Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Windows 11
Total 599 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-55526 2 Microsoft, N8n 4 Windows 11, Fastapi, Pydantic and 1 more 2026-06-17 N/A 9.1 CRITICAL
n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py
CVE-2024-7553 2 Microsoft, Mongodb 24 Windows 10 1507, Windows 10 1511, Windows 10 1607 and 21 more 2026-06-17 N/A 7.3 HIGH
Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined by the contents of untrusted files. This issue affects MongoDB Server v5.0 versions prior to 5.0.27, MongoDB Server v6.0 versions prior to 6.0.16, MongoDB Server v7.0 versions prior to 7.0.12, MongoDB Server v7.3 versions prior 7.3.3, MongoDB C Driver versions prior to 1.26.2 and MongoDB PHP Driver versions prior to 1.18.1. Required Configuration: Only environments with Windows as the underlying operating system is affected by this issue
CVE-2023-44216 7 Amd, Apple, Canonical and 4 more 16 Ryzen 5 7600x, Ryzen 7 4800u, M1 Mac Mini and 13 more 2026-06-17 N/A 5.3 MEDIUM
PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text contained on a web page from one origin if they control a resource from a different origin.
CVE-2023-29413 2 Microsoft, Schneider-electric 7 Windows 10, Windows 11, Windows Server 2016 and 4 more 2026-06-17 N/A 7.5 HIGH
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor service.
CVE-2023-29412 2 Microsoft, Schneider-electric 7 Windows 10, Windows 11, Windows Server 2016 and 4 more 2026-06-17 N/A 9.8 CRITICAL
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface.
CVE-2023-29411 2 Microsoft, Schneider-electric 7 Windows 10, Windows 11, Windows Server 2016 and 4 more 2026-06-17 N/A 9.8 CRITICAL
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface.
CVE-2023-21776 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2026-06-17 N/A 5.5 MEDIUM
Windows Kernel Information Disclosure Vulnerability
CVE-2023-21771 1 Microsoft 3 Windows 10, Windows 11, Windows Server 2022 2026-06-17 N/A 7.0 HIGH
Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability
CVE-2023-21768 1 Microsoft 2 Windows 11, Windows Server 2022 2026-06-17 N/A 7.8 HIGH
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2023-21767 1 Microsoft 8 Windows 10, Windows 11, Windows 8.1 and 5 more 2026-06-17 N/A 7.8 HIGH
Windows Overlay Filter Elevation of Privilege Vulnerability
CVE-2023-21766 1 Microsoft 5 Windows 10, Windows 11, Windows Server 2016 and 2 more 2026-06-17 N/A 4.7 MEDIUM
Windows Overlay Filter Information Disclosure Vulnerability
CVE-2023-21765 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2026-06-17 N/A 7.8 HIGH
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2023-21760 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2026-06-17 N/A 7.1 HIGH
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2023-21759 1 Microsoft 3 Windows 10, Windows 11, Windows Server 2022 2026-06-17 N/A 3.3 LOW
Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability
CVE-2023-21758 1 Microsoft 5 Windows 10, Windows 11, Windows Server 2016 and 2 more 2026-06-17 N/A 7.5 HIGH
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
CVE-2023-21757 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2026-06-17 N/A 7.5 HIGH
Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability
CVE-2023-21752 1 Microsoft 3 Windows 10, Windows 11, Windows 7 2026-06-17 N/A 7.1 HIGH
Windows Backup Service Elevation of Privilege Vulnerability
CVE-2023-21746 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2026-06-17 N/A 7.8 HIGH
Windows NTLM Elevation of Privilege Vulnerability
CVE-2023-21558 1 Microsoft 8 Windows 10, Windows 11, Windows 8.1 and 5 more 2026-06-17 N/A 7.8 HIGH
Windows Error Reporting Service Elevation of Privilege Vulnerability
CVE-2023-20564 2 Amd, Microsoft 4 Ryzen Master, Ryzen Master Monitoring Sdk, Windows 10 and 1 more 2026-06-17 N/A 6.7 MEDIUM
Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may permit a privileged attacker to perform memory reads/writes potentially leading to a loss of confidentiality or arbitrary kernel execution.