microsoft / windows_11_23h2
761 known vulnerabilities in microsoft windows_11_23h2.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-62713 | Medium | 2.0% | 7.8 | Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an a… | |
| CVE-2024-38259 | Medium | 1.9% | 8.8 | Microsoft Management Console Remote Code Execution Vulnerability | |
| CVE-2024-21372 | Medium | 1.8% | 8.8 | Windows OLE Remote Code Execution Vulnerability | |
| CVE-2024-21358 | Medium | 1.8% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerabilit… | |
| CVE-2024-21360 | Medium | 1.8% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerabilit… | |
| CVE-2024-21365 | Medium | 1.8% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerabilit… | |
| CVE-2024-21366 | Medium | 1.8% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerabilit… | |
| CVE-2024-21370 | Medium | 1.8% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerabilit… | |
| CVE-2024-38239 | Medium | 1.7% | 7.2 | Windows Kerberos Elevation of Privilege Vulnerability | |
| CVE-2024-21420 | Medium | 1.7% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerabilit… | |
| CVE-2026-50652 | Medium | 1.7% | 7.5 | Deserialization of untrusted data in Azure Active Directory allows an unauthoriz… | |
| CVE-2026-59132 | Medium | 1.7% | 7.5 | Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to de… | |
| CVE-2026-61929 | Medium | 1.7% | 7.0 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-65788 | Medium | 1.7% | 7.0 | Use after free in Desktop Window Manager allows an authorized attacker to elevat… | |
| CVE-2024-21375 | Medium | 1.7% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerabilit… | |
| CVE-2024-21349 | Medium | 1.6% | 8.8 | Microsoft ActiveX Data Objects Remote Code Execution Vulnerability | |
| CVE-2024-21359 | Medium | 1.6% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerabilit… | |
| CVE-2024-21361 | Medium | 1.6% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerabilit… | |
| CVE-2024-21367 | Medium | 1.6% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerabilit… | |
| CVE-2024-21368 | Medium | 1.6% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerabilit… | |
| CVE-2024-21352 | Medium | 1.6% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerabilit… | |
| CVE-2024-21391 | Medium | 1.6% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerabilit… | |
| CVE-2026-61348 | Medium | 1.6% | 7.0 | Use after free in Windows Ancillary Function Driver for WinSock allows an author… | |
| CVE-2026-20875 | Medium | 1.6% | 7.5 | Null pointer dereference in Windows Local Security Authority Subsystem Service (… | |
| CVE-2024-21369 | Medium | 1.5% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerabilit… | |
| CVE-2024-38240 | Medium | 1.5% | 8.1 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | |
| CVE-2024-21350 | Medium | 1.5% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerabilit… | |
| CVE-2024-38045 | Medium | 1.4% | 8.1 | Windows TCP/IP Remote Code Execution Vulnerability | |
| CVE-2026-20868 | Medium | 1.4% | 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) a… | |
| CVE-2026-20846 | Medium | 1.4% | 7.5 | Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service… | |
| CVE-2024-21416 | Medium | 1.4% | 8.1 | Windows TCP/IP Remote Code Execution Vulnerability | |
| CVE-2024-21347 | Medium | 1.4% | 7.5 | Microsoft ODBC Driver Remote Code Execution Vulnerability | |
| CVE-2026-42985 | Medium | 1.3% | 8.8 | Use after free in Remote Desktop Client allows an unauthorized attacker to execu… | |
| CVE-2026-33096 | Medium | 1.2% | 7.5 | Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny s… | |
| CVE-2026-62815 | Medium | 1.2% | 9.8 | Use after free in Microsoft QUIC allows an unauthorized attacker to execute code… | |
| CVE-2026-69587 | Medium | 1.2% | 7.5 | Null pointer dereference in Windows IKE Extension allows an unauthorized attacke… | |
| CVE-2026-69588 | Medium | 1.2% | 7.5 | Missing release of memory after effective lifetime in Windows TCP/IP allows an u… | |
| CVE-2026-32225 | Medium | 1.2% | 8.8 | Protection mechanism failure in Windows Shell allows an unauthorized attacker to… | |
| CVE-2026-20921 | Medium | 1.2% | 7.5 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-69881 | Medium | 1.2% | 7.5 | Null pointer dereference in Windows IKE Extension allows an unauthorized attacke… | |
| CVE-2026-40378 | Medium | 1.2% | 7.5 | Memory allocation with excessive size value in Windows Local Security Authority … | |
| CVE-2026-50355 | Medium | 1.2% | 7.5 | Stack-based buffer overflow in Active Directory Federation Services allows an un… | |
| CVE-2026-50368 | Medium | 1.2% | 7.5 | Stack-based buffer overflow in Active Directory Federation Services allows an un… | |
| CVE-2026-50411 | Medium | 1.2% | 7.5 | Stack-based buffer overflow in Active Directory Federation Services (AD FS) allo… | |
| CVE-2026-50647 | Medium | 1.2% | 7.5 | Loop with unreachable exit condition ('infinite loop') in Active Directory Feder… | |
| CVE-2026-50653 | Medium | 1.2% | 7.5 | Loop with unreachable exit condition ('infinite loop') in Azure Active Directory… | |
| CVE-2026-20856 | Medium | 1.1% | 8.1 | Improper input validation in Windows Server Update Service allows an unauthorize… | |
| CVE-2026-54113 | Medium | 1.1% | 7.5 | Allocation of resources without limits or throttling in Windows Kernel allows an… | |
| CVE-2026-69428 | Medium | 1.1% | 7.5 | Out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol allow… | |
| CVE-2026-20922 | Medium | 1.1% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to exec… |