Windows 11 23h2
by Microsoft
Source repositories
CVEs (2,235)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-41098 | Med | 0.36 | 5.5 | 0.01 | Nov 9, 2022 | Windows GDI+ Information Disclosure Vulnerability | ||
| CVE-2022-41055 | Med | 0.36 | 5.5 | 0.01 | Nov 9, 2022 | Windows Human Interface Device Information Disclosure Vulnerability | ||
| CVE-2022-38043 | Med | 0.36 | 5.5 | 0.01 | Oct 11, 2022 | Windows Security Support Provider Interface Information Disclosure Vulnerability | ||
| CVE-2022-38026 | Med | 0.36 | 5.5 | 0.01 | Oct 11, 2022 | Windows DHCP Client Information Disclosure Vulnerability | ||
| CVE-2022-38025 | Med | 0.36 | 5.5 | 0.01 | Oct 11, 2022 | Windows Distributed File System (DFS) Information Disclosure Vulnerability | ||
| CVE-2022-37996 | Med | 0.36 | 5.5 | 0.01 | Oct 11, 2022 | Windows Kernel Memory Information Disclosure Vulnerability | ||
| CVE-2026-45595 | Med | 0.35 | 5.4 | 0.00 | Jun 9, 2026 | Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-35423 | Med | 0.35 | 5.4 | 0.01 | May 12, 2026 | Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2024-21313 | Med | 0.35 | 5.3 | 0.01 | Jan 9, 2024 | Windows TCP/IP Information Disclosure Vulnerability | ||
| CVE-2023-35384 | Med | 0.35 | 5.4 | 0.02 | Aug 8, 2023 | Windows HTML Platforms Security Feature Bypass Vulnerability | ||
| CVE-2023-32013 | Med | 0.35 | 5.3 | 0.02 | Jun 14, 2023 | Windows Hyper-V Denial of Service Vulnerability | ||
| CVE-2023-28226 | Med | 0.35 | 5.3 | 0.01 | Apr 11, 2023 | Windows Enroll Engine Security Feature Bypass Vulnerability | ||
| CVE-2023-21682 | Med | 0.35 | 5.3 | 0.01 | Jan 10, 2023 | Windows Point-to-Point Protocol (PPP) Information Disclosure Vulnerability | ||
| CVE-2023-21525 | Med | 0.35 | 5.3 | 0.02 | Jan 10, 2023 | Remote Procedure Call Runtime Denial of Service Vulnerability | ||
| CVE-2026-45655 | Med | 0.34 | 5.3 | 0.00 | Jun 9, 2026 | Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | ||
| CVE-2026-42914 | Med | 0.34 | 5.3 | 0.01 | Jun 9, 2026 | Windows Kerberos Denial of Service Vulnerability | ||
| CVE-2026-33829 | Med | 0.31 | 4.3 | 0.03 | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2024-20691 | Med | 0.31 | 4.7 | 0.01 | Jan 9, 2024 | Windows Themes Information Disclosure Vulnerability | ||
| CVE-2023-32019 | Med | 0.31 | 4.7 | 0.01 | Jun 14, 2023 | Windows Kernel Information Disclosure Vulnerability | ||
| CVE-2023-21766 | Med | 0.31 | 4.7 | 0.01 | Jan 10, 2023 | Windows Overlay Filter Information Disclosure Vulnerability |
- risk 0.36cvss 5.5epss 0.01
Windows GDI+ Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Human Interface Device Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Security Support Provider Interface Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows DHCP Client Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Distributed File System (DFS) Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Kernel Memory Information Disclosure Vulnerability
- risk 0.35cvss 5.4epss 0.00
Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.35cvss 5.4epss 0.01
Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network.
- risk 0.35cvss 5.3epss 0.01
Windows TCP/IP Information Disclosure Vulnerability
- risk 0.35cvss 5.4epss 0.02
Windows HTML Platforms Security Feature Bypass Vulnerability
- risk 0.35cvss 5.3epss 0.02
Windows Hyper-V Denial of Service Vulnerability
- risk 0.35cvss 5.3epss 0.01
Windows Enroll Engine Security Feature Bypass Vulnerability
- risk 0.35cvss 5.3epss 0.01
Windows Point-to-Point Protocol (PPP) Information Disclosure Vulnerability
- risk 0.35cvss 5.3epss 0.02
Remote Procedure Call Runtime Denial of Service Vulnerability
- risk 0.34cvss 5.3epss 0.00
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- risk 0.34cvss 5.3epss 0.01
Windows Kerberos Denial of Service Vulnerability
- risk 0.31cvss 4.3epss 0.03
Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.
- risk 0.31cvss 4.7epss 0.01
Windows Themes Information Disclosure Vulnerability
- risk 0.31cvss 4.7epss 0.01
Windows Kernel Information Disclosure Vulnerability
- risk 0.31cvss 4.7epss 0.01
Windows Overlay Filter Information Disclosure Vulnerability
Page 46 of 112