Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-591

MITRE ↗

CWE-591

63
HIGH
14
MEDIUM
77 CVEs · Page 1/2
8.1
CVE-2025-21224

Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability

8.1
CVE-2025-21294

Microsoft Digest Authentication Remote Code Execution Vulnerability

8.1
CVE-2025-21309

Windows Remote Desktop Services Remote Code Execution Vulnerability

8.1
CVE-2025-24035

Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to

8.1
CVE-2025-24045

Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to

8.1
CVE-2025-26671

Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

8.1
CVE-2025-27482

Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to

7.8
CVE-2025-26648

Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker to elevate privileges

7.5
CVE-2025-26686

Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code ove

7.5
CVE-2025-27484

Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an autho

7.1
CVE-2025-48819

Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an autho

7.0
CVE-2025-26665

Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate priv

7.0
CVE-2025-27475

Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate priv

7.0
CVE-2025-27732

Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate pri

6.5
CVE-2025-11711

There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnera

5.9
CVE-2025-27471

Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to den

5.9
CVE-2025-30394

Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to

8.8
CVE-2024-38131

Clipboard Virtual Channel Extension Remote Code Execution Vulnerability

8.1
CVE-2024-49106

Windows Remote Desktop Services Remote Code Execution Vulnerability

8.1
CVE-2024-49108

Windows Remote Desktop Services Remote Code Execution Vulnerability

8.1
CVE-2024-49115

Windows Remote Desktop Services Remote Code Execution Vulnerability

8.1
CVE-2024-49123

Windows Remote Desktop Services Remote Code Execution Vulnerability

8.1
CVE-2024-49126

Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability

8.1
CVE-2024-49128

Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to

8.1
CVE-2024-49132

Windows Remote Desktop Services Remote Code Execution Vulnerability

7.8
CVE-2024-20686

Win32k Elevation of Privilege Vulnerability

7.8
CVE-2024-21446

NTFS Elevation of Privilege Vulnerability

7.8
CVE-2024-43563

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

7.5
CVE-2024-38263

Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

7.5
CVE-2024-38262

Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

7.2
CVE-2024-49091

Windows Domain Name Service Remote Code Execution Vulnerability

7.0
CVE-2024-21355

Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability

7.0
CVE-2024-21405

Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability

7.0
CVE-2024-26236

Windows Update Stack Elevation of Privilege Vulnerability

7.0
CVE-2024-26242

Windows Telephony Server Elevation of Privilege Vulnerability

7.0
CVE-2024-38106 KEV

Windows Kernel Elevation of Privilege Vulnerability

7.0
CVE-2024-38137

Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability

7.0
CVE-2024-49095

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

7.0
CVE-2024-49097

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

6.5
CVE-2024-43633

Windows Hyper-V Denial of Service Vulnerability

5.9
CVE-2024-38264

Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability

5.3
CVE-2024-34525

FileCodeBox 2.0 stores a OneDrive password and AWS key in a cleartext env file.

8.1
CVE-2023-21535

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

8.1
CVE-2023-21546

Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability

8.1
CVE-2023-21548

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

8.1
CVE-2023-28219

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-28220

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-28283

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

7.8
CVE-2023-28236

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2023-24946

Windows Backup Service Elevation of Privilege Vulnerability

Frequently Asked Questions

What is CWE-591?

CWE-591 (CWE-591) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-591?

There are 77 CVE records associated with CWE-591 in our database. Of these, 0 are critical severity, 63 are high severity, and 14 are medium severity.

How can I protect against CWE-591 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-591 using AI-powered security agents.

Detect CWE-591 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-591 vulnerabilities across your infrastructure.

Get Started