CWE-591
77 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-591page 2 of 2
- CVE-2024-49091HIGHCVSS 7.2EG 7.22024-12-12
Windows Domain Name Service Remote Code Execution Vulnerability
- CVE-2024-49095HIGHCVSS 7.0EG 7.02024-12-12
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
- CVE-2024-49097HIGHCVSS 7.0EG 7.02024-12-12
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
- CVE-2024-49106HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2024-49108HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2024-49115HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2024-49123HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2024-49126HIGHCVSS 8.1EG 8.12024-12-12
Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
- CVE-2024-49128HIGHCVSS 8.1EG 8.12024-12-12
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- CVE-2024-49132HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2025-11711MEDIUMCVSS 6.5EG 6.52025-10-14
There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
- CVE-2025-21224HIGHCVSS 8.1EG 8.12025-01-14
Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
- CVE-2025-21294HIGHCVSS 8.1EG 8.12025-01-14
Microsoft Digest Authentication Remote Code Execution Vulnerability
- CVE-2025-21309HIGHCVSS 8.1EG 8.12025-01-14
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2025-24035HIGHCVSS 8.1EG 8.12025-03-11
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- CVE-2025-24045HIGHCVSS 8.1EG 8.12025-03-11
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- CVE-2025-26648HIGHCVSS 7.8EG 7.82025-04-08
Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2025-26665HIGHCVSS 7.0EG 7.02025-04-08
Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate privileges locally.
- CVE-2025-26671HIGHCVSS 8.1EG 8.12025-04-08
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- CVE-2025-26686HIGHCVSS 7.5EG 7.52025-04-08
Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
- CVE-2025-27471MEDIUMCVSS 5.9EG 5.92025-04-08
Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network.
- CVE-2025-27475HIGHCVSS 7.0EG 7.02025-04-08
Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally.
- CVE-2025-27482HIGHCVSS 8.1EG 8.12025-04-08
Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
- CVE-2025-27484HIGHCVSS 7.5EG 7.52025-04-08
Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over a network.
- CVE-2025-27732HIGHCVSS 7.0EG 7.02025-04-08
Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
- CVE-2025-30394MEDIUMCVSS 5.9EG 5.92025-05-13
Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.
- CVE-2025-48819HIGHCVSS 7.1EG 7.12025-07-08
Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network.
Map vulnerabilities like CWE-591 to your infrastructure
EchelonGraph correlates every CVE — across CWE-591 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →