Known vulnerabilities in Windows Server - page 40

Vendor: Microsoft
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 6300
Public exploits: 488
Known exploited (KEV): 268
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Windows Server Windows Server is affected by 6300 known vulnerabilities: 95 critical, 1270 high, 1244 medium, 3689 low Critical High Medium Low

Vulnerabilities (6300)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU121446 - Heap-based Buffer Overflow
CVE-2024-55414
CWE-122 Low
No
No
2008 R2 6.1.7601.28117, 2008 6.0.6003.23717, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011498
#VU121445 - External Control of File Name or Path
CVE-2026-20931
CWE-73 Medium
No
No
2008 R2 6.1.7601.28117, 2008 6.0.6003.23717, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011497
#VU121439 - Exposure of sensitive information to an unauthorized actor
CVE-2026-20823
CWE-200 Low
No
No
2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011492
#VU121438 - Exposure of sensitive information to an unauthorized actor
CVE-2026-20932
CWE-200 Low
No
No
2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011492
#VU121437 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-20808
CWE-362 Low
No
No
2022 23H2 10.0.25398.2092, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011492
#VU121435 - Exposure of sensitive information to an unauthorized actor
CVE-2026-20937
CWE-200 Low
No
No
2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011492
#VU121434 - Exposure of sensitive information to an unauthorized actor
CVE-2026-20939
CWE-200 Low
No
No
2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011492
#VU121417 - Use After Free
CVE-2026-20870
CWE-416 Low
No
No
2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011470
#VU121405 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-20869
CWE-362 Low
No
No
2008 R2 6.1.7601.28117, 2008 6.0.6003.23717, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011458
#VU121391 - Heap-based Buffer Overflow
CVE-2026-20864
CWE-122 Low
No
No
2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011444
#VU121387 - Improper input validation
CVE-2026-20856
CWE-20 High
No
No
2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011440
#VU121369 - Incorrect Privilege Assignment
CVE-2026-20852
CWE-266 Low
No
No
2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011422
#VU121368 - Incorrect Privilege Assignment
CVE-2026-20804
CWE-266 Low
No
No
2008 R2 6.1.7601.28117, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.32230 14.01.2026 SB2026011422
#VU121363 - Exposure of sensitive information to an unauthorized actor
CVE-2026-20847
CWE-200 Medium
No
No
2008 R2 6.1.7601.28117, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011417
#VU121357 - Use After Free
CVE-2026-20844
CWE-416 Low
No
No
2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011411
#VU121350 - Use After Free
CVE-2026-20842
CWE-416 Low
No
No
2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011403
#VU121348 - Reliance on Component That is Not Updateable
CVE-2026-21265
CWE-1329 Low
No
No
2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.32230 14.01.2026 SB2026011401
#VU121345 - Heap-based Buffer Overflow
CVE-2026-20922
CWE-122 Medium
No
No
2008 R2 6.1.7601.28117, 2008 6.0.6003.23717, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113132
#VU121344 - Heap-based Buffer Overflow
CVE-2026-20840
CWE-122 Medium
No
No
2008 R2 6.1.7601.28117, 2008 6.0.6003.23717, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113132
#VU121333 - Protection Mechanism Failure
CVE-2026-20824
CWE-693 Medium
No
No
2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113131


Showing elements 781 - 800 out of 6300