Known vulnerabilities in Windows Server - page 95

Vendor: Microsoft
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 6300
Public exploits: 488
Known exploited (KEV): 268
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Windows Server Windows Server is affected by 6300 known vulnerabilities: 95 critical, 1270 high, 1244 medium, 3689 low Critical High Medium Low

Vulnerabilities (6300)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU97031 - Use After Free
CVE-2024-38259
CWE-416 High
No
No
2022 23H2 10.0.25398.1128, 2022 10.0.20348.2695, 2022 10.0.20348.2700 10.09.2024 SB20240910107
#VU97025 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2024-43461
CWE-451 Critical
No
Exploited
2008 R2 6.1.7601.27320, 2008 6.0.6003.22870, 2012 R2 6.3.9600.22175, 2012 6.2.9200.25073, 2022 23H2 10.0.25398.1128, 2022 10.0.20348.2695, 2022 10.0.20348.2700 10.09.2024 SB2024091097
#VU97024 - Improper input validation
CVE-2024-38230
CWE-20 Medium
No
No
2012 R2 6.3.9600.22175, 2012 6.2.9200.25073, 2016 10.0.14393.7336, 2019 10.0.17763.6293, 2022 10.0.20348.2695, 2022 10.0.20348.2700 10.09.2024 SB2024091096
#VU97023 - Out-of-bounds read
CVE-2024-38250
CWE-125 Low
No
No
2008 R2 6.1.7601.27320, 2008 6.0.6003.22870, 2012 R2 6.3.9600.22175, 2012 6.2.9200.25073, 2022 23H2 10.0.25398.1128, 2022 10.0.20348.2695, 2022 10.0.20348.2700 10.09.2024 SB2024091095
#VU97022 - Heap-based Buffer Overflow
CVE-2024-38045
CWE-122 High
No
No
2022 23H2 10.0.25398.1128, 2022 10.0.20348.2695, 2022 10.0.20348.2700 10.09.2024 SB2024091094
#VU97021 - Heap-based Buffer Overflow
CVE-2024-21416
CWE-122 High
No
No
2022 23H2 10.0.25398.1128, 2022 10.0.20348.2695, 2022 10.0.20348.2700 10.09.2024 SB2024091094
#VU97020 - Double Free
CVE-2024-38247
CWE-415 Low
No
No
2008 R2 6.1.7601.27320, 2012 R2 6.3.9600.22175, 2012 6.2.9200.25073, 2022 23H2 10.0.25398.1128, 2022 10.0.20348.2695, 2022 10.0.20348.2700 10.09.2024 SB2024091095
#VU97019 - Use After Free
CVE-2024-38249
CWE-416 Low
No
No
2008 R2 6.1.7601.27320, 2008 6.0.6003.22870, 2012 R2 6.3.9600.22175, 2012 6.2.9200.25073, 2022 23H2 10.0.25398.1128, 2022 10.0.20348.2695, 2022 10.0.20348.2700 10.09.2024 SB2024091095
#VU97018 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-38258
CWE-22 Medium
No
No
2008 R2 6.1.7601.27320, 2008 6.0.6003.22870, 2012 R2 6.3.9600.22175, 2012 6.2.9200.25073, 2016 10.0.14393.7336, 2019 10.0.17763.6293, 2022 23H2 10.0.25398.1128, 2022 10.0.20348.2695, 2022 10.0.20348.2700 10.09.2024 SB2024091093
#VU97017 - Improper input validation
CVE-2024-43455
CWE-20 Medium
No
No
2008 R2 6.1.7601.27320, 2008 6.0.6003.22870, 2012 R2 6.3.9600.22175, 2012 6.2.9200.25073, 2016 10.0.14393.7336, 2019 10.0.17763.6293, 2022 23H2 10.0.25398.1128, 2022 10.0.20348.2695, 2022 10.0.20348.2700 10.09.2024 SB2024091093
#VU97015 - Improper Authorization
CVE-2024-38231
CWE-285 Medium
No
No
2008 R2 6.1.7601.27320, 2008 6.0.6003.22870, 2012 R2 6.3.9600.22175, 2012 6.2.9200.25073, 2016 10.0.14393.7336, 2019 10.0.17763.6293, 2022 23H2 10.0.25398.1128, 2022 10.0.20348.2695, 2022 10.0.20348.2700 10.09.2024 SB2024091093
#VU97014 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-43454
CWE-22 Medium
No
No
2008 R2 6.1.7601.27320, 2008 6.0.6003.22870, 2012 R2 6.3.9600.22175, 2012 6.2.9200.25073, 2016 10.0.14393.7336, 2019 10.0.17763.6293, 2022 23H2 10.0.25398.1128, 2022 10.0.20348.2695, 2022 10.0.20348.2700 10.09.2024 SB2024091093
#VU97013 - Protection Mechanism Failure
CVE-2024-38217
CWE-693 Critical
No
Exploited
2008 R2 6.1.7601.27320, 2008 6.0.6003.22870, 2012 R2 6.3.9600.22175, 2012 6.2.9200.25073, 2022 23H2 10.0.25398.1128, 2022 10.0.20348.2695, 2022 10.0.20348.2700 10.09.2024 SB2024091091
#VU97012 - Sensitive Data Storage in Improperly Locked Memory
CVE-2024-38263
CWE-591 Medium
No
No
2008 R2 6.1.7601.27320, 2008 6.0.6003.22870, 2012 R2 6.3.9600.22175, 2012 6.2.9200.25073, 2016 10.0.14393.7336, 2019 10.0.17763.6293, 2022 23H2 10.0.25398.1128, 2022 10.0.20348.2695, 2022 10.0.20348.2700 10.09.2024 SB2024091093
#VU97011 - Improper Privilege Management
CVE-2024-38014
CWE-269 High
No
Exploited
2008 R2 6.1.7601.27320, 2008 6.0.6003.22870, 2012 R2 6.3.9600.22175, 2012 6.2.9200.25073, 2022 23H2 10.0.25398.1128, 2022 10.0.20348.2695, 2022 10.0.20348.2700 10.09.2024 SB2024091090
#VU97010 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2024-43467
CWE-362 Medium
No
No
2008 R2 6.1.7601.27320, 2008 6.0.6003.22870, 2012 R2 6.3.9600.22175, 2012 6.2.9200.25073, 2016 10.0.14393.7336, 2019 10.0.17763.6293, 2022 23H2 10.0.25398.1128, 2022 10.0.20348.2695, 2022 10.0.20348.2700 10.09.2024 SB2024091093
#VU97009 - Use of Uninitialized Resource
CVE-2024-38260
CWE-908 Medium
No
No
2008 R2 6.1.7601.27320, 2012 R2 6.3.9600.22175, 2012 6.2.9200.25073, 2016 10.0.14393.7336, 2019 10.0.17763.6293, 2022 23H2 10.0.25398.1128, 2022 10.0.20348.2695, 2022 10.0.20348.2700 10.09.2024 SB2024091093
#VU95984 - Insufficient Verification of Data Authenticity
CVE-2024-37968
CWE-345 Medium
No
No
2008 R2 6.1.7601.27277, 2008 6.0.6003.22825, 2012 R2 6.3.9600.22134, 2012 6.2.9200.25031, 2016 10.0.14393.7259, 2019 10.0.17763.6189, 2022 10.0.20348.2655 14.08.2024 SB2024081420
#VU95981 - Use After Free
CVE-2024-38140
CWE-416 High
No
No
2008 R2 6.1.7601.27277, 2008 6.0.6003.22825, 2012 R2 6.3.9600.22134, 2012 6.2.9200.25031, 2016 10.0.14393.7259, 2022 10.0.20348.2655 14.08.2024 SB2024081417
#VU86236 - Insufficient Verification of Data Authenticity
CVE-2023-40547
CWE-345 High
No
No
2012 R2 6.3.9600.22134, 2012 6.2.9200.25031, 2016 10.0.14393.7259, 2022 10.0.20348.2655 07.02.2024 SB2024020767
SB20240312192
SB20240312193
and 27 more


Showing elements 1881 - 1900 out of 6300