microsoft / windows_11_25h2
1,081 known vulnerabilities in microsoft windows_11_25h2.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-32225 | Medium | 1.2% | 8.8 | Protection mechanism failure in Windows Shell allows an unauthorized attacker to… | |
| CVE-2026-20921 | Medium | 1.2% | 7.5 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-69881 | Medium | 1.2% | 7.5 | Null pointer dereference in Windows IKE Extension allows an unauthorized attacke… | |
| CVE-2026-40378 | Medium | 1.2% | 7.5 | Memory allocation with excessive size value in Windows Local Security Authority … | |
| CVE-2026-49787 | Medium | 1.2% | 7.5 | Allocation of resources without limits or throttling in Windows HTTP.sys allows … | |
| CVE-2026-49788 | Medium | 1.2% | 7.5 | Allocation of resources without limits or throttling in HTTP/2 allows an unautho… | |
| CVE-2026-50355 | Medium | 1.2% | 7.5 | Stack-based buffer overflow in Active Directory Federation Services allows an un… | |
| CVE-2026-50368 | Medium | 1.2% | 7.5 | Stack-based buffer overflow in Active Directory Federation Services allows an un… | |
| CVE-2026-50411 | Medium | 1.2% | 7.5 | Stack-based buffer overflow in Active Directory Federation Services (AD FS) allo… | |
| CVE-2026-50424 | Medium | 1.2% | 7.5 | Untrusted pointer dereference in Windows Domain Controller allows an unauthorize… | |
| CVE-2026-50496 | Medium | 1.2% | 7.5 | Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized … | |
| CVE-2026-50647 | Medium | 1.2% | 7.5 | Loop with unreachable exit condition ('infinite loop') in Active Directory Feder… | |
| CVE-2026-50653 | Medium | 1.2% | 7.5 | Loop with unreachable exit condition ('infinite loop') in Azure Active Directory… | |
| CVE-2026-50695 | Medium | 1.2% | 7.5 | Stack-based buffer overflow in Active Directory Federation Services allows an un… | |
| CVE-2026-50696 | Medium | 1.2% | 7.5 | Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allow… | |
| CVE-2026-54119 | Medium | 1.2% | 7.5 | Loop with unreachable exit condition ('infinite loop') in Windows Active Directo… | |
| CVE-2026-20856 | Medium | 1.1% | 8.1 | Improper input validation in Windows Server Update Service allows an unauthorize… | |
| CVE-2026-54113 | Medium | 1.1% | 7.5 | Allocation of resources without limits or throttling in Windows Kernel allows an… | |
| CVE-2026-69428 | Medium | 1.1% | 7.5 | Out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol allow… | |
| CVE-2026-56186 | Medium | 1.1% | 8.1 | Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose… | |
| CVE-2026-20854 | Medium | 1.1% | 7.5 | Use after free in Windows Local Security Authority Subsystem Service (LSASS) all… | |
| CVE-2026-20922 | Medium | 1.1% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to exec… | |
| CVE-2026-44815 | Medium | 1.1% | 9.8 | Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attack… | |
| CVE-2026-50429 | Medium | 1.1% | 8.2 | Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose… | |
| CVE-2026-69525 | Medium | 1.0% | 9.8 | Use after free in Windows Remote Desktop Services allows an unauthorized attacke… | |
| CVE-2026-69829 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to e… | |
| CVE-2026-47302 | Medium | 1.0% | 7.5 | Allocation of resources without limits or throttling in .NET allows an unauthori… | |
| CVE-2026-48573 | Medium | 1.0% | 7.9 | No cwe for this issue in Windows Secure Boot allows an authorized attacker to by… | |
| CVE-2026-48576 | Medium | 1.0% | 7.9 | No cwe for this issue in Windows Secure Boot allows an authorized attacker to by… | |
| CVE-2026-50463 | Medium | 1.0% | 7.5 | Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose… | |
| CVE-2026-50470 | Medium | 1.0% | 7.5 | Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized … | |
| CVE-2026-20849 | Medium | 1.0% | 7.5 | Reliance on untrusted inputs in a security decision in Windows Kerberos allows a… | |
| CVE-2026-69496 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized a… | |
| CVE-2026-42990 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized atta… | |
| CVE-2026-49172 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacke… | |
| CVE-2026-50447 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Windows Message Queuing allows an unauthorized att… | |
| CVE-2026-56190 | Medium | 1.0% | 9.8 | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to … | |
| CVE-2026-69910 | Medium | 1.0% | 9.8 | Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker t… | |
| CVE-2026-50646 | Medium | 1.0% | 7.8 | Protection mechanism failure in .NET Framework allows an unauthorized attacker t… | |
| CVE-2026-47289 | Medium | 1.0% | 8.8 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac… | |
| CVE-2026-70296 | Medium | 1.0% | 9.8 | Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker… | |
| CVE-2026-77493 | Medium | 1.0% | 9.8 | Double free in Microsoft Graphics Component allows an unauthorized attacker to e… | |
| CVE-2026-50649 | Medium | 0.9% | 7.8 | Deserialization of untrusted data in .NET allows an unauthorized attacker to exe… | |
| CVE-2026-62784 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv)… | |
| CVE-2026-62800 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker t… | |
| CVE-2026-50682 | Medium | 0.9% | 7.1 | Out-of-bounds read in Windows Active Directory allows an authorized attacker to … | |
| CVE-2026-49178 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Active Directory Domain Services allows an authori… | |
| CVE-2026-50666 | Medium | 0.9% | 8.8 | Use after free in Windows Remote Access Connection Manager allows an authorized … | |
| CVE-2026-56194 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Windows Network File System allows an authorized a… | |
| CVE-2026-56647 | Medium | 0.9% | 8.8 | Integer overflow or wraparound in Windows Remote Access Service Infrastructure a… |