VendorsMicrosoftwindows_server_2016all versions
Vulnerabilities

Microsoft Windows Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6168CVEs
CVE-2020-1472
Netlogon Elevation of Privilege Vulnerability
Published 2020-08-17 · Analyzed
10.0KEV1 PoCEPSS 0.994
CVE-2020-0646
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.
Published 2020-01-14 · Analyzed
10.0KEV1 PoCEPSS 0.992
CVE-2020-1350
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'.
Published 2020-07-14 · Analyzed
10.0KEVEPSS 0.967
CVE-2022-26809
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
10.0EPSS 0.910
CVE-2020-0609
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0610.
Published 2020-01-14 · Modified
10.02 PoCEPSS 0.777
CVE-2019-1181
Remote Desktop Services Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
10.0EPSS 0.758
CVE-2017-8543
Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to take control of the affected system when Windows Search fails to handle objects in memory, aka "Windows Search Remote Code Execution Vulnerability".
Published 2017-06-15 · Analyzed
10.0KEVEPSS 0.742
CVE-2022-30136
Windows Network File System Remote Code Execution Vulnerability
Published 2022-06-15 · Modified
10.0EPSS 0.732
CVE-2020-0610
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0609.
Published 2020-01-14 · Modified
10.02 PoCEPSS 0.676
CVE-2018-8476
A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory, aka "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability." This affects Windows Server 2012 R2, Windows Server 2008, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows Server 2008 R2, Windows 10 Servers.
Published 2018-11-14 · Modified
10.0EPSS 0.648
CVE-2017-11771
The Microsoft Windows Search component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly handle DNS responses, aka "Windows Search Remote Code Execution Vulnerability".
Published 2017-10-13 · Modified
10.0EPSS 0.519
CVE-2018-8421
A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 2.0.
Published 2018-09-13 · Modified
10.0EPSS 0.291
CVE-2017-8589
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way that Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability".
Published 2017-07-11 · Modified
10.0EPSS 0.262
CVE-2018-8540
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 4.6.2.
Published 2018-12-12 · Modified
10.0EPSS 0.216
CVE-2018-8626
A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly handle requests, aka "Windows DNS Server Heap Overflow Vulnerability." This affects Windows Server 2012 R2, Windows Server 2019, Windows Server 2016, Windows 10, Windows 10 Servers.
Published 2018-12-12 · Modified
10.0EPSS 0.212
CVE-2019-1182
Remote Desktop Services Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
10.0EPSS 0.168
CVE-2021-26897
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
10.0EPSS 0.116
CVE-2020-17051
Windows Network File System Remote Code Execution Vulnerability
Published 2020-11-11 · Modified
10.0EPSS 0.106
CVE-2019-1226
Remote Desktop Services Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
10.0EPSS 0.082
CVE-2019-1222
Remote Desktop Services Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
10.0EPSS 0.076
CVE-2021-26895
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
10.0EPSS 0.073
CVE-2021-26894
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
10.0EPSS 0.073
CVE-2020-0690
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.
Published 2020-03-12 · Modified
10.0EPSS 0.070
CVE-2020-1467
Windows Hard Link Elevation of Privilege Vulnerability
Published 2020-08-17 · Modified
10.0EPSS 0.035
CVE-2019-14678
SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME engine when the AUTOMAP option is used.
Published 2019-11-14 · Modified
10.0EPSS 0.030
CVE-2022-21874
Windows Security Center API Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
10.0EPSS 0.023
CVE-2021-26424
Windows TCP/IP Remote Code Execution Vulnerability
Published 2021-08-12 · Modified
9.9EPSS 0.611
CVE-2021-28476
Windows Hyper-V Remote Code Execution Vulnerability
Published 2021-05-11 · Modified
9.9EPSS 0.386
CVE-2019-1384
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an attacker could send a specially crafted authentication request, aka 'Microsoft Windows Security Feature Bypass Vulnerability'.
Published 2019-11-12 · Modified
9.9EPSS 0.076
CVE-2020-17095
Windows Hyper-V Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
9.9EPSS 0.050
CVE-2019-1365
An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the context of NT AUTHORITY\system escaping the Sandbox.The security update addresses the vulnerability by correcting how Microsoft IIS Server sanitizes web requests., aka 'Microsoft IIS Server Elevation of Privilege Vulnerability'.
Published 2019-10-10 · Modified
9.9EPSS 0.044
CVE-2020-1112
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
Published 2020-05-21 · Modified
9.9EPSS 0.033
CVE-2021-26867
Windows Hyper-V Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
9.9EPSS 0.028
CVE-2021-34458
Windows Kernel Remote Code Execution Vulnerability
Published 2021-07-16 · Modified
9.9EPSS 0.026
CVE-2021-34450
Windows Hyper-V Remote Code Execution Vulnerability
Published 2021-07-16 · Modified
9.9EPSS 0.025
CVE-2026-57092
Microsoft Windows VMSwitch Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
9.9EPSS 0.009
CVE-2025-59287
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
Published 2025-10-14 · Analyzed
9.8KEVEPSS 1.000
CVE-2023-21554
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-04-11 · Modified
9.8EPSS 0.955
CVE-2023-24941
Windows Network File System Remote Code Execution Vulnerability
Published 2023-05-09 · Modified
9.8EPSS 0.947
CVE-2024-38077
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
Published 2024-07-09 · Modified
9.8EPSS 0.841
1 / 155Next →