VYPR

Windows 11 24h2

by Microsoft

Source repositories

CVEs (1,923)

  • CVE-2026-49170HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

  • CVE-2026-49168MedJul 14, 2026
    risk 0.00cvss 6.8epss 0.00

    Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.

  • CVE-2026-49167MedJul 14, 2026
    risk 0.00cvss 4.7epss 0.00

    Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2026-49166HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

  • CVE-2026-49165HigJul 14, 2026
    risk 0.00cvss 7.1epss 0.00

    Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.

  • CVE-2026-49164HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.01

    Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

  • CVE-2026-49162HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

  • CVE-2026-48572HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2026-48571HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2026-44806MedJul 14, 2026
    risk 0.00cvss 5.3epss 0.01

    Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

  • CVE-2026-44800HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42990CriJul 14, 2026
    risk 0.00cvss 9.8epss 0.01

    Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.

  • CVE-2026-42982HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42975HigJul 14, 2026
    risk 0.00cvss 8.0epss 0.01

    Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.

  • CVE-2026-42900HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-41087MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

  • CVE-2026-40422MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.

  • CVE-2026-40378HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

  • CVE-2026-34349MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.

  • CVE-2026-34348MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.

Page 96 of 97