024
- CVE-2024-9680 (Browser + Windows Exploit Chain) – Sandbox Escape, 2024
- CVE-2023-36033 (DWM Core Library) – Elevation of Privilege, 2023
- CVE-2024-30051 (DWM Core Library) – Elevation of Privilege, 2024
- CVE-2025-33053 (WebDAV) – Remote Code Execution, Patched June 2025
- EternalBlue (CVE-2017-0144) – SMB Exploit, 2017
- CVE-2024-21338 (Windows AppLocker Driver) – Kernel Access, Exploited 2024
- CVE-2024-49138 (CLFS Zero-Day) – Ransomware, Patched Dec 2024
- CVE-2024-24993 (Windows NTFS) – Buffer Overflow, Exploited 2025
- Stuxnet Zero-Days – Industrial Espionage, 2010