Windows
by Microsoft
CVEs (2,653)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-50476 | Hig | 0.00 | 7.8 | 0.02 | Jul 14, 2026 | Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50450 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50431 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability | ||
| CVE-2026-50365 | Hig | 0.00 | 8.0 | 0.00 | Jul 14, 2026 | Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network. | ||
| CVE-2026-50344 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50334 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally. | ||
| CVE-2026-54992 | Hig | 0.00 | 8.4 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-54114 | Hig | 0.00 | 7.8 | 0.02 | Jul 14, 2026 | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50333 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50298 | Med | 0.00 | 6.8 | 0.00 | Jul 14, 2026 | Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack. | ||
| CVE-2026-50295 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2026-40378 | Hig | 0.00 | 7.5 | 0.01 | Jul 14, 2026 | Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | ||
| CVE-2017-20190 | 0.00 | — | 0.00 | Mar 27, 2024 | Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side performance degradation during processing of multiple Unicode combining characters, aka a "Zalgo text" attack. NOTE: third parties dispute whether the computational cost of interpreting… | |||
| CVE-2015-6126 | 0.00 | — | 0.02 | Dec 9, 2015 | Race condition in the Pragmatic General Multicast (PGM) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511… | |||
| CVE-2015-6113 | 0.00 | — | 0.02 | Nov 11, 2015 | The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to bypass intended filesystem permissions by leveraging… | |||
| CVE-2015-6112 | 0.00 | — | 0.03 | Nov 11, 2015 | SChannel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 lacks the required extended master-secret binding support to ensure that a server's X.509 certificate… | |||
| CVE-2015-6109 | 0.00 | — | 0.03 | Nov 11, 2015 | The kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the KASLR protection mechanism, and consequently discover a driver base address, via a crafted application, aka "Windows Kernel Memory… | |||
| CVE-2015-6095 | 0.00 | — | 0.04 | Nov 11, 2015 | Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles password changes, which allows physically proximate attackers to… | |||
| CVE-2015-2478 | 0.00 | — | 0.02 | Nov 11, 2015 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application that triggers a Winsock… | |||
| CVE-2015-2552 | 0.00 | — | 0.02 | Oct 14, 2015 | The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows physically proximate attackers to bypass the Trusted Boot protection mechanism, and consequently interfere with the integrity of code, BitLocker,… |
- risk 0.00cvss 7.8epss 0.02
Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 5.5epss 0.00
Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability
- risk 0.00cvss 8.0epss 0.00
Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.
- risk 0.00cvss 7.8epss 0.00
Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally.
- risk 0.00cvss 8.4epss 0.00
Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.02
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 6.8epss 0.00
Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.
- risk 0.00cvss 5.5epss 0.00
Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally.
- risk 0.00cvss 7.5epss 0.01
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
- CVE-2017-20190Mar 27, 2024risk 0.00cvss —epss 0.00
Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side performance degradation during processing of multiple Unicode combining characters, aka a "Zalgo text" attack. NOTE: third parties dispute whether the computational cost of interpreting…
- CVE-2015-6126Dec 9, 2015risk 0.00cvss —epss 0.02
Race condition in the Pragmatic General Multicast (PGM) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511…
- CVE-2015-6113Nov 11, 2015risk 0.00cvss —epss 0.02
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to bypass intended filesystem permissions by leveraging…
- CVE-2015-6112Nov 11, 2015risk 0.00cvss —epss 0.03
SChannel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 lacks the required extended master-secret binding support to ensure that a server's X.509 certificate…
- CVE-2015-6109Nov 11, 2015risk 0.00cvss —epss 0.03
The kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the KASLR protection mechanism, and consequently discover a driver base address, via a crafted application, aka "Windows Kernel Memory…
- CVE-2015-6095Nov 11, 2015risk 0.00cvss —epss 0.04
Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles password changes, which allows physically proximate attackers to…
- CVE-2015-2478Nov 11, 2015risk 0.00cvss —epss 0.02
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application that triggers a Winsock…
- CVE-2015-2552Oct 14, 2015risk 0.00cvss —epss 0.02
The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows physically proximate attackers to bypass the Trusted Boot protection mechanism, and consequently interfere with the integrity of code, BitLocker,…
Page 121 of 133