VYPR

Windows 11 23h2

Sign in to watch

by Microsoft

CVEs (113)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2026-32212Med0.365.50.00Apr 14, 2026Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
CVE-2026-32181Med0.365.50.00Apr 14, 2026Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally.
CVE-2026-32085Med0.365.50.00Apr 14, 2026Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information locally.
CVE-2026-32084Med0.365.50.00Apr 14, 2026Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-32081Med0.365.50.00Apr 14, 2026Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-32079Med0.365.50.00Apr 14, 2026Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-27931Med0.365.50.00Apr 14, 2026Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
CVE-2026-27930Med0.365.50.00Apr 14, 2026Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
CVE-2026-20806Med0.365.50.00Apr 14, 2026Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.
CVE-2026-33829Med0.314.30.00Apr 14, 2026Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-26175Med0.304.60.00Apr 14, 2026Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with a physical attack.
CVE-2026-20928Med0.304.60.00Apr 14, 2026Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.
CVE-2026-27906Med0.294.40.00Apr 14, 2026Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally.

Page 6 of 6