Known vulnerabilities in Windows Server 2025 10.0.26100.2605 - page 74

Vendor: Microsoft
Version: 2025 10.0.26100.2605
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 1627
Public exploits: 49
Known exploited (KEV): 38
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Windows Server version 2025 10.0.26100.2605 Windows Server 2025 10.0.26100.2605 is affected by 1627 vulnerabilities: 7 critical, 263 high, 300 medium, 1056 low Critical High Medium Low

Vulnerabilities (1627)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU107993 - Heap-based Buffer Overflow
CVE-2025-26634
CWE-122 Medium
No
No
2008 R2 6.1.7601.27663, 2016 10.0.14393.7785, 2019 10.0.17763.6893, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3207, 2025 10.0.26100.3194 28.04.2025 SB20250311117
#VU105529 - NULL Pointer Dereference
CVE-2025-24997
CWE-476 Low
No
No
2012 R2 6.3.9600.22470, 2022 23H2 10.0.25398.1486, 2022 10.0.20348.3270, 2022 10.0.20348.3328, 2025 10.0.26100.3403, 2025 10.0.26100.3476 11.03.2025 SB2025031169
#VU105528 - Heap-based Buffer Overflow
CVE-2025-24995
CWE-122 Low
No
No
2012 R2 6.3.9600.22470, 2016 10.0.14393.7876, 2019 10.0.17763.7009, 2022 23H2 10.0.25398.1486, 2022 10.0.20348.3270, 2022 10.0.20348.3328, 2025 10.0.26100.3403, 2025 10.0.26100.3476 11.03.2025 SB2025031168
#VU105527 - Untrusted Pointer Dereference
CVE-2025-24084
CWE-822 High
No
No
2012 R2 6.3.9600.22470, 2022 23H2 10.0.25398.1486, 2022 10.0.20348.3270, 2022 10.0.20348.3328, 2025 10.0.26100.3403, 2025 10.0.26100.3476 11.03.2025 SB2025031167
#VU105526 - Improper Access Control
CVE-2025-24076
CWE-284 Low
Public exploit available
No
2012 R2 6.3.9600.22470, 2022 23H2 10.0.25398.1486, 2025 10.0.26100.3403, 2025 10.0.26100.3476 11.03.2025 SB2025031166
#VU105524 - Heap-based Buffer Overflow
CVE-2025-24051
CWE-122 High
No
No
2008 R2 6.1.7601.27618, 2008 6.0.6003.23168, 2012 R2 6.3.9600.22470, 2012 6.2.9200.25368, 2016 10.0.14393.7876, 2019 10.0.17763.7009, 2022 23H2 10.0.25398.1486, 2022 10.0.20348.3270, 2022 10.0.20348.3328, 2025 10.0.26100.3403, 2025 10.0.26100.3476 11.03.2025 SB2025031165
#VU105521 - Sensitive Data Storage in Improperly Locked Memory
CVE-2025-24035
CWE-591 High
No
No
2008 R2 6.1.7601.27618, 2008 6.0.6003.23168, 2012 R2 6.3.9600.22470, 2012 6.2.9200.25368, 2016 10.0.14393.7876, 2019 10.0.17763.7009, 2022 23H2 10.0.25398.1486, 2022 10.0.20348.3270, 2022 10.0.20348.3328, 2025 10.0.26100.3403, 2025 10.0.26100.3476 11.03.2025 SB2025031163
#VU105520 - Sensitive Data Storage in Improperly Locked Memory
CVE-2025-24045
CWE-591 High
No
No
2012 R2 6.3.9600.22470, 2012 6.2.9200.25368, 2016 10.0.14393.7876, 2019 10.0.17763.7009, 2022 23H2 10.0.25398.1486, 2022 10.0.20348.3270, 2022 10.0.20348.3328, 2025 10.0.26100.3403, 2025 10.0.26100.3476 11.03.2025 SB2025031163
#VU105519 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-26645
CWE-22 High
No
No
2008 R2 6.1.7601.27618, 2008 6.0.6003.23168, 2012 R2 6.3.9600.22470, 2012 6.2.9200.25368, 2016 10.0.14393.7876, 2019 10.0.17763.7009, 2022 23H2 10.0.25398.1486, 2022 10.0.20348.3328, 2025 10.0.26100.3476 11.03.2025 SB2025031162
#VU105518 - Improper input validation
CVE-2025-26633
CWE-20 Critical
Public exploit available
Exploited
2008 R2 6.1.7601.27618, 2008 6.0.6003.23168, 2012 R2 6.3.9600.22470, 2012 6.2.9200.25368, 2016 10.0.14393.7876, 2019 10.0.17763.7009, 2022 23H2 10.0.25398.1486, 2022 10.0.20348.3270, 2022 10.0.20348.3328, 2025 10.0.26100.3403, 2025 10.0.26100.3476 11.03.2025 SB2025031161
#VU105517 - Incorrect Conversion between Numeric Types
CVE-2025-24059
CWE-681 Low
No
No
2008 R2 6.1.7601.27618, 2008 6.0.6003.23168, 2012 R2 6.3.9600.22470, 2012 6.2.9200.25368, 2016 10.0.14393.7876, 2019 10.0.17763.7009, 2022 23H2 10.0.25398.1486, 2022 10.0.20348.3270, 2022 10.0.20348.3328, 2025 10.0.26100.3403, 2025 10.0.26100.3476 11.03.2025 SB2025031160
#VU105515 - Information Exposure Through Log Files
CVE-2025-24984
CWE-532 Medium
No
Exploited
2012 R2 6.3.9600.22470, 2012 6.2.9200.25368, 2016 10.0.14393.7876, 2019 10.0.17763.7009, 2022 23H2 10.0.25398.1486, 2022 10.0.20348.3270, 2022 10.0.20348.3328, 2025 10.0.26100.3403, 2025 10.0.26100.3476 11.03.2025 SB2025031158
#VU105514 - Heap-based Buffer Overflow
CVE-2025-24993
CWE-122 High
No
Exploited
2008 R2 6.1.7601.27618, 2008 6.0.6003.23168, 2012 R2 6.3.9600.22470, 2012 6.2.9200.25368, 2016 10.0.14393.7876, 2019 10.0.17763.7009, 2022 23H2 10.0.25398.1486, 2022 10.0.20348.3270, 2022 10.0.20348.3328, 2025 10.0.26100.3403, 2025 10.0.26100.3476 11.03.2025 SB2025031157
#VU105513 - Out-of-bounds read
CVE-2025-24991
CWE-125 High
No
Exploited
2008 R2 6.1.7601.27618, 2008 6.0.6003.23168, 2012 R2 6.3.9600.22470, 2012 6.2.9200.25368, 2016 10.0.14393.7876, 2019 10.0.17763.7009, 2022 23H2 10.0.25398.1486, 2022 10.0.20348.3270, 2022 10.0.20348.3328, 2025 10.0.26100.3403, 2025 10.0.26100.3476 11.03.2025 SB2025031156
#VU105512 - Integer overflow
CVE-2025-24985
CWE-190 High
No
Exploited
2008 R2 6.1.7601.27618, 2008 6.0.6003.23168, 2012 R2 6.3.9600.22470, 2012 6.2.9200.25368, 2016 10.0.14393.7876, 2019 10.0.17763.7009, 2022 23H2 10.0.25398.1486, 2022 10.0.20348.3270, 2022 10.0.20348.3328, 2025 10.0.26100.3403, 2025 10.0.26100.3476 11.03.2025 SB2025031155
#VU103826 - Improper Access Control
CVE-2025-21359
CWE-284 Low
No
No
2008 R2 6.1.7601.27566, 2008 6.0.6003.23117, 2012 R2 6.3.9600.22417, 2012 6.2.9200.25317, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3148, 2022 10.0.20348.3207, 2025 10.0.26100.3107, 2025 10.0.26100.3194 11.02.2025 SB20250211128
#VU103825 - Improper Authentication
CVE-2025-21349
CWE-287 High
No
No
2016 10.0.14393.7785, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3148, 2022 10.0.20348.3207, 2025 10.0.26100.3107, 2025 10.0.26100.3194 11.02.2025 SB20250211127
#VU103823 - Improper input validation
CVE-2025-21375
CWE-20 Low
No
No
2008 R2 6.1.7601.27566, 2008 6.0.6003.23117, 2012 R2 6.3.9600.22417, 2012 6.2.9200.25317, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3148, 2022 10.0.20348.3207, 2025 10.0.26100.3107, 2025 10.0.26100.3194 11.02.2025 SB20250211125
#VU103822 - Improper input validation
CVE-2025-21350
CWE-20 Medium
No
No
2008 R2 6.1.7601.27566, 2008 6.0.6003.23117, 2012 R2 6.3.9600.22417, 2012 6.2.9200.25317, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3148, 2022 10.0.20348.3207, 2025 10.0.26100.3107, 2025 10.0.26100.3194 11.02.2025 SB20250211124
#VU103821 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-21420
CWE-59 Low
Public exploit available
No
2012 R2 6.3.9600.22417, 2012 6.2.9200.25317, 2016 10.0.14393.7785, 2019 10.0.17763.6893, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3148, 2022 10.0.20348.3207, 2025 10.0.26100.3107, 2025 10.0.26100.3194 11.02.2025 SB20250211123


Showing elements 1461 - 1480 out of 1627