microsoft / windows_11_24h2
1,111 known vulnerabilities in microsoft windows_11_24h2.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-20861 | Medium | 0.3% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20866 | Medium | 0.3% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20867 | Medium | 0.3% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20869 | Medium | 0.3% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20873 | Medium | 0.3% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20874 | Medium | 0.3% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50650 | Medium | 0.3% | 7.8 | Improper control of generation of code ('code injection') in .NET Framework allo… | |
| CVE-2026-70354 | Medium | 0.3% | 7.8 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code loca… | |
| CVE-2026-32221 | Medium | 0.3% | 8.4 | Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorize… | |
| CVE-2026-41092 | Medium | 0.3% | 7.8 | Improper access control in Microsoft Kinect allows an authorized attacker to ele… | |
| CVE-2026-42829 | Medium | 0.3% | 7.8 | Improper access control in Windows Administrator Protection allows an authorized… | |
| CVE-2026-83995 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elev… | |
| CVE-2026-42910 | Medium | 0.3% | 7.8 | Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized … | |
| CVE-2026-42983 | Medium | 0.3% | 7.8 | Use after free in Windows DWM Core Library allows an authorized attacker to elev… | |
| CVE-2026-45592 | Medium | 0.3% | 7.8 | Integer overflow or wraparound in Windows Internet (wininet.dll) allows an autho… | |
| CVE-2026-45593 | Medium | 0.3% | 7.8 | Use after free in Windows SDK allows an authorized attacker to elevate privilege… | |
| CVE-2026-45600 | Medium | 0.3% | 7.8 | Access of resource using incompatible type ('type confusion') in Windows Kernel-… | |
| CVE-2026-45605 | Medium | 0.3% | 7.8 | Use after free in Windows Bluetooth Service allows an authorized attacker to ele… | |
| CVE-2026-45637 | Medium | 0.3% | 7.8 | Use after free in Windows DWM Core Library allows an authorized attacker to elev… | |
| CVE-2026-45638 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allo… | |
| CVE-2026-69911 | Medium | 0.3% | 7.0 | Use after free in Microsoft Windows Search Component allows an authorized attack… | |
| CVE-2026-50307 | Medium | 0.3% | 7.0 | Use after free in Windows TCP/IP allows an authorized attacker to elevate privil… | |
| CVE-2026-50358 | Medium | 0.3% | 7.0 | Use after free in Windows Media allows an authorized attacker to elevate privile… | |
| CVE-2026-50359 | Medium | 0.3% | 7.0 | Use after free in Microsoft XML Core Services allows an authorized attacker to e… | |
| CVE-2026-50390 | Medium | 0.3% | 7.0 | Access of resource using incompatible type ('type confusion') in Windows Kernel … | |
| CVE-2026-50393 | Medium | 0.3% | 7.0 | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to e… | |
| CVE-2026-50396 | Medium | 0.3% | 7.0 | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to e… | |
| CVE-2026-50406 | Medium | 0.3% | 7.0 | Use after free in Windows Backup Engine allows an authorized attacker to elevate… | |
| CVE-2026-50476 | Medium | 0.3% | 7.8 | Use after free in Microsoft Windows allows an authorized attacker to elevate pri… | |
| CVE-2026-50490 | Medium | 0.3% | 7.0 | Use after free in Windows Installer allows an authorized attacker to elevate pri… | |
| CVE-2026-50491 | Medium | 0.3% | 7.0 | Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker … | |
| CVE-2026-50674 | Medium | 0.3% | 7.0 | Use after free in Windows USB Print Driver allows an authorized attacker to elev… | |
| CVE-2026-54129 | Medium | 0.3% | 7.0 | Use after free in Windows Hyper-V allows an authorized attacker to elevate privi… | |
| CVE-2026-54989 | Medium | 0.3% | 7.0 | Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows … | |
| CVE-2026-56187 | Medium | 0.3% | 7.0 | Use after free in Windows MIDI Service Module allows an authorized attacker to e… | |
| CVE-2026-57093 | Medium | 0.3% | 7.0 | Use after free in Windows Ancillary Function Driver for WinSock allows an author… | |
| CVE-2026-61356 | Medium | 0.3% | 7.8 | Missing authentication for critical function in Windows Remote Desktop Services … | |
| CVE-2026-61364 | Medium | 0.3% | 7.8 | Missing authentication for critical function in Windows Remote Desktop Services … | |
| CVE-2026-61365 | Medium | 0.3% | 7.8 | Missing authentication for critical function in Windows Remote Desktop Services … | |
| CVE-2026-61367 | Medium | 0.3% | 7.8 | Missing authentication for critical function in Windows Remote Desktop Services … | |
| CVE-2026-69907 | Medium | 0.3% | 7.8 | Improper handling of insufficient permissions or privileges in Windows Enterpris… | |
| CVE-2026-83990 | Medium | 0.3% | 7.8 | Stack-based buffer overflow in Microsoft Graphics Component allows an authorized… | |
| CVE-2026-84000 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Microsoft Graphics Component allows an authorized … | |
| CVE-2026-56181 | Medium | 0.3% | 8.3 | Origin validation error in Windows Network Address Translation (NAT) allows an u… | |
| CVE-2026-41108 | Medium | 0.3% | 7.0 | Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacke… | |
| CVE-2026-62890 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to exec… | |
| CVE-2026-66799 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to… | |
| CVE-2026-48578 | Medium | 0.3% | 7.9 | Improper access control in Windows Secure Boot allows an authorized attacker to … | |
| CVE-2026-44802 | Medium | 0.3% | 7.8 | Use after free in Windows DWM Core Library allows an authorized attacker to elev… | |
| CVE-2026-44809 | Medium | 0.3% | 7.8 | Use after free in Windows Common Log File System Driver allows an authorized att… |