Known vulnerabilities in Windows Server 2025 10.0.26100.2605 - page 47

Vendor: Microsoft
Version: 2025 10.0.26100.2605
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 1627
Public exploits: 49
Known exploited (KEV): 38
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Windows Server version 2025 10.0.26100.2605 Windows Server 2025 10.0.26100.2605 is affected by 1627 vulnerabilities: 7 critical, 263 high, 300 medium, 1056 low Critical High Medium Low

Vulnerabilities (1627)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU117235 - Exposure of sensitive information to an unauthorized actor
CVE-2025-59284
CWE-200 Medium
Public exploit available
No
2012 R2 6.3.9600.22824, 2025 10.0.26100.6899 15.10.2025 SB2025101592
#VU117233 - Use of a Key Past its Expiration Date
CVE-2025-48813
CWE-324 Low
No
No
2012 R2 6.3.9600.22824, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101590
#VU117230 - Buffer over-read
CVE-2025-59192
CWE-126 Low
No
No
2012 R2 6.3.9600.22824, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101587
#VU117229 - NULL Pointer Dereference
CVE-2025-55698
CWE-476 Medium
No
No
2012 R2 6.3.9600.22824, 2025 10.0.26100.6899 15.10.2025 SB2025101586
#VU117228 - Use After Free
CVE-2025-55678
CWE-416 Low
No
No
2008 R2 6.1.7601.27974, 2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101586
#VU117225 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-59282
CWE-362 Medium
No
No
2008 R2 6.1.7601.27974, 2008 6.0.6003.23571, 2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101584
#VU117224 - Use After Free
CVE-2025-59202
CWE-416 Low
No
No
2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101583
#VU117223 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-59200
CWE-362 Low
No
No
2012 R2 6.3.9600.22824, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101582
#VU117222 - Deserialization of Untrusted Data
CVE-2025-59287
CWE-502 Critical
Public exploit available
Exploited
2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101581
#VU117221 - Improper Authentication
CVE-2025-55340
CWE-287 Low
No
No
2012 R2 6.3.9600.22824, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101580
#VU117218 - Use After Free
CVE-2025-59210
CWE-416 Low
No
No
2012 R2 6.3.9600.22824, 2025 10.0.26100.6899 15.10.2025 SB2025101577
#VU117212 - Information Exposure Through Log Files
CVE-2025-59203
CWE-532 Low
No
No
2012 R2 6.3.9600.22824, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101571
#VU117206 - Information Exposure Through Log Files
CVE-2025-59197
CWE-532 Low
No
No
2012 R2 6.3.9600.22824, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101564
#VU117204 - Resource exhaustion
CVE-2025-59502
CWE-400 Medium
No
No
2012 R2 6.3.9600.22824, 2019 10.0.17763.7792, 2022 23H2 10.0.25398.1849, 2022 10.0.20348.4106, 2022 10.0.20348.4171, 2025 10.0.26100.6508, 2025 10.0.26100.6584 15.10.2025 SB2025101562
#VU117203 - Heap-based Buffer Overflow
CVE-2025-59295
CWE-122 High
No
No
2008 R2 6.1.7601.27974, 2008 6.0.6003.23571, 2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101561
#VU117202 - Exposure of sensitive information to an unauthorized actor
CVE-2025-59294
CWE-200 Low
No
No
2012 R2 6.3.9600.22824, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101560
#VU117199 - Improper Authentication
CVE-2025-59280
CWE-287 Low
No
No
2008 R2 6.1.7601.27974, 2008 6.0.6003.23571, 2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101557
#VU117198 - Heap-based Buffer Overflow
CVE-2025-59255
CWE-122 Low
No
No
2012 R2 6.3.9600.22824, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101555
#VU117196 - Exposure of sensitive information to an unauthorized actor
CVE-2025-59211
CWE-200 Low
No
No
2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101548
#VU117195 - Exposure of sensitive information to an unauthorized actor
CVE-2025-59209
CWE-200 Low
No
No
2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101548


Showing elements 921 - 940 out of 1627