microsoft / windows_11_25h2
1,081 known vulnerabilities in microsoft windows_11_25h2.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-61349 | Medium | 0.2% | 7.8 | Use after free in Windows Work Folder Service allows an authorized attacker to e… | |
| CVE-2026-81354 | Medium | 0.2% | 8.2 | Heap-based buffer overflow in Windows Hello allows an authorized attacker to ele… | |
| CVE-2026-69501 | Medium | 0.2% | 7.0 | Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized… | |
| CVE-2026-49805 | Medium | 0.2% | 7.0 | Improper access control in Windows Win32K allows an authorized attacker to eleva… | |
| CVE-2026-50297 | Medium | 0.2% | 7.0 | Improper access control in Windows Win32K allows an authorized attacker to eleva… | |
| CVE-2026-50325 | Medium | 0.2% | 7.0 | Improper access control in Windows Win32K allows an authorized attacker to eleva… | |
| CVE-2026-68847 | Medium | 0.2% | 7.0 | Use after free in Windows Connected User Experiences and Telemetry allows an aut… | |
| CVE-2026-69864 | Medium | 0.2% | 7.8 | Use after free in Windows Hello allows an authorized attacker to elevate privile… | |
| CVE-2026-21221 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-34335 | Medium | 0.2% | 7.0 | Use after free in Windows Ancillary Function Driver for WinSock allows an author… | |
| CVE-2026-42911 | Medium | 0.2% | 7.0 | Use after free in Windows Ancillary Function Driver for WinSock allows an author… | |
| CVE-2026-45640 | Medium | 0.2% | 7.0 | Use after free in Windows Bluetooth Port Driver allows an authorized attacker to… | |
| CVE-2026-56179 | Medium | 0.2% | 8.3 | Origin validation error in Windows Network Address Translation (NAT) allows an u… | |
| CVE-2026-85360 | Medium | 0.2% | 7.0 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-80083 | Medium | 0.2% | 8.8 | Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker t… | |
| CVE-2026-55144 | Medium | 0.2% | 7.1 | Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to… | |
| CVE-2026-65776 | Medium | 0.2% | 7.0 | Use after free in Windows Win32K allows an authorized attacker to elevate privil… | |
| CVE-2026-33101 | Medium | 0.2% | 7.8 | Use after free in Windows Print Spooler Components allows an authorized attacker… | |
| CVE-2026-83996 | Medium | 0.2% | 8.8 | Heap-based buffer overflow in Windows Error Reporting allows an authorized attac… | |
| CVE-2026-70283 | Medium | 0.2% | 7.0 | Incorrect authorization in Windows Win32K allows an authorized attacker to eleva… | |
| CVE-2026-47648 | Medium | 0.2% | 7.0 | Untrusted search path in Windows Storage allows an authorized attacker to elevat… | |
| CVE-2026-47304 | Medium | 0.2% | 8.1 | Improper verification of cryptographic signature in .NET allows an unauthorized … | |
| CVE-2026-42976 | Medium | 0.2% | 7.8 | Missing authentication for critical function in Windows RPC API allows an author… | |
| CVE-2026-50317 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50321 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50378 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50440 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50667 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50676 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-58526 | Medium | 0.2% | 7.0 | Use after free in Windows Storage allows an authorized attacker to elevate privi… | |
| CVE-2026-58527 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-62777 | Medium | 0.2% | 7.8 | Missing authentication for critical function in Windows License Manager allows a… | |
| CVE-2026-65678 | Medium | 0.2% | 7.0 | Use after free in Windows Win32K allows an authorized attacker to elevate privil… | |
| CVE-2026-65778 | Medium | 0.2% | 7.0 | Use after free in Windows Autopilot allows an authorized attacker to elevate pri… | |
| CVE-2026-65779 | Medium | 0.2% | 7.0 | Use after free in Windows Autopilot allows an authorized attacker to elevate pri… | |
| CVE-2026-83942 | Medium | 0.2% | 7.8 | Missing authorization in Windows Kernel allows an authorized attacker to elevate… | |
| CVE-2026-83999 | Medium | 0.2% | 7.0 | Improper link resolution before file access ('link following') in Windows Resili… | |
| CVE-2026-33104 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-62753 | Medium | 0.2% | 7.0 | Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to … | |
| CVE-2026-42912 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-44800 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-49183 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-49784 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-49802 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-49803 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-49806 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-49808 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50322 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50345 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50356 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … |