microsoft / windows_11_25h2
1,081 known vulnerabilities in microsoft windows_11_25h2.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-61918 | Low | 0.9% | 6.5 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to d… | |
| CVE-2026-62782 | Low | 0.9% | 6.5 | Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disc… | |
| CVE-2026-50415 | Low | 0.9% | 5.3 | Exposure of sensitive information to an unauthorized actor in Windows Media allo… | |
| CVE-2026-69569 | Low | 0.9% | 5.7 | Untrusted pointer dereference in Windows Print Spooler Components allows an auth… | |
| CVE-2026-68874 | Low | 0.8% | 5.7 | Out-of-bounds read in Windows Program Compatibility Assistant Service allows an … | |
| CVE-2026-69349 | Low | 0.8% | 5.7 | Use of uninitialized resource in Windows Management Instrumentation allows an au… | |
| CVE-2026-69507 | Low | 0.8% | 5.7 | Insertion of sensitive information into externally-accessible file or directory … | |
| CVE-2026-61921 | Low | 0.8% | 6.5 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to d… | |
| CVE-2026-61924 | Low | 0.8% | 6.5 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to d… | |
| CVE-2026-42907 | Low | 0.8% | 6.5 | Exposure of sensitive information to an unauthorized actor in Windows Shell allo… | |
| CVE-2026-42914 | Low | 0.8% | 5.3 | Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny ser… | |
| CVE-2026-20834 | Low | 0.8% | 4.6 | Absolute path traversal in Windows Shell allows an unauthorized attacker to perf… | |
| CVE-2026-73019 | Low | 0.7% | 4.3 | Improper resolution of path equivalence in Windows URL Moniker allows an unautho… | |
| CVE-2026-20821 | Low | 0.7% | 6.2 | Exposure of sensitive information to an unauthorized actor in Windows Remote Pro… | |
| CVE-2026-56649 | Low | 0.7% | 5.9 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20932 | Low | 0.7% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows File Explo… | |
| CVE-2026-20823 | Low | 0.7% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows File Explo… | |
| CVE-2026-20827 | Low | 0.7% | 5.5 | Exposure of sensitive information to an unauthorized actor in Tablet Windows Use… | |
| CVE-2026-20838 | Low | 0.7% | 5.5 | Generation of error message containing sensitive information in Windows Kernel a… | |
| CVE-2026-50485 | Low | 0.7% | 4.5 | Buffer over-read in Windows Hyper-V allows an authorized attacker to deny servic… | |
| CVE-2026-20828 | Low | 0.7% | 4.6 | Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauth… | |
| CVE-2026-65794 | Low | 0.7% | 6.5 | Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclo… | |
| CVE-2026-20862 | Low | 0.6% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Management… | |
| CVE-2026-78446 | Low | 0.6% | 5.3 | Use after free in Windows Distributed File System (DFS) allows an authorized att… | |
| CVE-2026-68898 | Low | 0.6% | 6.5 | Out-of-bounds read in Windows iSCSI allows an unauthorized attacker to deny serv… | |
| CVE-2026-20851 | Low | 0.6% | 6.2 | Out-of-bounds read in Capability Access Management Service (camsvc) allows an un… | |
| CVE-2026-62750 | Low | 0.6% | 6.5 | Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized … | |
| CVE-2026-20829 | Low | 0.6% | 5.5 | Out-of-bounds read in Windows TPM allows an authorized attacker to disclose info… | |
| CVE-2026-20835 | Low | 0.6% | 5.5 | Out-of-bounds read in Capability Access Management Service (camsvc) allows an au… | |
| CVE-2026-20819 | Low | 0.6% | 5.5 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enc… | |
| CVE-2026-50659 | Low | 0.6% | 6.5 | Improper encoding or escaping of output in .NET allows an authorized attacker to… | |
| CVE-2026-57083 | Low | 0.5% | 5.5 | Use of uninitialized resource in Microsoft Windows Codecs Library allows an unau… | |
| CVE-2026-57084 | Low | 0.5% | 5.5 | Use of uninitialized resource in Windows File Explorer allows an unauthorized at… | |
| CVE-2026-20825 | Low | 0.5% | 4.4 | Improper access control in Windows Hyper-V allows an authorized attacker to disc… | |
| CVE-2026-62801 | Low | 0.5% | 6.5 | Improper limitation of a pathname to a restricted directory ('path traversal') i… | |
| CVE-2026-58528 | Low | 0.5% | 6.8 | Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an un… | |
| CVE-2026-32223 | Low | 0.5% | 6.8 | Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized at… | |
| CVE-2026-20876 | Low | 0.5% | 6.7 | Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclav… | |
| CVE-2026-20939 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows File Explo… | |
| CVE-2026-50453 | Low | 0.5% | 6.1 | Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an un… | |
| CVE-2026-20937 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows File Explo… | |
| CVE-2026-49807 | Low | 0.5% | 6.2 | Exposure of sensitive information to an unauthorized actor in Windows DirectX al… | |
| CVE-2026-50294 | Low | 0.5% | 6.2 | Exposure of sensitive system information to an unauthorized control sphere in Wi… | |
| CVE-2026-69781 | Low | 0.5% | 6.5 | Missing release of memory after effective lifetime in Windows DHCP Client allows… | |
| CVE-2026-57097 | Low | 0.5% | 6.4 | Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass… | |
| CVE-2026-78455 | Low | 0.5% | 4.3 | Out-of-bounds read in Xbox allows an unauthorized attacker to disclose informati… | |
| CVE-2026-78516 | Low | 0.5% | 4.3 | Buffer over-read in Windows Storage allows an unauthorized attacker to disclose … | |
| CVE-2026-69406 | Low | 0.5% | 5.5 | Exposure of sensitive system information to an unauthorized control sphere in Wi… | |
| CVE-2026-57095 | Low | 0.5% | 6.2 | Exposure of sensitive information to an unauthorized actor in Windows Win32K all… | |
| CVE-2026-20839 | Low | 0.5% | 5.5 | Improper access control in Windows Client-Side Caching (CSC) Service allows an a… |