Known vulnerabilities in Windows Server - page 29

Vendor: Microsoft
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 6300
Public exploits: 488
Known exploited (KEV): 268
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Windows Server Windows Server is affected by 6300 known vulnerabilities: 95 critical, 1270 high, 1244 medium, 3689 low Critical High Medium Low

Vulnerabilities (6300)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU131216 - Type confusion
CVE-2026-35417
CWE-843 Low
No
No
2019 10.0.17763.8755, 2022 23H2 10.0.25398.2330, 2022 10.0.20348.5074, 2022 10.0.20348.5139, 2025 10.0.26100.32772, 2025 10.0.26100.32860 12.05.2026 SB20260512102
#VU131215 - Use After Free
CVE-2026-34347
CWE-416 Low
No
No
2012 R2 6.3.9600.23181, 2012 6.2.9200.26079, 2016 10.0.14393.9140, 2019 10.0.17763.8755, 2022 23H2 10.0.25398.2330, 2022 10.0.20348.5074, 2022 10.0.20348.5139, 2025 10.0.26100.32772, 2025 10.0.26100.32860 12.05.2026 SB20260512102
#VU131213 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-34331
CWE-362 Low
No
No
2012 R2 6.3.9600.23181, 2012 6.2.9200.26079, 2016 10.0.14393.9140, 2019 10.0.17763.8755, 2022 23H2 10.0.25398.2330, 2022 10.0.20348.5074, 2022 10.0.20348.5139, 2025 10.0.26100.32772, 2025 10.0.26100.32860 12.05.2026 SB20260512101
#VU131212 - Integer overflow
CVE-2026-34330
CWE-190 Low
No
No
2012 R2 6.3.9600.23181, 2012 6.2.9200.26079, 2016 10.0.14393.9140, 2019 10.0.17763.8755, 2022 23H2 10.0.25398.2330, 2022 10.0.20348.5074, 2022 10.0.20348.5139, 2025 10.0.26100.32772, 2025 10.0.26100.32860 12.05.2026 SB20260512101
#VU131211 - Use After Free
CVE-2026-33840
CWE-416 Low
No
No
2025 10.0.26100.32772, 2025 10.0.26100.32860 12.05.2026 SB20260512101
#VU131210 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-33839
CWE-362 Low
No
No
2019 10.0.17763.8755, 2022 23H2 10.0.25398.2330, 2022 10.0.20348.5074, 2022 10.0.20348.5139, 2025 10.0.26100.32772, 2025 10.0.26100.32860 12.05.2026 SB20260512101
#VU131209 - Improper Access Control
CVE-2026-33834
CWE-284 Low
No
No
2012 R2 6.3.9600.23181, 2012 6.2.9200.26079, 2016 10.0.14393.9140, 2019 10.0.17763.8755, 2022 23H2 10.0.25398.2330, 2022 10.0.20348.5074, 2022 10.0.20348.5139, 2025 10.0.26100.32772, 2025 10.0.26100.32860 12.05.2026 SB20260512100
#VU131208 - Double Free
CVE-2026-32170
CWE-415 Medium
No
No
2012 R2 6.3.9600.23181, 2012 6.2.9200.26079, 2016 10.0.14393.9140, 2019 10.0.17763.8755, 2022 23H2 10.0.25398.2330, 2022 10.0.20348.5139, 2025 10.0.26100.32772, 2025 10.0.26100.32860 12.05.2026 SB2026051299
#VU131207 - Double Free
CVE-2026-21530
CWE-415 Medium
No
No
2012 R2 6.3.9600.23181, 2012 6.2.9200.26079, 2016 10.0.14393.9140, 2019 10.0.17763.8755, 2022 23H2 10.0.25398.2330, 2022 10.0.20348.5139, 2025 10.0.26100.32860 12.05.2026 SB2026051299
#VU126306 - Missing Required Cryptographic Step
CVE-2026-25250
CWE-325 Low
No
No
2012 R2 6.3.9600.23132, 2012 6.2.9200.26026, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 16.04.2026 SB2026041622
#VU126261 - Memory corruption
CVE-2023-20585
CWE-119 Low
No
No
2012 R2 6.3.9600.23132, 2025 10.0.26100.32690 16.04.2026 SB2026041617
SB2026052679
SB2026053002
and 7 more
#VU126224 - Use After Free
CVE-2026-32070
CWE-416 Low
No
No
2012 R2 6.3.9600.23132, 2012 6.2.9200.26026, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB20260415145
#VU126223 - Improper input validation
CVE-2026-27913
CWE-20 Low
No
No
2012 R2 6.3.9600.23132, 2012 6.2.9200.26026, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020 15.04.2026 SB20260415144
#VU126222 - Improper Handling of Insufficient Permissions or Privileges
CVE-2026-27910
CWE-280 Low
No
No
2012 R2 6.3.9600.23132, 2012 6.2.9200.26026, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB20260415143
#VU126221 - Exposure of sensitive information to an unauthorized actor
CVE-2026-32081
CWE-200 Low
No
No
2012 R2 6.3.9600.23132, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB20260415142
#VU126220 - Insufficient UI Warning of Dangerous Operations
CVE-2026-26151
CWE-357 High
No
No
2012 R2 6.3.9600.23132, 2012 6.2.9200.26026, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB20260415141
#VU126219 - Double Free
CVE-2026-33824
CWE-415 High
Available
No
2012 R2 6.3.9600.23132, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB20260415140
#VU126218 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-33827
CWE-362 High
No
No
2012 R2 6.3.9600.23132, 2012 6.2.9200.26026, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB20260415139
#VU126217 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-33104
CWE-362 Low
No
No
2012 R2 6.3.9600.23132, 2012 6.2.9200.26026, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB20260415138
#VU126215 - Improper Authentication
CVE-2026-32072
CWE-287 Low
No
No
2012 R2 6.3.9600.23132, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB20260415136


Showing elements 561 - 580 out of 6300