VendorsMicrosoftwindows_serverall versions
Vulnerabilities

Microsoft Windows Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

303CVEs
CVE-2022-21896
Windows DWM Core Library Elevation of Privilege Vulnerability
Published 2022-01-11 · Modified
7.0EPSS 0.006
CVE-2022-29138
Windows Clustered Shared Volume Elevation of Privilege Vulnerability
Published 2022-05-10 · Modified
7.0EPSS 0.006
CVE-2022-21866
Windows System Launcher Elevation of Privilege Vulnerability
Published 2022-01-11 · Modified
7.0EPSS 0.006
CVE-2022-23287
Windows ALPC Elevation of Privilege Vulnerability
Published 2022-03-09 · Modified
7.0EPSS 0.006
CVE-2022-23288
Windows DWM Core Library Elevation of Privilege Vulnerability
Published 2022-03-09 · Modified
7.0EPSS 0.006
CVE-2022-23298
Windows NT OS Kernel Elevation of Privilege Vulnerability
Published 2022-03-09 · Modified
7.0EPSS 0.006
CVE-2022-22016
Windows PlayToManager Elevation of Privilege Vulnerability
Published 2022-05-10 · Modified
7.0EPSS 0.006
CVE-2022-26939
Storage Spaces Direct Elevation of Privilege Vulnerability
Published 2022-05-10 · Modified
7.0EPSS 0.006
CVE-2022-24525
Windows Update Stack Elevation of Privilege Vulnerability
Published 2022-03-09 · Modified
7.0EPSS 0.004
CVE-2022-23283
Windows ALPC Elevation of Privilege Vulnerability
Published 2022-03-09 · Modified
7.0EPSS 0.004
CVE-2022-24505
Windows ALPC Elevation of Privilege Vulnerability
Published 2022-03-09 · Modified
7.0EPSS 0.004
CVE-2022-21928
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
6.9EPSS 0.007
CVE-2018-8438
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8436, CVE-2018-8437.
Published 2018-09-13 · Modified
6.8EPSS 0.072
CVE-2021-43216
Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
Published 2021-12-15 · Modified
6.8EPSS 0.032
CVE-2022-23253
Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
Published 2022-03-09 · Modified
6.5EPSS 0.564
CVE-2021-26414
Windows DCOM Server Security Feature Bypass
Published 2021-06-08 · Modified
6.5EPSS 0.498
CVE-2022-24502
Windows HTML Platforms Security Feature Bypass Vulnerability
Published 2022-03-09 · Modified
6.5EPSS 0.331
CVE-2017-11927
Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow an information vulnerability due to the way the Windows its:// protocol handler determines the zone of a request, aka "Microsoft Windows Information Disclosure Vulnerability".
Published 2017-12-12 · Modified
6.5EPSS 0.096
CVE-2018-8422
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8424.
Published 2018-09-13 · Modified
6.5EPSS 0.063
CVE-2022-29112
Windows Graphics Component Information Disclosure Vulnerability
Published 2022-05-10 · Modified
6.5EPSS 0.032
CVE-2022-26934
Windows Graphics Component Information Disclosure Vulnerability
Published 2022-05-10 · Modified
6.5EPSS 0.029
CVE-2022-26936
Windows Server Service Information Disclosure Vulnerability
Published 2022-05-10 · Modified
6.5EPSS 0.029
CVE-2022-21915
Windows GDI+ Information Disclosure Vulnerability
Published 2022-01-11 · Modified
6.5EPSS 0.027
CVE-2022-22015
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Published 2022-05-10 · Modified
6.5EPSS 0.025
CVE-2021-40460
Windows Remote Procedure Call Runtime Security Feature Bypass Vulnerability
Published 2021-10-13 · Modified
6.5EPSS 0.016
CVE-2022-21918
DirectX Graphics Kernel File Denial of Service Vulnerability
Published 2022-01-11 · Modified
6.5EPSS 0.011
CVE-2022-26935
Windows WLAN AutoConfig Service Information Disclosure Vulnerability
Published 2022-05-10 · Modified
6.5EPSS 0.010
CVE-2022-21847
Windows Hyper-V Denial of Service Vulnerability
Published 2022-01-11 · Modified
6.5EPSS 0.010
CVE-2022-29121
Windows WLAN AutoConfig Service Denial of Service Vulnerability
Published 2022-05-10 · Modified
6.5EPSS 0.009
CVE-2022-29120
Windows Clustered Shared Volume Information Disclosure Vulnerability
Published 2022-05-10 · Modified
6.5EPSS 0.008
CVE-2021-43244
Windows Kernel Information Disclosure Vulnerability
Published 2021-12-15 · Modified
6.5EPSS 0.008
CVE-2022-29122
Windows Clustered Shared Volume Information Disclosure Vulnerability
Published 2022-05-10 · Modified
6.5EPSS 0.008
CVE-2022-29134
Windows Clustered Shared Volume Information Disclosure Vulnerability
Published 2022-05-10 · Modified
6.5EPSS 0.008
CVE-2022-29123
Windows Clustered Shared Volume Information Disclosure Vulnerability
Published 2022-05-10 · Modified
6.5EPSS 0.008
CVE-2018-0885
The Microsoft Hyper-V Network Switch in 64-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows a denial of service vulnerability due to how input from a privileged user on a guest operating system is validated, aka "Hyper-V Denial of Service Vulnerability".
Published 2018-03-14 · Modified
6.3EPSS 0.053
CVE-2018-8470
A security feature bypass vulnerability exists in Internet Explorer due to how scripts are handled that allows a universal cross-site scripting (UXSS) condition, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11.
Published 2018-09-13 · Modified
6.1EPSS 0.033
CVE-2022-23278
Microsoft Defender for Endpoint Spoofing Vulnerability
Published 2022-03-09 · Modified
5.9EPSS 0.019
CVE-2018-8567
An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge.
Published 2018-11-14 · Modified
5.8EPSS 0.031
CVE-2018-0888
The Microsoft Hyper-V Network Switch in 64-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to how guest operating system input is validated, aka "Hyper-V Information Disclosure Vulnerability".
Published 2018-03-14 · Modified
5.6EPSS 0.014
CVE-2022-22712
Windows Hyper-V Denial of Service Vulnerability
Published 2022-02-09 · Modified
5.6EPSS 0.008
← Prev6 / 8Next →