Windows 11 23h2
Sign in to watchby Microsoft
CVEs (113)
| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-32212 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. | |
| CVE-2026-32181 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally. | |
| CVE-2026-32085 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information locally. | |
| CVE-2026-32084 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | |
| CVE-2026-32081 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | |
| CVE-2026-32079 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | |
| CVE-2026-27931 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. | |
| CVE-2026-27930 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. | |
| CVE-2026-20806 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally. | |
| CVE-2026-33829 | Med | 0.31 | 4.3 | 0.00 | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network. | |
| CVE-2026-26175 | Med | 0.30 | 4.6 | 0.00 | Apr 14, 2026 | Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with a physical attack. | |
| CVE-2026-20928 | Med | 0.30 | 4.6 | 0.00 | Apr 14, 2026 | Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack. | |
| CVE-2026-27906 | Med | 0.29 | 4.4 | 0.00 | Apr 14, 2026 | Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally. |
Page 6 of 6