Known vulnerabilities in Windows Server - page 41

Vendor: Microsoft
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 6300
Public exploits: 488
Known exploited (KEV): 268
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Windows Server Windows Server is affected by 6300 known vulnerabilities: 95 critical, 1270 high, 1244 medium, 3689 low Critical High Medium Low

Vulnerabilities (6300)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU121332 - Out-of-bounds read
CVE-2026-20828
CWE-125 Low
No
No
2008 R2 6.1.7601.28117, 2008 6.0.6003.23717, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113130
#VU121331 - Out-of-bounds read
CVE-2026-20829
CWE-125 Low
No
No
2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113129
#VU121330 - Heap-based Buffer Overflow
CVE-2026-20837
CWE-122 High
No
No
2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113128
#VU121329 - Improper Access Control
CVE-2026-20839
CWE-284 Low
No
No
2008 R2 6.1.7601.28117, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113127
#VU121328 - Use After Free
CVE-2026-20871
CWE-416 Low
No
No
2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113126
#VU121323 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2026-20833
CWE-327 Low
No
No
2008 R2 6.1.7601.28117, 2008 6.0.6003.23717, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113123
SB2026031840
#VU121322 - Reliance on Untrusted Inputs in a Security Decision
CVE-2026-20849
CWE-807 Medium
No
No
2008 R2 6.1.7601.28117, 2008 6.0.6003.23717, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113123
#VU121321 - Use After Free
CVE-2026-20923
CWE-416 Low
No
No
2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113122
#VU121320 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-20918
CWE-362 Low
No
No
2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113122
#VU121319 - Use After Free
CVE-2026-20877
CWE-416 Low
No
No
2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113122
#VU121318 - Use After Free
CVE-2026-20865
CWE-416 Low
No
No
2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113122
#VU121317 - Use After Free
CVE-2026-20858
CWE-416 Low
No
No
2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113122
#VU121300 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-20873
CWE-362 Low
No
No
2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113122
#VU121299 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-20874
CWE-362 Low
No
No
2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113122
#VU121298 - Use After Free
CVE-2026-20924
CWE-416 Low
No
No
2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113122
#VU121297 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-20867
CWE-362 Low
No
No
2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113122
#VU121296 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-20861
CWE-362 Low
No
No
2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113122
#VU121294 - Exposure of sensitive information to an unauthorized actor
CVE-2026-20862
CWE-200 Low
No
No
2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113122
#VU121293 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-20866
CWE-362 Low
No
No
2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113122
#VU121278 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-20941
CWE-59 Low
No
No
2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB2026011398


Showing elements 801 - 820 out of 6300