CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

microsoft

windows_11_25h2

334 known vulnerabilities · sorted by CVSS score

CVE-2025-49708
CRITICAL9.9

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.

microsoft / windows_10_1809+11
Network
Published Oct 14, 2025
Page 1 of 17
CVE-2025-60724
CRITICAL9.8

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

microsoft / office+21
Network
Published Nov 11, 2025
CVE-2026-25177
HIGH8.8

Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.

microsoft / windows_10_1607+24
Network
Published Mar 10, 2026
CVE-2025-59295
HIGH8.8

Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.

microsoft / windows_10_1507+21
Network
Published Oct 14, 2025
CVE-2025-62456
HIGH8.8

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network.

microsoft / windows_11_23h2+5
Network
Published Dec 9, 2025
CVE-2025-58715
HIGH8.8

Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

microsoft / windows_10_1507+16
Local
Published Oct 14, 2025
CVE-2026-23669
HIGH8.8

Use after free in RPC Runtime allows an authorized attacker to execute code over a network.

microsoft / windows_10_1607+24
Network
Published Mar 10, 2026
CVE-2025-58716
HIGH8.8

Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

microsoft / windows_10_1507+16
Local
Published Oct 14, 2025
CVE-2025-62549
HIGH8.8

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

microsoft / windows_10_1607+18
Network
Published Dec 9, 2025
CVE-2026-20868
HIGH8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

microsoft / windows_10_1607+18
Network
Published Jan 13, 2026
CVE-2026-21513
HIGH8.8

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

microsoft / windows_10_1607+22
Network
Published Feb 10, 2026
CVE-2026-21510
HIGH8.8

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

microsoft / windows_10_1607+22
Network
Published Feb 10, 2026
CVE-2025-64678
HIGH8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

microsoft / windows_10_1607+18
Network
Published Dec 9, 2025
CVE-2026-25188
HIGH8.8

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network.

microsoft / windows_10_1607+24
Adjacent
Published Mar 10, 2026
CVE-2025-58718
HIGH8.8

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

microsoft / remote_desktop_client+23
Network
Published Oct 14, 2025
CVE-2026-24283
HIGH8.8

Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally.

microsoft / windows_11_24h2+7
Local
Published Mar 10, 2026
CVE-2026-21255
HIGH8.8

Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally.

microsoft / windows_10_1607+14
Local
Published Feb 10, 2026
CVE-2026-20856
HIGH8.1

Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

microsoft / windows_10_1607+15
Network
Published Jan 13, 2026
CVE-2025-60715
HIGH8.0

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

microsoft / windows_10_1607+18
Network
Published Nov 11, 2025
CVE-2026-25173
HIGH8.0

Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

microsoft / windows_10_1607+24
Network
Published Mar 10, 2026