microsoft / windows_11_25h2
1,081 known vulnerabilities in microsoft windows_11_25h2.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-69609 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose i… | |
| CVE-2026-69616 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Remote Desktop Services allows an authorized attac… | |
| CVE-2026-69627 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authori… | |
| CVE-2026-69808 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose i… | |
| CVE-2026-71341 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Partition Management Driver allows an authorized a… | |
| CVE-2026-72980 | Low | 0.4% | 4.4 | Uncontrolled search path element in Windows Hello allows an authorized attacker … | |
| CVE-2026-42915 | Low | 0.4% | 5.5 | Incorrect calculation of buffer size in Windows VMSwitch allows an authorized at… | |
| CVE-2026-45606 | Low | 0.4% | 5.5 | Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authoriz… | |
| CVE-2026-65785 | Low | 0.4% | 6.5 | Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized … | |
| CVE-2026-68831 | Low | 0.4% | 5.5 | Files or directories accessible to external parties in Windows Defender Firewall… | |
| CVE-2026-50475 | Low | 0.4% | 5.5 | Buffer over-read in Windows Kernel allows an authorized attacker to disclose inf… | |
| CVE-2026-61368 | Low | 0.4% | 5.0 | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to d… | |
| CVE-2026-57085 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Print Spooler Components allows an authorized atta… | |
| CVE-2026-59136 | Low | 0.4% | 5.5 | Use of uninitialized resource in Microsoft COM for Windows allows an authorized … | |
| CVE-2026-69832 | Low | 0.4% | 5.6 | Exposure of sensitive system information to an unauthorized control sphere in Wi… | |
| CVE-2026-45634 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows DHCP Server allows an authorized attacker to discl… | |
| CVE-2026-68842 | Low | 0.4% | 5.5 | Exposure of sensitive system information to an unauthorized control sphere in Wi… | |
| CVE-2026-49167 | Low | 0.4% | 4.7 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-50312 | Low | 0.4% | 4.7 | Use after free in Windows Ancillary Function Driver for WinSock allows an author… | |
| CVE-2026-58545 | Low | 0.4% | 5.5 | Improper access control in Windows Kernel allows an authorized attacker to bypas… | |
| CVE-2026-45604 | Low | 0.3% | 5.5 | Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an a… | |
| CVE-2026-83991 | Low | 0.3% | 5.5 | Missing authentication for critical function in Windows Cloud Files Mini Filter … | |
| CVE-2026-69294 | Low | 0.3% | 5.5 | Generation of error message containing sensitive information in Microsoft COM fo… | |
| CVE-2026-55000 | Low | 0.3% | 6.4 | Use after free in Windows USB Print Driver allows an unauthorized attacker to el… | |
| CVE-2026-45608 | Low | 0.3% | 6.8 | Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to dis… | |
| CVE-2026-59130 | Low | 0.3% | 5.6 | No cwe for this issue in AMD Zen allows an authorized attacker to disclose infor… | |
| CVE-2026-50302 | Low | 0.3% | 4.2 | Improper certificate validation in Windows Cryptographic Services allows an unau… | |
| CVE-2026-62769 | Low | 0.3% | 6.7 | Numeric truncation error in Windows DNS allows an authorized attacker to elevate… | |
| CVE-2026-62881 | Low | 0.3% | 6.7 | Numeric truncation error in Windows DNS allows an authorized attacker to elevate… | |
| CVE-2026-71339 | Low | 0.3% | 6.7 | Heap-based buffer overflow in Windows Installer allows an authorized attacker to… | |
| CVE-2026-59135 | Low | 0.3% | 5.5 | Weak authentication in Microsoft Windows Search Component allows an authorized a… | |
| CVE-2026-45642 | Low | 0.3% | 3.9 | Improper input validation in Microsoft Azure Attestation service and Device Heal… | |
| CVE-2026-62708 | Low | 0.3% | 6.4 | Use after free in Windows Kernel allows an unauthorized attacker to elevate priv… | |
| CVE-2026-70304 | Low | 0.3% | 6.7 | Heap-based buffer overflow in Windows DNS allows an authorized attacker to eleva… | |
| CVE-2026-70330 | Low | 0.3% | 6.7 | Heap-based buffer overflow in Windows DNS allows an authorized attacker to eleva… | |
| CVE-2026-62786 | Low | 0.3% | 5.5 | Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose i… | |
| CVE-2026-62793 | Low | 0.3% | 5.5 | Buffer over-read in Windows NTFS allows an authorized attacker to disclose infor… | |
| CVE-2026-62796 | Low | 0.3% | 5.5 | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose inf… | |
| CVE-2026-62798 | Low | 0.3% | 5.5 | Untrusted pointer dereference in Windows Win32K allows an authorized attacker to… | |
| CVE-2026-65662 | Low | 0.3% | 5.5 | Out-of-bounds read in Windows GDI allows an authorized attacker to disclose info… | |
| CVE-2026-50310 | Low | 0.3% | 4.7 | Integer overflow or wraparound in Windows Devices Human Interface allows an auth… | |
| CVE-2026-69554 | Low | 0.3% | 5.5 | Missing authentication for critical function in Microsoft Windows Search Compone… | |
| CVE-2026-68833 | Low | 0.3% | 6.8 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to ex… | |
| CVE-2026-71329 | Low | 0.3% | 6.8 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to ex… | |
| CVE-2026-72999 | Low | 0.3% | 6.8 | Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to … | |
| CVE-2026-77892 | Low | 0.3% | 6.8 | No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to… | |
| CVE-2026-83501 | Low | 0.3% | 5.5 | Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows… | |
| CVE-2026-50295 | Low | 0.3% | 5.5 | Improper privilege management in Microsoft Windows DNS allows an authorized atta… | |
| CVE-2026-50495 | Low | 0.3% | 6.1 | Improper access control in Microsoft Windows DNS allows an authorized attacker t… | |
| CVE-2026-65784 | Low | 0.3% | 5.5 | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose inf… |