Windows
by Microsoft
CVEs (2,653)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-7237 | Med | 0.50 | 6.5 | 0.67 | Nov 10, 2016 | Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote… | ||
| CVE-2016-3375 | Hig | 0.50 | 7.5 | 0.17 | Sep 14, 2016 | The OLE Automation mechanism and VBScript scripting engine in Microsoft Internet Explorer 9 through 11, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow… | ||
| CVE-2016-3369 | Hig | 0.50 | 7.5 | 0.12 | Sep 14, 2016 | Microsoft Windows 10 Gold and 1511 allows attackers to cause a denial of service via unspecified vectors, aka "Windows Denial of Service Vulnerability." | ||
| CVE-2026-40406 | Hig | 0.49 | 7.5 | 0.01 | May 12, 2026 | Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-35424 | Hig | 0.49 | 7.5 | 0.01 | May 12, 2026 | Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-32071 | Hig | 0.49 | 7.5 | 0.01 | Apr 14, 2026 | Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-23674 | Hig | 0.49 | 7.5 | 0.01 | Mar 10, 2026 | Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-20875 | Hig | 0.49 | 7.5 | 0.02 | Jan 13, 2026 | Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | ||
| CVE-2025-32724 | Hig | 0.49 | 7.5 | 0.02 | Jun 10, 2025 | Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | ||
| CVE-2025-27485 | Hig | 0.49 | 7.5 | 0.02 | Apr 8, 2025 | Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. | ||
| CVE-2025-21276 | Hig | 0.49 | 7.5 | 0.02 | Jan 14, 2025 | Windows MapUrlToZone Denial of Service Vulnerability | ||
| CVE-2025-21218 | Hig | 0.49 | 7.5 | 0.03 | Jan 14, 2025 | Windows Kerberos Denial of Service Vulnerability | ||
| CVE-2024-43450 | Hig | 0.49 | 7.5 | 0.01 | Nov 12, 2024 | Windows DNS Spoofing Vulnerability | ||
| CVE-2024-43565 | Hig | 0.49 | 7.5 | 0.02 | Oct 8, 2024 | Windows Network Address Translation (NAT) Denial of Service Vulnerability | ||
| CVE-2024-43562 | Hig | 0.49 | 7.5 | 0.02 | Oct 8, 2024 | Windows Network Address Translation (NAT) Denial of Service Vulnerability | ||
| CVE-2024-38129 | Hig | 0.49 | 7.5 | 0.01 | Oct 8, 2024 | Windows Kerberos Elevation of Privilege Vulnerability | ||
| CVE-2024-38233 | Hig | 0.49 | 7.5 | 0.02 | Sep 10, 2024 | Windows Networking Denial of Service Vulnerability | ||
| CVE-2024-38232 | Hig | 0.49 | 7.5 | 0.02 | Sep 10, 2024 | Windows Networking Denial of Service Vulnerability | ||
| CVE-2024-26248 | Hig | 0.49 | 7.5 | 0.01 | Apr 9, 2024 | Windows Kerberos Elevation of Privilege Vulnerability | ||
| CVE-2024-21427 | Hig | 0.49 | 7.5 | 0.02 | Mar 12, 2024 | Windows Kerberos Security Feature Bypass Vulnerability |
- risk 0.50cvss 6.5epss 0.67
Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote…
- risk 0.50cvss 7.5epss 0.17
The OLE Automation mechanism and VBScript scripting engine in Microsoft Internet Explorer 9 through 11, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow…
- risk 0.50cvss 7.5epss 0.12
Microsoft Windows 10 Gold and 1511 allows attackers to cause a denial of service via unspecified vectors, aka "Windows Denial of Service Vulnerability."
- risk 0.49cvss 7.5epss 0.01
Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network.
- risk 0.49cvss 7.5epss 0.01
Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.49cvss 7.5epss 0.02
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.02
Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.02
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.02
Windows MapUrlToZone Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows Kerberos Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
Windows DNS Spoofing Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Network Address Translation (NAT) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Network Address Translation (NAT) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
Windows Kerberos Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Networking Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Networking Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
Windows Kerberos Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Kerberos Security Feature Bypass Vulnerability
Page 55 of 133