Skip to main content

Vendor/product archive

microsoft / windows_11_25h2 CVEs

Beta · best-effort

1,201 CVEs tagged to microsoft / windows_11_25h219 Critical, 890 High, 286 Medium, 6 Low, 0 Unrated.

CVE-2026-49174

Published Jul 14, 2026

Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

CVSS 6.1 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-49172

Published Jul 14, 2026

Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
29.1

CVE-2026-49170

Published Jul 14, 2026

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
6
Buzz score
35.5

CVE-2026-49168

Published Jul 14, 2026

Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.

CVSS 6.8 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-49165

Published Jul 14, 2026

Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.

CVSS 7.1 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-44806

Published Jul 14, 2026

Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-42982

Published Jul 14, 2026

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
7
Buzz score
38.3

CVE-2026-42900

Published Jul 14, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a netwo…

CVSS 8.1 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-41087

Published Jul 14, 2026

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-40422

Published Jul 14, 2026

Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-40378

Published Jul 14, 2026

Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

CVSS 7.5 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-34349

Published Jul 14, 2026

Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
29.1
Showing 551-575 of 1,201 CVEsPage 23 of 49