Known vulnerabilities in Windows Server 2022 20H2 - page 3

Vendor: Microsoft
Version: 2022 20H2
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 943
Public exploits: 37
Known exploited (KEV): 41
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Windows Server version 2022 20H2 Windows Server 2022 20H2 is affected by 943 vulnerabilities: 21 critical, 185 high, 267 medium, 470 low Critical High Medium Low

Vulnerabilities (943)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU112576 - NULL Pointer Dereference
CVE-2025-49694
CWE-476 Low
No
No
2022 23H2 10.0.25398.1732, 2025 10.0.26100.4652, 2025 10.0.26200.4349 09.07.2025 SB2025070913
#VU112575 - Double Free
CVE-2025-49693
CWE-415 Low
No
No
2022 23H2 10.0.22621.5472, 2022 23H2 10.0.25398.1732, 2025 10.0.26100.4652 09.07.2025 SB2025070913
#VU112476 - Integer overflow
CVE-2025-48002
CWE-190 Medium
No
No
2022 23H2 10.0.22621.5472, 2025 10.0.26100.4652 08.07.2025 SB2025070840
#VU109100 - Use After Free
CVE-2025-29970
CWE-416 Low
No
No
2012 R2 6.3.9600.22577, 2022 23H2 10.0.25398.1611, 2025 10.0.26100.3981, 2025 10.0.26100.4061 13.05.2025 SB20250513102
#VU109094 - Improper input validation
CVE-2025-29955
CWE-20 Low
No
No
2012 R2 6.3.9600.22577, 2022 23H2 10.0.25398.1611, 2025 10.0.26100.3981, 2025 10.0.26100.4061 13.05.2025 SB2025051396
#VU105851 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2025-9491
CWE-451 High
Public exploit available
Exploited
2008 R2 6.1.7601.28021, 2008 6.0.6003.23624, 2012 R2 6.3.9600.22869, 2012 6.2.9200.25768, 2016 10.0.14393.8594, 2019 10.0.17763.8027, 2022 23H2 10.0.25398.1965, 2022 10.0.20348.4346, 2022 10.0.20348.4405, 2025 10.0.26100.7092, 2025 10.0.26100.7171 18.03.2025 SB2025031863
#VU95526 - Improper Access Control
CVE-2024-38202
CWE-284 Low
No
No
- 08.08.2024 SB2024080808
#VU95525 - Improper Access Control
CVE-2024-21302
CWE-284 Low
No
No
- 08.08.2024 SB2024080807
#VU88432 - Stack-based buffer overflow
CVE-2024-23593
CWE-121 Low
No
No
- 10.04.2024 SB2024041075
SB2025061025
#VU88431 - Stack-based buffer overflow
CVE-2024-23594
CWE-121 Low
No
No
- 10.04.2024 SB2024041075
SB2025061025
#VU88429 - Resource exhaustion
CVE-2024-26215
CWE-400 Medium
No
No
- 10.04.2024 SB2024041073
#VU88428 - Heap-based Buffer Overflow
CVE-2024-26229
CWE-122 Low
Public exploit available
No
- 10.04.2024 SB2024041072
#VU88427 - Authorization Bypass Through User-Controlled Key
CVE-2024-20665
CWE-639 Low
No
No
- 10.04.2024 SB2024041071
#VU88425 - Out-of-bounds read
CVE-2024-26172
CWE-125 Low
No
No
- 10.04.2024 SB2024041068
#VU88422 - Heap-based Buffer Overflow
CVE-2024-26214
CWE-122 High
No
No
- 10.04.2024 SB2024041065
#VU88421 - Improper Link Resolution Before File Access ('Link Following')
CVE-2024-26158
CWE-59 Low
No
No
- 10.04.2024 SB2024041064
#VU88419 - Improper input validation
CVE-2024-26253
CWE-20 Low
No
No
- 10.04.2024 SB2024041062
#VU88418 - Untrusted Pointer Dereference
CVE-2024-26252
CWE-822 Low
No
No
- 10.04.2024 SB2024041062
#VU88417 - Protection Mechanism Failure
CVE-2024-20669
CWE-693 Low
No
No
- 10.04.2024 SB2024041061
#VU88391 - Improper Access Control
CVE-2024-28922
CWE-284 Low
No
No
- 10.04.2024 SB2024041061


Showing elements 41 - 60 out of 943