VendorsMicrosoftwindows_11_23h2all versions
Vulnerabilities

Microsoft Windows 11

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2313CVEs
CVE-2025-49708
Microsoft Graphics Component Elevation of Privilege Vulnerability
Published 2025-10-14 · Analyzed
9.9EPSS 0.012
CVE-2025-21298
Windows OLE Remote Code Execution Vulnerability
Published 2025-01-14 · Analyzed
9.8EPSS 0.809
CVE-2023-38545
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255 bytes. If the host name is detected to be longer, curl switches to local name resolving and instead passes on the resolved address only. Due to this bug, the local variable that means "let the host resolve the name" could get the wrong value during a slow SOCKS5 handshake, and contrary to the intention, copy the too long host name to the target buffer instead of copying just the resolved address there. The target buffer being a heap based buffer, and the host name coming from the URL that curl has been told to operate with.
Published 2023-10-18 · Modified
9.8EPSS 0.785
CVE-2026-33824
Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
Published 2026-04-14 · Analyzed
9.8KEVEPSS 0.727
CVE-2024-38063
Windows TCP/IP Remote Code Execution Vulnerability
Published 2024-08-13 · Analyzed
9.8EPSS 0.706
CVE-2024-30080
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2024-06-11 · Modified
9.8EPSS 0.431
CVE-2025-47981
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
Published 2025-07-08 · Analyzed
9.8EPSS 0.326
CVE-2026-47291
HTTP.sys Remote Code Execution Vulnerability
Published 2026-06-09 · Analyzed
9.8EPSS 0.228
CVE-2025-55234
Windows SMB Elevation of Privilege Vulnerability
Published 2025-09-09 · Modified
9.8EPSS 0.201
CVE-2023-36397
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Published 2023-11-14 · Modified
9.8EPSS 0.175
CVE-2026-45657
Windows Kernel Remote Code Execution Vulnerability
Published 2026-06-09 · Analyzed
9.8EPSS 0.155
CVE-2023-36049
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
Published 2023-11-14 · Modified
9.8EPSS 0.125
CVE-2025-53766
GDI+ Remote Code Execution Vulnerability
Published 2025-08-12 · Analyzed
9.8EPSS 0.080
CVE-2025-60724
GDI+ Remote Code Execution Vulnerability
Published 2025-11-11 · Analyzed
9.8EPSS 0.059
CVE-2024-38140
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Published 2024-08-13 · Modified
9.8EPSS 0.038
CVE-2023-36028
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
Published 2023-11-14 · Modified
9.8EPSS 0.028
CVE-2024-0057
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
Published 2024-01-09 · Modified
9.8EPSS 0.028
CVE-2024-38199
Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
Published 2024-08-13 · Analyzed
9.8EPSS 0.022
CVE-2026-41096
Windows DNS Client Remote Code Execution Vulnerability
Published 2026-05-12 · Analyzed
9.8EPSS 0.019
CVE-2025-21307
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Published 2025-01-14 · Analyzed
9.8EPSS 0.019
CVE-2024-38240
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Published 2024-09-10 · Analyzed
9.8EPSS 0.015
CVE-2024-21416
Windows TCP/IP Remote Code Execution Vulnerability
Published 2024-09-10 · Analyzed
9.8EPSS 0.014
CVE-2026-62815
Microsoft QUIC Remote Code Execution Vulnerability
Published 2026-08-11 · Analyzed
9.8EPSS 0.012
CVE-2026-44815
DHCP Client Service Remote Code Execution Vulnerability
Published 2026-06-09 · Analyzed
9.8EPSS 0.011
CVE-2026-69525
Remote Desktop Services Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.010
CVE-2026-69829
Windows Shell Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.010
CVE-2026-69715
Windows Direct Show Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.010
CVE-2026-69910
Windows Hyper-V Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.010
CVE-2026-49172
Windows FTP Service Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
9.8EPSS 0.010
CVE-2026-69586
Microsoft Windows PDF Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.010
CVE-2026-69496
Windows Compressed Folder Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.010
CVE-2026-69590
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.010
CVE-2026-69579
Windows Message Queuing Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.010
CVE-2026-77493
Windows Graphics Component Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.010
CVE-2026-70296
Windows Imaging Component Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.010
CVE-2026-69463
Windows NTFS Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.009
CVE-2026-69768
Windows RNDIS Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.009
CVE-2026-72950
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.009
CVE-2026-72983
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.009
CVE-2026-72982
Windows Netlogon Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.009
1 / 58Next →