microsoft / windows_11_24h2
1,111 known vulnerabilities in microsoft windows_11_24h2.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-83979 | Medium | 0.3% | 7.8 | Use after free in Windows Biometric Service allows an authorized attacker to ele… | |
| CVE-2026-83980 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83981 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83982 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83983 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83985 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83986 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83987 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83988 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-33828 | Medium | 0.3% | 7.8 | Trust boundary violation in Windows Attestation allows an authorized attacker to… | |
| CVE-2026-45654 | Medium | 0.3% | 7.9 | Improper access control in Windows Secure Boot allows an authorized attacker to … | |
| CVE-2026-20877 | Medium | 0.3% | 7.8 | Use after free in Windows Management Services allows an authorized attacker to e… | |
| CVE-2026-20918 | Medium | 0.3% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20924 | Medium | 0.3% | 7.8 | Use after free in Windows Management Services allows an authorized attacker to e… | |
| CVE-2026-33098 | Medium | 0.3% | 7.8 | Use after free in Windows Container Isolation FS Filter Driver allows an authori… | |
| CVE-2026-45641 | Medium | 0.3% | 8.4 | Access of resource using incompatible type ('type confusion') in Windows Hyper-V… | |
| CVE-2026-50451 | Medium | 0.3% | 7.1 | Missing authentication for critical function in Windows Routing and Remote Acces… | |
| CVE-2026-20826 | Medium | 0.3% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20831 | Medium | 0.3% | 7.8 | Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function … | |
| CVE-2026-54127 | Medium | 0.3% | 7.4 | Use after free in Windows Hyper-V allows an unauthorized attacker to elevate pri… | |
| CVE-2026-83498 | Medium | 0.3% | 7.8 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enc… | |
| CVE-2026-45588 | Medium | 0.3% | 7.9 | Protection mechanism failure in Windows Secure Boot allows an authorized attacke… | |
| CVE-2026-47656 | Medium | 0.3% | 7.9 | Protection mechanism failure in Windows Boot Manager allows an authorized attack… | |
| CVE-2026-48568 | Medium | 0.3% | 7.9 | Protection mechanism failure in Windows Secure Boot allows an authorized attacke… | |
| CVE-2026-48570 | Medium | 0.3% | 7.9 | Protection mechanism failure in Windows Secure Boot allows an authorized attacke… | |
| CVE-2026-48575 | Medium | 0.3% | 7.9 | Protection mechanism failure in Windows Secure Boot allows an authorized attacke… | |
| CVE-2026-50459 | Medium | 0.3% | 7.0 | Use after free in Windows Kernel allows an unauthorized attacker to elevate priv… | |
| CVE-2026-49171 | Medium | 0.3% | 7.5 | Use after free in Microsoft Windows Speech allows an authorized attacker to elev… | |
| CVE-2026-69900 | Medium | 0.3% | 7.8 | Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allow… | |
| CVE-2026-40409 | Medium | 0.3% | 7.8 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege V… | |
| CVE-2026-49170 | Medium | 0.3% | 7.8 | Insufficient granularity of access control in Windows StateRepository API allows… | |
| CVE-2026-50311 | Medium | 0.3% | 7.8 | Improper access control in Windows Server allows an authorized attacker to eleva… | |
| CVE-2026-50333 | Medium | 0.3% | 7.8 | Missing authentication for critical function in Windows Spaceport.sys allows an … | |
| CVE-2026-50335 | Medium | 0.3% | 7.8 | Improper access control in Windows Operating Systems allows an authorized attack… | |
| CVE-2026-50342 | Medium | 0.3% | 8.8 | Improper access control in Windows MIDI Service Module allows an authorized atta… | |
| CVE-2026-50343 | Medium | 0.3% | 7.8 | Improper privilege management in Microsoft Install Service allows an authorized … | |
| CVE-2026-50344 | Medium | 0.3% | 7.8 | Improper authorization in Windows OLE allows an authorized attacker to elevate p… | |
| CVE-2026-50346 | Medium | 0.3% | 7.8 | Improper authorization in RPC Runtime allows an authorized attacker to elevate p… | |
| CVE-2026-50351 | Medium | 0.3% | 7.8 | Improper access control in Windows Audio Compression Manager (ACM) allows an aut… | |
| CVE-2026-50373 | Medium | 0.3% | 7.8 | Improper access control in Microsoft Windows Search Component allows an authoriz… | |
| CVE-2026-50391 | Medium | 0.3% | 7.8 | Improper privilege management in Windows Group Policy allows an authorized attac… | |
| CVE-2026-50405 | Medium | 0.3% | 7.8 | Insufficient granularity of access control in Windows Filtering Platform (WFP) a… | |
| CVE-2026-50423 | Medium | 0.3% | 7.8 | Improper access control in Windows Kernel allows an authorized attacker to eleva… | |
| CVE-2026-50465 | Medium | 0.3% | 7.1 | Improper access control in Microsoft Windows DNS allows an authorized attacker t… | |
| CVE-2026-58540 | Medium | 0.3% | 7.8 | Improper authorization in Windows Installer allows an authorized attacker to ele… | |
| CVE-2026-20808 | Medium | 0.3% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20814 | Medium | 0.3% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20815 | Medium | 0.3% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20836 | Medium | 0.3% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20858 | Medium | 0.3% | 7.8 | Use after free in Windows Management Services allows an authorized attacker to e… |