microsoft / windows_11_25h2
1,081 known vulnerabilities in microsoft windows_11_25h2.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-80096 | Medium | 0.7% | 8.8 | Out-of-bounds read in Windows Remote Desktop Services allows an authorized attac… | |
| CVE-2026-62792 | Medium | 0.7% | 8.1 | Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to… | |
| CVE-2026-50686 | Medium | 0.7% | 8.1 | Access of resource using incompatible type ('type confusion') in Windows OLE all… | |
| CVE-2026-69332 | Medium | 0.7% | 8.0 | Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate priv… | |
| CVE-2026-69423 | Medium | 0.7% | 8.0 | Heap-based buffer overflow in Windows USB Video Driver allows an authorized atta… | |
| CVE-2026-69727 | Medium | 0.7% | 8.0 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-69773 | Medium | 0.7% | 8.0 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-69826 | Medium | 0.7% | 8.0 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-50369 | Medium | 0.7% | 8.8 | Use after free in Windows Remote Desktop Services allows an authorized attacker … | |
| CVE-2026-20837 | Medium | 0.7% | 7.8 | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to e… | |
| CVE-2026-62817 | Medium | 0.7% | 8.8 | Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute co… | |
| CVE-2026-57089 | Medium | 0.7% | 7.5 | Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allow… | |
| CVE-2026-62790 | Medium | 0.7% | 8.8 | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker t… | |
| CVE-2026-69514 | Medium | 0.7% | 7.5 | Heap-based buffer overflow in Windows Remote Desktop Services allows an authoriz… | |
| CVE-2026-69599 | Medium | 0.7% | 7.5 | Use after free in Windows Remote Desktop Services allows an authorized attacker … | |
| CVE-2026-50502 | Medium | 0.7% | 8.0 | Insufficient granularity of access control in Windows Event Logging Service allo… | |
| CVE-2026-42974 | Medium | 0.6% | 8.1 | Integer overflow or wraparound in Windows Performance Monitor allows an unauthor… | |
| CVE-2026-42981 | Medium | 0.6% | 8.1 | Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an … | |
| CVE-2026-69852 | Medium | 0.6% | 7.5 | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows… | |
| CVE-2026-62822 | Medium | 0.6% | 8.8 | Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker t… | |
| CVE-2026-84001 | Medium | 0.6% | 7.5 | Out-of-bounds read in Windows Key Distribution Center allows an unauthorized att… | |
| CVE-2026-61363 | Medium | 0.6% | 7.5 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac… | |
| CVE-2026-59134 | Medium | 0.6% | 7.5 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac… | |
| CVE-2026-73012 | Medium | 0.6% | 8.8 | Heap-based buffer overflow in Windows Management Services allows an authorized a… | |
| CVE-2026-56188 | Medium | 0.6% | 9.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-62795 | Medium | 0.6% | 8.8 | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an… | |
| CVE-2026-50525 | Medium | 0.6% | 7.5 | Allocation of resources without limits or throttling in .NET allows an unauthori… | |
| CVE-2026-47653 | Medium | 0.6% | 8.8 | Use after free in Remote Desktop Client allows an unauthorized attacker to execu… | |
| CVE-2026-54984 | Medium | 0.6% | 7.8 | Heap-based buffer overflow in Windows Imaging Component allows an unauthorized a… | |
| CVE-2026-83992 | Medium | 0.6% | 8.8 | Heap-based buffer overflow in Windows Imaging Component allows an unauthorized a… | |
| CVE-2026-68846 | Medium | 0.6% | 7.1 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-69366 | Medium | 0.6% | 7.1 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-62819 | Medium | 0.6% | 8.1 | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows… | |
| CVE-2026-73016 | Medium | 0.6% | 8.8 | Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorize… | |
| CVE-2026-50398 | Medium | 0.6% | 8.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50414 | Medium | 0.6% | 7.5 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-58608 | Medium | 0.6% | 8.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20864 | Medium | 0.6% | 7.8 | Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows… | |
| CVE-2026-62889 | Medium | 0.6% | 8.1 | Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unautho… | |
| CVE-2026-68834 | Medium | 0.6% | 8.0 | Stack-based buffer overflow in Windows NTFS allows an authorized attacker to ele… | |
| CVE-2026-73013 | Medium | 0.6% | 8.8 | Heap-based buffer overflow in Windows Imaging Component allows an unauthorized a… | |
| CVE-2026-73023 | Medium | 0.6% | 8.8 | Heap-based buffer overflow in Windows Imaging Component allows an unauthorized a… | |
| CVE-2026-77495 | Medium | 0.6% | 8.8 | Heap-based buffer overflow in Windows Imaging Component allows an unauthorized a… | |
| CVE-2026-48563 | Medium | 0.6% | 7.5 | Use after free in Remote Desktop Client allows an unauthorized attacker to execu… | |
| CVE-2026-62706 | Medium | 0.5% | 8.8 | Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized … | |
| CVE-2026-42900 | Medium | 0.5% | 8.1 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50365 | Medium | 0.5% | 8.0 | Improper authentication in Windows RPC API allows an unauthorized attacker to el… | |
| CVE-2026-50460 | Medium | 0.5% | 8.1 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-62872 | Medium | 0.5% | 8.8 | Incorrect authorization in .NET Framework allows an authorized attacker to eleva… | |
| CVE-2026-42975 | Medium | 0.5% | 8.0 | Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthoriz… |