Known vulnerabilities in Windows Server - page 2

Vendor: Microsoft
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 6300
Public exploits: 488
Known exploited (KEV): 268
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Windows Server Windows Server is affected by 6300 known vulnerabilities: 95 critical, 1270 high, 1244 medium, 3689 low Critical High Medium Low

Vulnerabilities (6300)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU137969 - Allocation of Resources Without Limits or Throttling
CVE-2026-49788
CWE-770 Medium
No
No
2012 R2 6.3.9600.23291, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137968 - Allocation of Resources Without Limits or Throttling
CVE-2026-49787
CWE-770 Medium
No
No
2012 R2 6.3.9600.23291, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137967 - Improper Access Control
CVE-2026-49783
CWE-284 Low
No
No
2012 R2 6.3.9600.23291, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137966 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-49183
CWE-362 Low
No
No
2012 R2 6.3.9600.23291, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137965 - Heap-based Buffer Overflow
CVE-2026-49184
CWE-122 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137964 - Integer underflow
CVE-2026-49181
CWE-191 Medium
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137963 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-49180
CWE-59 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137962 - Heap-based Buffer Overflow
CVE-2026-49178
CWE-122 Medium
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137961 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-44800
CWE-362 Low
No
No
2012 R2 6.3.9600.23291, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137959 - Uncontrolled Memory Allocation
CVE-2026-40378
CWE-789 Medium
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137958 - Missing Release of Resource after Effective Lifetime
CVE-2026-44806
CWE-772 Medium
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137957 - Protection Mechanism Failure
CVE-2026-34348
CWE-693 Low
No
No
2012 R2 6.3.9600.23291, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137956 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-40400
CWE-22 High
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137955 - Exposure of sensitive information to an unauthorized actor
CVE-2026-34328
CWE-200 Low
No
No
2012 R2 6.3.9600.23291, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137954 - Heap-based Buffer Overflow
CVE-2026-58640
CWE-122 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137953 - Command injection
CVE-2026-58635
CWE-77 Low
No
No
2012 R2 6.3.9600.23291, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137952 - Out-of-bounds read
CVE-2026-58609
CWE-125 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137951 - Use After Free
CVE-2026-58608
CWE-416 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137950 - NULL Pointer Dereference
CVE-2026-57976
CWE-476 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137949 - Untrusted Search Path
CVE-2026-57097
CWE-426 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705


Showing elements 21 - 40 out of 6300