Windows
This hub aggregates every CVE we track for Windows, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
2,435
CVEs tracked
383
Critical
1,296
High
80
In CISA KEV
Severity distribution
HIGH1,296MEDIUM669CRITICAL383LOW87
Monthly trend
1
1
1
0
0
3
0
1
1
1
0
0
3
1
2
0
3
0
0
0
0
0
0
1
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Windows.
- BDU:2026-08267Уязвимость операционных систем Windows, связанная с недостаточной защитой служебных данных, позволяющая нарушителю обойти функцию шифрования данных BitLocker7.8
- CVE-2025-11567CWE-276: Incorrect Default Permissions vulnerability exists that could cause elevated system access when the target installation folder is not properly secured.7.8
- CVE-2025-11566CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker on the local network to gain access to the user account by performing an arbitra...7.3
- CVE-2025-11565CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause elevated system access when a Web Admin user on the local network tamper...7.0
- CVE-2025-59033The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code signer certificate...7.4
- CVE-2022-50238The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online Microsoft recommended driver block rules. Some entries present on the online list have been excluded ...7.4
- CVE-2025-9491Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability7.8
- CVE-2025-46385CWE-918 Server-Side Request Forgery (SSRF)8.6
- CVE-2025-46384CWE-434 Unrestricted Upload of File with Dangerous Type8.8
- CVE-2025-46383CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')6.1
- BDU:2025-04739Уязвимость планировщика заданий операционных систем Windows, позволяющая нарушителю выполнить произвольные команды с привилегиями SYSTEM8.8
- BDU:2025-02936Уязвимость механизма обработки .LNK-файлов пользовательского интерфейса операционных систем Windows, позволяющая нарушителю скрытно выполнить произвольные команды операционной системы7.0
- BDU:2025-01870Уязвимость пользовательского интерфейса (UI) операционных систем Windows, позволяющая нарушителю скрыть от пользователей файлы, распакованные из специально сформированного архива4.5
- CVE-2022-40733An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as pa...5.0
- CVE-2022-40732An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as pa...5.0
Product normalization is registry-driven with AI assist and human review. How it works