Known vulnerabilities in Windows Server - page 51

Vendor: Microsoft
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 7208
Public exploits: 498
Known exploited (KEV): 273
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Windows Server Windows Server is affected by 7208 known vulnerabilities: 95 critical, 1384 high, 1400 medium, 4327 low Critical High Medium Low

Vulnerabilities (7208)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU138042 - Type confusion
CVE-2026-50421
CWE-843 Low
No
No
2012 R2 6.3.9600.23291, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU138041 - Out-of-bounds read
CVE-2026-50422
CWE-125 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU138040 - Use After Free
CVE-2026-50427
CWE-416 Low
No
No
2012 R2 6.3.9600.23291, 2019 10.0.17763.9020, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU138039 - Relative Path Traversal
CVE-2026-50426
CWE-23 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU138038 - Improper Authentication
CVE-2026-50365
CWE-287 Medium
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU138037 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-50454
CWE-22 Low
No
No
2012 R2 6.3.9600.23291, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU138036 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-50469
CWE-59 Low
No
No
2012 R2 6.3.9600.23291, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU138035 - Use After Free
CVE-2026-50369
CWE-416 Medium
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU138034 - Heap-based Buffer Overflow
CVE-2026-50471
CWE-122 High
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU138033 - Out-of-bounds read
CVE-2026-50437
CWE-125 Low
No
No
2012 R2 6.3.9600.23291, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU138032 - Improper Authorization
CVE-2026-50344
CWE-285 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU138031 - Improper Access Control
CVE-2026-50334
CWE-284 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU138030 - Stack-based buffer overflow
CVE-2026-50387
CWE-121 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU138029 - Heap-based Buffer Overflow
CVE-2026-50448
CWE-122 High
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU138028 - Insufficient Granularity of Access Control
CVE-2026-50405
CWE-1220 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU138027 - Use of Uninitialized Resource
CVE-2026-50376
CWE-908 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU138026 - Improper Authorization
CVE-2026-50346
CWE-285 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU138025 - Out-of-bounds read
CVE-2026-50401
CWE-125 Low
No
No
2012 R2 6.3.9600.23291, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU138024 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-50378
CWE-362 Low
No
No
2012 R2 6.3.9600.23291, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU138023 - Improper Access Control
CVE-2026-50418
CWE-284 Low
No
No
2012 R2 6.3.9600.23291, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705


Showing elements 1001 - 1020 out of 7208