microsoft / windows_11_23h2
761 known vulnerabilities in microsoft windows_11_23h2.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-72994 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-72995 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-73000 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-73002 | Medium | 0.2% | 7.8 | Integer overflow or wraparound in Windows Biometric Service allows an authorized… | |
| CVE-2026-73007 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-73011 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-73015 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-73020 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-73024 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows … | |
| CVE-2026-73026 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-77904 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an … | |
| CVE-2026-78447 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-78448 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83955 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83969 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83974 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83976 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-61349 | Medium | 0.2% | 7.8 | Use after free in Windows Work Folder Service allows an authorized attacker to e… | |
| CVE-2026-81354 | Medium | 0.2% | 8.2 | Heap-based buffer overflow in Windows Hello allows an authorized attacker to ele… | |
| CVE-2026-69501 | Medium | 0.2% | 7.0 | Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized… | |
| CVE-2026-68847 | Medium | 0.2% | 7.0 | Use after free in Windows Connected User Experiences and Telemetry allows an aut… | |
| CVE-2026-69864 | Medium | 0.2% | 7.8 | Use after free in Windows Hello allows an authorized attacker to elevate privile… | |
| CVE-2026-34335 | Medium | 0.2% | 7.0 | Use after free in Windows Ancillary Function Driver for WinSock allows an author… | |
| CVE-2026-42911 | Medium | 0.2% | 7.0 | Use after free in Windows Ancillary Function Driver for WinSock allows an author… | |
| CVE-2026-45640 | Medium | 0.2% | 7.0 | Use after free in Windows Bluetooth Port Driver allows an authorized attacker to… | |
| CVE-2026-85360 | Medium | 0.2% | 7.0 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-80083 | Medium | 0.2% | 8.8 | Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker t… | |
| CVE-2026-83996 | Medium | 0.2% | 8.8 | Heap-based buffer overflow in Windows Error Reporting allows an authorized attac… | |
| CVE-2026-70283 | Medium | 0.2% | 7.0 | Incorrect authorization in Windows Win32K allows an authorized attacker to eleva… | |
| CVE-2026-47648 | Medium | 0.2% | 7.0 | Untrusted search path in Windows Storage allows an authorized attacker to elevat… | |
| CVE-2026-47304 | Medium | 0.2% | 8.1 | Improper verification of cryptographic signature in .NET allows an unauthorized … | |
| CVE-2026-62777 | Medium | 0.2% | 7.8 | Missing authentication for critical function in Windows License Manager allows a… | |
| CVE-2026-65678 | Medium | 0.2% | 7.0 | Use after free in Windows Win32K allows an authorized attacker to elevate privil… | |
| CVE-2026-83942 | Medium | 0.2% | 7.8 | Missing authorization in Windows Kernel allows an authorized attacker to elevate… | |
| CVE-2026-33104 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-62753 | Medium | 0.2% | 7.0 | Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to … | |
| CVE-2026-42912 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-44800 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-62780 | Medium | 0.2% | 7.0 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-69466 | Medium | 0.2% | 7.0 | Time-of-check time-of-use (toctou) race condition in Windows Kernel allows an au… | |
| CVE-2026-62725 | Medium | 0.2% | 7.0 | Use after free in Windows Telephony Service allows an authorized attacker to ele… | |
| CVE-2026-62773 | Medium | 0.2% | 7.0 | Use after free in Windows Kerberos allows an authorized attacker to elevate priv… | |
| CVE-2026-62774 | Medium | 0.2% | 7.0 | Use after free in Windows Graphics Kernel allows an authorized attacker to eleva… | |
| CVE-2026-62892 | Medium | 0.2% | 7.0 | Use after free in Capability Access Management Service (camsvc) allows an author… | |
| CVE-2026-68837 | Medium | 0.2% | 7.0 | Use after free in Windows File History Service allows an authorized attacker to … | |
| CVE-2026-69578 | Medium | 0.2% | 7.0 | Numeric truncation error in Windows Kernel allows an authorized attacker to elev… | |
| CVE-2026-73003 | Medium | 0.2% | 7.0 | Use after free in Windows Modern Device Management (MDM) allows an authorized at… | |
| CVE-2026-73022 | Medium | 0.2% | 7.0 | Use after free in Windows Modern Device Management (MDM) allows an authorized at… | |
| CVE-2026-77905 | Medium | 0.2% | 7.0 | Use after free in Windows Management Instrumentation allows an authorized attack… | |
| CVE-2026-42836 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … |