Known vulnerabilities in Windows Server - page 51

Vendor: Microsoft
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 6300
Public exploits: 488
Known exploited (KEV): 268
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Windows Server Windows Server is affected by 6300 known vulnerabilities: 95 critical, 1270 high, 1244 medium, 3689 low Critical High Medium Low

Vulnerabilities (6300)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU117108 - Improper Enforcement of Behavioral Workflow
CVE-2025-55337
CWE-841 Low
No
No
2012 R2 6.3.9600.22824, 2025 10.0.26100.6899 14.10.2025 SB2025101495
#VU117107 - Improper Enforcement of Behavioral Workflow
CVE-2025-55332
CWE-841 Low
No
No
2012 R2 6.3.9600.22824, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 14.10.2025 SB2025101495
#VU117106 - Improper Enforcement of Behavioral Workflow
CVE-2025-55330
CWE-841 Low
No
No
2012 R2 6.3.9600.22824, 2022 23H2 10.0.25398.1913, 2025 10.0.26100.6899 14.10.2025 SB2025101495
#VU117104 - Security Features
CVE-2025-55338
CWE-254 Low
No
No
2012 R2 6.3.9600.22824, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 14.10.2025 SB2025101495
#VU117095 - Improper Access Control
CVE-2025-55694
CWE-284 Low
No
No
2012 R2 6.3.9600.22824, 2022 23H2 10.0.25398.1913, 2025 10.0.26100.6899 14.10.2025 SB2025101491
#VU117092 - Improper input validation
CVE-2025-55692
CWE-20 Low
No
No
2012 R2 6.3.9600.22824, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 14.10.2025 SB2025101491
#VU117088 - Out-of-bounds read
CVE-2025-55695
CWE-125 Low
No
No
2008 R2 6.1.7601.27974, 2008 6.0.6003.23571, 2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 14.10.2025 SB2025101488
#VU117087 - Improper Access Control
CVE-2025-58714
CWE-284 Low
No
No
2008 R2 6.1.7601.27974, 2008 6.0.6003.23571, 2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 14.10.2025 SB2025101487
#VU117086 - Heap-based Buffer Overflow
CVE-2025-59242
CWE-122 Low
No
No
2008 R2 6.1.7601.27974, 2008 6.0.6003.23571, 2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 14.10.2025 SB2025101487
#VU117085 - Information Exposure Through Log Files
CVE-2025-59258
CWE-532 Low
No
No
2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 14.10.2025 SB2025101486
#VU117084 - Improper Access Control
CVE-2025-58726
CWE-284 Medium
No
No
2008 R2 6.1.7601.27974, 2008 6.0.6003.23571, 2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 14.10.2025 SB2025101485
#VU117070 - Double Free
CVE-2025-59289
CWE-415 Low
No
No
2012 R2 6.3.9600.22824, 2022 23H2 10.0.25398.1849, 2022 10.0.20348.4106, 2022 10.0.20348.4171, 2025 10.0.26100.6508, 2025 10.0.26100.6584 14.10.2025 SB2025101478
#VU117069 - Use After Free
CVE-2025-59290
CWE-416 Low
No
No
2012 R2 6.3.9600.22824, 2022 23H2 10.0.25398.1849, 2022 10.0.20348.4106, 2022 10.0.20348.4171, 2025 10.0.26100.6508, 2025 10.0.26100.6584 14.10.2025 SB2025101478
#VU117068 - Use After Free
CVE-2025-58728
CWE-416 Low
No
No
2012 R2 6.3.9600.22824, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2025 10.0.26100.6899 14.10.2025 SB2025101478
#VU117065 - Improper Access Control
CVE-2025-59253
CWE-284 Low
No
No
2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 14.10.2025 SB2025101477
#VU117064 - Improper input validation
CVE-2025-59198
CWE-20 Medium
No
No
2008 R2 6.1.7601.27974, 2008 6.0.6003.23571, 2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 14.10.2025 SB2025101477
#VU117063 - Improper input validation
CVE-2025-59190
CWE-20 Medium
No
No
2008 R2 6.1.7601.27974, 2008 6.0.6003.23571, 2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 14.10.2025 SB2025101477
#VU117057 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-59193
CWE-362 Low
No
No
2012 R2 6.3.9600.22824, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 14.10.2025 SB2025101474
#VU117056 - Use of Uninitialized Resource
CVE-2025-59204
CWE-908 Low
No
No
2012 R2 6.3.9600.22824, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 14.10.2025 SB2025101474
#VU117049 - Use After Free
CVE-2025-49708
CWE-416 Medium
No
No
2012 R2 6.3.9600.22824, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 14.10.2025 SB2025101472


Showing elements 1001 - 1020 out of 6300