Known vulnerabilities in Windows Server - page 78

Vendor: Microsoft
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 6300
Public exploits: 488
Known exploited (KEV): 268
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Windows Server Windows Server is affected by 6300 known vulnerabilities: 95 critical, 1270 high, 1244 medium, 3689 low Critical High Medium Low

Vulnerabilities (6300)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU103775 - Out-of-bounds read
CVE-2025-21254
CWE-125 Medium
No
No
2016 10.0.14393.7785, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3148, 2022 10.0.20348.3207, 2025 10.0.26100.3107, 2025 10.0.26100.3194 11.02.2025 SB2025021189
#VU103774 - Exposure of sensitive information to an unauthorized actor
CVE-2025-21377
CWE-200 Medium
No
Exploited
2008 R2 6.1.7601.27566, 2008 6.0.6003.23117, 2012 R2 6.3.9600.22417, 2012 6.2.9200.25317, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3148, 2022 10.0.20348.3207, 2025 10.0.26100.3107, 2025 10.0.26100.3194 11.02.2025 SB2025021188
#VU103773 - Resource exhaustion
CVE-2025-21352
CWE-400 Medium
No
No
2008 R2 6.1.7601.27566, 2008 6.0.6003.23117, 2012 R2 6.3.9600.22417, 2012 6.2.9200.25317, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3148, 2022 10.0.20348.3207, 2025 10.0.26100.3107, 2025 10.0.26100.3194 11.02.2025 SB2025021189
#VU102876 - Incorrect Permission Assignment for Critical Resource
CVE-2025-21325
CWE-732 Low
No
No
2016 10.0.14393.7785, 2025 10.0.26100.2894 17.01.2025 SB2025011705
#VU102806 - Improper input validation
CVE-2024-7344
CWE-20 Low
No
No
2012 R2 6.3.9600.22371, 2012 6.2.9200.25273, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1369, 2022 10.0.20348.3091, 2025 10.0.26100.2894 15.01.2025 SB2025011550
SB2025061025
#VU102803 - Exposure of sensitive information to an unauthorized actor
CVE-2025-21308
CWE-200 Medium
No
No
2012 R2 6.3.9600.22371, 2012 6.2.9200.25273, 2016 10.0.14393.7699, 2022 10.0.20348.3091, 2025 10.0.26100.2894 15.01.2025 SB2025011547
#VU102802 - Use After Free
CVE-2025-21295
CWE-416 High
No
No
2008 R2 6.1.7601.27520, 2012 R2 6.3.9600.22371, 2012 6.2.9200.25273, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1369, 2022 10.0.20348.3091, 2025 10.0.26100.2894 15.01.2025 SB2025011546
#VU102794 - Out-of-bounds read
CVE-2025-21215
CWE-125 Low
No
No
2008 R2 6.1.7601.27520, 2008 6.0.6003.23070, 2012 R2 6.3.9600.22371, 2012 6.2.9200.25273, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1369, 2022 10.0.20348.3091, 2025 10.0.26100.2894 15.01.2025 SB2025011541
#VU102793 - Protection Mechanism Failure
CVE-2025-21211
CWE-693 Low
No
No
2012 R2 6.3.9600.22371, 2012 6.2.9200.25273, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1369, 2022 10.0.20348.3091, 2025 10.0.26100.2894 15.01.2025 SB2025011541
#VU102792 - Improper Access Control
CVE-2025-21213
CWE-284 Low
No
No
2012 R2 6.3.9600.22371, 2012 6.2.9200.25273, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1369, 2022 10.0.20348.3091, 2025 10.0.26100.2894 15.01.2025 SB2025011541
#VU102791 - Improper Resolution of Path Equivalence
CVE-2025-21219
CWE-41 Low
No
No
2016 10.0.14393.7785, 2022 23H2 10.0.25398.1369, 2022 10.0.20348.3091 15.01.2025 SB2025011540
#VU102790 - Improper Resolution of Path Equivalence
CVE-2025-21329
CWE-41 Low
No
No
2008 R2 6.1.7601.27520, 2008 6.0.6003.23070, 2012 R2 6.3.9600.22371, 2012 6.2.9200.25273, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1369, 2022 10.0.20348.3091, 2025 10.0.26100.2894 15.01.2025 SB2025011540
#VU102789 - Improper Resolution of Path Equivalence
CVE-2025-21328
CWE-41 Low
No
No
2008 R2 6.1.7601.27520, 2008 6.0.6003.23070, 2012 R2 6.3.9600.22371, 2012 6.2.9200.25273, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1369, 2022 10.0.20348.3091 15.01.2025 SB2025011540
#VU102787 - Use After Free
CVE-2025-21298
CWE-416 High
Available
No
2008 R2 6.1.7601.27520, 2008 6.0.6003.23070, 2012 R2 6.3.9600.22371, 2012 6.2.9200.25273, 2016 10.0.14393.7699, 2022 23H2 10.0.25398.1369, 2022 10.0.20348.3091, 2025 10.0.26100.2894 15.01.2025 SB2025011538
#VU102783 - Resource exhaustion
CVE-2025-21231
CWE-400 Medium
No
No
2008 R2 6.1.7601.27520, 2008 6.0.6003.23070, 2012 R2 6.3.9600.22371, 2012 6.2.9200.25273, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1369, 2022 10.0.20348.3091, 2025 10.0.26100.2894 15.01.2025 SB2025011529
#VU102782 - Improper Resolution of Path Equivalence
CVE-2025-21269
CWE-41 Low
No
No
2008 R2 6.1.7601.27520, 2008 6.0.6003.23070, 2012 R2 6.3.9600.22371, 2012 6.2.9200.25273, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1369, 2022 10.0.20348.3091 15.01.2025 SB2025011528
#VU102781 - Cross-Site Request Forgery (CSRF)
CVE-2025-21193
CWE-352 Low
No
No
2016 10.0.14393.7699, 2016 10.0.14393.7785, 2019 10.0.17763.6775, 2022 23H2 10.0.25398.1369, 2022 10.0.20348.3091, 2025 10.0.26100.2894 15.01.2025 SB2025011527
#VU102780 - Use After Free
CVE-2025-21307
CWE-416 High
No
No
2008 R2 6.1.7601.27520, 2008 6.0.6003.23070, 2012 R2 6.3.9600.22371, 2012 6.2.9200.25273, 2016 10.0.14393.7699, 2022 23H2 10.0.25398.1369, 2022 10.0.20348.3091, 2025 10.0.26100.2894 15.01.2025 SB2025011526
#VU102779 - Exposure of sensitive information to an unauthorized actor
CVE-2025-21336
CWE-200 Low
No
No
2008 R2 6.1.7601.27520, 2008 6.0.6003.23070, 2012 R2 6.3.9600.22371, 2012 6.2.9200.25273, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1369, 2022 10.0.20348.3091, 2025 10.0.26100.2894 15.01.2025 SB2025011525
#VU102778 - Incorrect Implementation of Authentication Algorithm
CVE-2025-21311
CWE-303 High
No
No
2016 10.0.14393.7699, 2022 23H2 10.0.25398.1369, 2025 10.0.26100.2894 15.01.2025 SB2025011524


Showing elements 1541 - 1560 out of 6300