VendorsMicrosoftwindows_server_2016any version
Vulnerabilities

Microsoft Windows Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5805CVEs
CVE-2022-21920
Windows Kerberos Elevation of Privilege Vulnerability
Published 2022-01-11 · Modified
9.0EPSS 0.028
CVE-2022-21922
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.0EPSS 0.028
CVE-2020-1067
A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.
Published 2020-05-21 · Modified
9.0EPSS 0.025
CVE-2022-21857
Active Directory Domain Services Elevation of Privilege Vulnerability
Published 2022-01-11 · Modified
9.0EPSS 0.025
CVE-2021-1706
Windows LUAFV Elevation of Privilege Vulnerability
Published 2021-01-12 · Modified
9.0EPSS 0.021
CVE-2017-0021
Hyper-V in Microsoft Windows 10 1607 and Windows Server 2016 does not properly validate vSMB packet data, which allows attackers to execute arbitrary code on a target OS, aka "Hyper-V System Data Structure Vulnerability." This vulnerability is different from that described in CVE-2017-0095.
Published 2017-03-17 · Modified
9.0EPSS 0.017
CVE-2024-38124
Windows Netlogon Elevation of Privilege Vulnerability
Published 2024-10-08 · Analyzed
9.0EPSS 0.012
CVE-2022-21901
Windows Hyper-V Elevation of Privilege Vulnerability
Published 2022-01-11 · Modified
9.0EPSS 0.009
CVE-2021-40444
Microsoft MSHTML Remote Code Execution Vulnerability
Published 2021-09-15 · Analyzed
8.8KEVEPSS 0.975
CVE-2023-36025
Windows SmartScreen Security Feature Bypass Vulnerability
Published 2023-11-14 · Analyzed
8.8KEVEPSS 0.881
CVE-2025-33053
Internet Shortcut Files Remote Code Execution Vulnerability
Published 2025-06-10 · Analyzed
8.8KEVEPSS 0.870
CVE-2016-7200
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.
Published 2016-11-10 · Analyzed
8.8KEV2 PoCEPSS 0.828
CVE-2025-33073
Windows SMB Client Elevation of Privilege Vulnerability
Published 2025-06-10 · Analyzed
8.8KEV1 PoCEPSS 0.827
CVE-2021-26411
Internet Explorer Memory Corruption Vulnerability
Published 2021-03-11 · Analyzed
8.8KEVEPSS 0.808
CVE-2016-7201
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7200, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.
Published 2016-11-10 · Analyzed
8.8KEV2 PoCEPSS 0.800
CVE-2021-42287
Active Directory Domain Services Elevation of Privilege Vulnerability
Published 2021-11-10 · Analyzed
8.8KEVEPSS 0.772
CVE-2023-36899
ASP.NET Elevation of Privilege Vulnerability
Published 2023-08-08 · Modified
8.8EPSS 0.767
CVE-2018-0824
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-05-09 · Analyzed
8.8KEV1 PoCEPSS 0.732
CVE-2020-1020
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0938.
Published 2020-04-15 · Analyzed
8.8KEVEPSS 0.650
CVE-2021-33742
Windows MSHTML Platform Remote Code Execution Vulnerability
Published 2021-06-08 · Analyzed
8.8KEVEPSS 0.594
CVE-2020-1300
A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files.To exploit the vulnerability, an attacker would have to convince a user to either open a specially crafted cabinet file or spoof a network printer and trick a user into installing a malicious cabinet file disguised as a printer driver.The update addresses the vulnerability by correcting how Windows handles cabinet files., aka 'Windows Remote Code Execution Vulnerability'.
Published 2020-06-09 · Modified
8.8EPSS 0.594
CVE-2024-43461
Windows MSHTML Platform Spoofing Vulnerability
Published 2024-09-10 · Analyzed
8.8KEVEPSS 0.545
CVE-2025-53778
Windows NTLM Elevation of Privilege Vulnerability
Published 2025-08-12 · Modified
8.8EPSS 0.476
CVE-2021-24093
Windows Graphics Component Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
8.8EPSS 0.461
CVE-2013-3900
WinVerifyTrust Signature Validation Vulnerability
Published 2013-12-11 · Analyzed
8.8KEVEPSS 0.446
CVE-2020-1301
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0 (SMBv1) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'.
Published 2020-06-09 · Modified
8.8EPSS 0.438
CVE-2023-21674
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Published 2023-01-10 · Analyzed
8.8KEVEPSS 0.410
CVE-2022-24500
Windows SMB Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
8.8EPSS 0.380
CVE-2023-28231
DHCP Server Service Remote Code Execution Vulnerability
Published 2023-04-11 · Modified
8.8EPSS 0.366
CVE-2021-34480
Scripting Engine Memory Corruption Vulnerability
Published 2021-08-12 · Modified
8.8EPSS 0.339
CVE-2024-38144
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
Published 2024-08-13 · Analyzed
8.8EPSS 0.323
CVE-2020-0729
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
Published 2020-02-11 · Modified
8.8EPSS 0.309
CVE-2017-0222
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.
Published 2017-05-12 · Analyzed
8.8KEVEPSS 0.296
CVE-2017-0149
Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0018 and CVE-2017-0037.
Published 2017-03-17 · Analyzed
8.8KEVEPSS 0.292
CVE-2022-23285
Remote Desktop Client Remote Code Execution Vulnerability
Published 2022-03-09 · Modified
8.8EPSS 0.256
CVE-2023-36017
Windows Scripting Engine Memory Corruption Vulnerability
Published 2023-11-14 · Modified
8.8EPSS 0.253
CVE-2022-41128
Windows Scripting Languages Remote Code Execution Vulnerability
Published 2022-11-09 · Analyzed
8.8KEVEPSS 0.246
CVE-2026-21510
Windows Shell Security Feature Bypass Vulnerability
Published 2026-02-10 · Analyzed
8.8KEVEPSS 0.242
CVE-2020-1380
Scripting Engine Memory Corruption Vulnerability
Published 2020-08-17 · Analyzed
8.8KEVEPSS 0.242
CVE-2017-0210
An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Internet Explorer Elevation of Privilege Vulnerability."
Published 2017-04-12 · Analyzed
8.8KEVEPSS 0.223
← Prev13 / 146Next →