Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Microsoft Subscribe
Filtered by product Windows 11
Total 620 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-21776 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2023-02-10 N/A 5.5 MEDIUM
Windows Kernel Information Disclosure Vulnerability.
CVE-2022-38046 1 Microsoft 4 Windows 10, Windows 11, Windows Server 2019 and 1 more 2023-02-10 N/A 7.5 HIGH
Web Account Manager Information Disclosure Vulnerability.
CVE-2022-42970 2 Microsoft, Schneider-electric 8 Windows 10, Windows 11, Windows 7 and 5 more 2023-02-08 N/A 9.8 CRITICAL
A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)
CVE-2022-42971 2 Microsoft, Schneider-electric 8 Windows 10, Windows 11, Windows 7 and 5 more 2023-02-08 N/A 9.8 CRITICAL
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)
CVE-2022-42972 2 Microsoft, Schneider-electric 8 Windows 10, Windows 11, Windows 7 and 5 more 2023-02-08 N/A 7.8 HIGH
A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a local attacker modifies the webroot directory. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)
CVE-2022-42973 2 Microsoft, Schneider-electric 8 Windows 10, Windows 11, Windows 7 and 5 more 2023-02-08 N/A 7.8 HIGH
A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local attacker connects to the database. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)
CVE-2022-38038 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2023-01-18 N/A 7.8 HIGH
Windows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37988, CVE-2022-37990, CVE-2022-37991, CVE-2022-37995, CVE-2022-38022, CVE-2022-38037, CVE-2022-38039.
CVE-2022-37991 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2023-01-18 N/A 7.8 HIGH
Windows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37988, CVE-2022-37990, CVE-2022-37995, CVE-2022-38022, CVE-2022-38037, CVE-2022-38038, CVE-2022-38039.
CVE-2023-21752 1 Microsoft 3 Windows 10, Windows 11, Windows 7 2023-01-18 N/A 7.1 HIGH
Windows Backup Service Elevation of Privilege Vulnerability.
CVE-2023-21746 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2023-01-18 N/A 7.8 HIGH
Windows NTLM Elevation of Privilege Vulnerability.
CVE-2023-21757 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2023-01-18 N/A 7.5 HIGH
Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability.
CVE-2023-21765 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2023-01-18 N/A 7.8 HIGH
Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21678, CVE-2023-21760.
CVE-2023-21760 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2023-01-18 N/A 7.1 HIGH
Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21678, CVE-2023-21765.
CVE-2023-21758 1 Microsoft 5 Windows 10, Windows 11, Windows Server 2016 and 2 more 2023-01-18 N/A 7.5 HIGH
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability. This CVE ID is unique from CVE-2023-21677, CVE-2023-21683.
CVE-2023-21759 1 Microsoft 3 Windows 10, Windows 11, Windows Server 2022 2023-01-18 N/A 3.3 LOW
Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability.
CVE-2023-21766 1 Microsoft 5 Windows 10, Windows 11, Windows Server 2016 and 2 more 2023-01-18 N/A 4.7 MEDIUM
Windows Overlay Filter Information Disclosure Vulnerability.
CVE-2023-21558 1 Microsoft 8 Windows 10, Windows 11, Windows 8.1 and 5 more 2023-01-18 N/A 7.8 HIGH
Windows Error Reporting Service Elevation of Privilege Vulnerability.
CVE-2023-21768 1 Microsoft 2 Windows 11, Windows Server 2022 2023-01-18 N/A 7.8 HIGH
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability.
CVE-2023-21767 1 Microsoft 8 Windows 10, Windows 11, Windows 8.1 and 5 more 2023-01-18 N/A 7.8 HIGH
Windows Overlay Filter Elevation of Privilege Vulnerability.
CVE-2023-21771 1 Microsoft 3 Windows 10, Windows 11, Windows Server 2022 2023-01-18 N/A 7.0 HIGH
Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability.