VendorsMicrosoftwindows_serverall versions
Vulnerabilities

Microsoft Windows Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

303CVEs
CVE-2021-43246
Windows Hyper-V Denial of Service Vulnerability
Published 2021-12-15 · Modified
5.6EPSS 0.008
CVE-2022-22713
Windows Hyper-V Denial of Service Vulnerability
Published 2022-05-10 · Modified
5.6EPSS 0.007
CVE-2021-43224
Windows Common Log File System Driver Information Disclosure Vulnerability
Published 2021-12-15 · Modified
5.5EPSS 0.039
CVE-2022-21877
Storage Spaces Controller Information Disclosure Vulnerability
Published 2022-01-11 · Modified
5.5EPSS 0.029
CVE-2018-8445
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8336, CVE-2018-8419, CVE-2018-8442, CVE-2018-8443, CVE-2018-8446.
Published 2018-09-13 · Modified
5.5EPSS 0.028
CVE-2022-22010
Media Foundation Information Disclosure Vulnerability
Published 2022-03-09 · Modified
5.5EPSS 0.026
CVE-2018-0811
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way objects are initialized in memory, aka "Windows Kernel Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0813, CVE-2018-0814, CVE-2018-0894, CVE-2018-0895, CVE-2018-0896, CVE-2018-0897, CVE-2018-0898, CVE-2018-0899, CVE-2018-0900, CVE-2018-0901 and CVE-2018-0926.
Published 2018-03-14 · Modified
5.5EPSS 0.018
CVE-2018-0813
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way objects are initialized in memory, aka "Windows Kernel Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0811, CVE-2018-0814, CVE-2018-0894, CVE-2018-0895, CVE-2018-0896, CVE-2018-0897, CVE-2018-0898, CVE-2018-0899, CVE-2018-0900, and CVE-2018-0901 and CVE-2018-0926.
Published 2018-03-14 · Modified
5.5EPSS 0.018
CVE-2018-0814
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way objects are initialized in memory, aka "Windows Kernel Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0811, CVE-2018-0813, CVE-2018-0894, CVE-2018-0895, CVE-2018-0896, CVE-2018-0897, CVE-2018-0898, CVE-2018-0899, CVE-2018-0900, and CVE-2018-0901 and CVE-2018-0926.
Published 2018-03-14 · Modified
5.5EPSS 0.018
CVE-2018-0926
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way memory addresses are handled, aka "Windows Kernel Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0811, CVE-2018-0813, CVE-2018-0814, CVE-2018-0894, CVE-2018-0895, CVE-2018-0896, CVE-2018-0897, CVE-2018-0898, CVE-2018-0899, CVE-2018-0900, and CVE-2018-0901.
Published 2018-03-14 · Modified
5.5EPSS 0.017
CVE-2018-8419
An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8336, CVE-2018-8442, CVE-2018-8443, CVE-2018-8445, CVE-2018-8446.
Published 2018-09-13 · Modified
5.5EPSS 0.017
CVE-2022-21876
Win32k Information Disclosure Vulnerability
Published 2022-01-11 · Modified
5.5EPSS 0.013
CVE-2022-22002
Windows User Account Profile Picture Denial of Service Vulnerability
Published 2022-02-09 · Modified
5.5EPSS 0.013
CVE-2022-29114
Windows Print Spooler Information Disclosure Vulnerability
Published 2022-05-10 · Modified
5.5EPSS 0.012
CVE-2022-23281
Windows Common Log File System Driver Information Disclosure Vulnerability
Published 2022-03-09 · Modified
5.5EPSS 0.011
CVE-2022-29140
Windows Print Spooler Information Disclosure Vulnerability
Published 2022-05-10 · Modified
5.5EPSS 0.011
CVE-2022-21906
Windows Defender Application Control Security Feature Bypass Vulnerability
Published 2022-01-11 · Modified
5.5EPSS 0.011
CVE-2022-22710
Windows Common Log File System Driver Denial of Service Vulnerability
Published 2022-02-09 · Modified
5.5EPSS 0.009
CVE-2022-26933
Windows NTFS Information Disclosure Vulnerability
Published 2022-05-10 · Modified
5.5EPSS 0.009
CVE-2022-21998
Windows Common Log File System Driver Information Disclosure Vulnerability
Published 2022-02-09 · Modified
5.5EPSS 0.008
CVE-2022-29102
Windows Failover Cluster Information Disclosure Vulnerability
Published 2022-05-10 · Modified
5.5EPSS 0.008
CVE-2022-22011
Windows Graphics Component Information Disclosure Vulnerability
Published 2022-05-10 · Modified
5.5EPSS 0.008
CVE-2022-26930
Windows Remote Access Connection Manager Information Disclosure Vulnerability
Published 2022-05-10 · Modified
5.5EPSS 0.008
CVE-2022-21985
Windows Remote Access Connection Manager Information Disclosure Vulnerability
Published 2022-02-09 · Modified
5.5EPSS 0.008
CVE-2022-23297
Windows NT Lan Manager Datagram Receiver Driver Information Disclosure Vulnerability
Published 2022-03-09 · Modified
5.5EPSS 0.008
CVE-2021-38662
Windows Fast FAT File System Driver Information Disclosure Vulnerability
Published 2021-10-13 · Modified
5.5EPSS 0.008
CVE-2021-43227
Storage Spaces Controller Information Disclosure Vulnerability
Published 2021-12-15 · Modified
5.5EPSS 0.008
CVE-2021-43235
Storage Spaces Controller Information Disclosure Vulnerability
Published 2021-12-15 · Modified
5.5EPSS 0.008
CVE-2018-8356
A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, ASP.NET Core 1.1, Microsoft .NET Framework 4.5.2, ASP.NET Core 2.0, ASP.NET Core 1.0, .NET Core 1.1, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 1.0, .NET Core 2.0, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.
Published 2018-07-11 · Modified
5.5EPSS 0.007
CVE-2021-38663
Windows exFAT File System Information Disclosure Vulnerability
Published 2021-10-13 · Modified
5.5EPSS 0.007
CVE-2021-40455
Windows Installer Spoofing Vulnerability
Published 2021-10-13 · Modified
5.5EPSS 0.006
CVE-2021-40454
Rich Text Edit Control Information Disclosure Vulnerability
Published 2021-10-13 · Modified
5.5EPSS 0.005
CVE-2022-21924
Workstation Service Remote Protocol Security Feature Bypass Vulnerability
Published 2022-01-11 · Modified
5.4EPSS 0.029
CVE-2022-24503
Remote Desktop Protocol Client Information Disclosure Vulnerability
Published 2022-03-09 · Modified
5.4EPSS 0.024
CVE-2017-11834
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11791.
Published 2017-11-15 · Modified
5.3EPSS 0.127
CVE-2017-11830
Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to make an unsigned file appear to be signed, due to a security feature bypass, aka "Device Guard Security Feature Bypass Vulnerability".
Published 2017-11-15 · Modified
5.31 PoCEPSS 0.026
CVE-2006-3074
klif.sys in Kaspersky Internet Security 6.0 and 7.0, Kaspersky Anti-Virus (KAV) 6.0 and 7.0, KAV 6.0 for Windows Workstations, and KAV 6.0 for Windows Servers does not validate certain parameters to the (1) NtCreateKey, (2) NtCreateProcess, (3) NtCreateProcessEx, (4) NtCreateSection, (5) NtCreateSymbolicLinkObject, (6) NtCreateThread, (7) NtDeleteValueKey, (8) NtLoadKey2, (9) NtOpenKey, (10) NtOpenProcess, (11) NtOpenSection, and (12) NtQueryValueKey hooked system calls, which allows local users to cause a denial of service (reboot) via an invalid parameter, as demonstrated by the ClientId parameter to NtOpenProcess.
Published 2006-06-19 · Modified
5.01 PoCEPSS 0.072
CVE-2007-1918
The RFC_SET_REG_SERVER_PROPERTY function in the SAP RFC Library 6.40 and 7.00 before 20070109 implements an option for exclusive access to an RFC server, which allows remote attackers to cause a denial of service (client lockout) via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.
Published 2007-04-10 · Modified
5.0EPSS 0.025
CVE-2007-1913
The TRUSTED_SYSTEM_SECURITY function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to verify the existence of users and groups on systems and domains via unspecified vectors, a different vulnerability than CVE-2006-6010. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.
Published 2007-04-10 · Modified
5.0EPSS 0.022
CVE-2022-21894
Secure Boot Security Feature Bypass Vulnerability
Published 2022-01-11 · Modified
4.9EPSS 0.066
← Prev7 / 8Next →