VendorsMicrosoftwindows_server_2016any version
Vulnerabilities

Microsoft Windows Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5805CVEs
CVE-2021-34535
Remote Desktop Client Remote Code Execution Vulnerability
Published 2021-08-12 · Modified
8.8EPSS 0.217
CVE-2020-1436
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Windows Font Library Remote Code Execution Vulnerability'.
Published 2020-07-14 · Modified
8.8EPSS 0.213
CVE-2025-54918
Windows NTLM Elevation of Privilege Vulnerability
Published 2025-09-09 · Analyzed
8.8EPSS 0.194
CVE-2025-21293
Active Directory Domain Services Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
8.8EPSS 0.190
CVE-2022-21990
Remote Desktop Client Remote Code Execution Vulnerability
Published 2022-03-09 · Modified
8.8EPSS 0.188
CVE-2019-0566
An elevation of privilege vulnerability exists in Microsoft Edge Browser Broker COM object, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge.
Published 2019-01-08 · Modified
8.81 PoCEPSS 0.186
CVE-2024-20674
Windows Kerberos Security Feature Bypass Vulnerability
Published 2024-01-09 · Modified
8.8EPSS 0.172
CVE-2017-11762
The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability in the way it handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-11763.
Published 2017-10-13 · Modified
8.8EPSS 0.171
CVE-2017-11763
The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability in the way it handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-11763.
Published 2017-10-13 · Modified
8.8EPSS 0.171
CVE-2024-38060
Windows Imaging Component Remote Code Execution Vulnerability
Published 2024-07-09 · Modified
8.8EPSS 0.159
CVE-2018-8475
A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-09-13 · Modified
8.8EPSS 0.159
CVE-2026-21513
MSHTML Framework Security Feature Bypass Vulnerability
Published 2026-02-10 · Analyzed
8.8KEVEPSS 0.156
CVE-2018-8260
A Remote Code Execution vulnerability exists in .NET software when the software fails to check the source markup of a file, aka ".NET Framework Remote Code Execution Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 4.7.2.
Published 2018-07-11 · Modified
8.8EPSS 0.155
CVE-2017-8625
Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to bypass Device Guard User Mode Code Integrity (UMCI) policies due to Internet Explorer failing to validate UMCI policies, aka "Internet Explorer Security Feature Bypass Vulnerability".
Published 2017-08-08 · Modified
8.8EPSS 0.153
CVE-2021-38666
Remote Desktop Client Remote Code Execution Vulnerability
Published 2021-11-10 · Modified
8.8EPSS 0.151
CVE-2020-1281
A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.
Published 2020-06-09 · Modified
8.8EPSS 0.145
CVE-2025-29962
Windows Media Remote Code Execution Vulnerability
Published 2025-05-13 · Analyzed
8.8EPSS 0.143
CVE-2024-49039
Windows Task Scheduler Elevation of Privilege Vulnerability
Published 2024-11-12 · Analyzed
8.8KEVEPSS 0.142
CVE-2024-43532
Remote Registry Service Elevation of Privilege Vulnerability
Published 2024-10-08 · Analyzed
8.8EPSS 0.120
CVE-2019-1419
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts, aka 'OpenType Font Parsing Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1456.
Published 2019-11-12 · Modified
8.8EPSS 0.116
CVE-2019-1113
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'.
Published 2019-07-29 · Modified
8.8EPSS 0.100
CVE-2020-16915
Media Foundation Memory Corruption Vulnerability
Published 2020-10-16 · Modified
8.8EPSS 0.098
CVE-2019-1456
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts, aka 'OpenType Font Parsing Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1419.
Published 2019-11-12 · Modified
8.8EPSS 0.097
CVE-2021-1678
Windows Print Spooler Spoofing Vulnerability
Published 2021-01-12 · Modified
8.8EPSS 0.093
CVE-2020-0684
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
Published 2020-03-12 · Modified
8.8EPSS 0.090
CVE-2025-53143
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2025-08-12 · Analyzed
8.8EPSS 0.081
CVE-2025-53145
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2025-08-12 · Analyzed
8.8EPSS 0.076
CVE-2025-53144
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2025-08-12 · Analyzed
8.8EPSS 0.076
CVE-2021-36947
Windows Print Spooler Remote Code Execution Vulnerability
Published 2021-08-12 · Modified
8.8EPSS 0.075
CVE-2023-35641
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
Published 2023-12-12 · Modified
8.8EPSS 0.072
CVE-2023-35630
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
Published 2023-12-12 · Modified
8.8EPSS 0.061
CVE-2020-1239
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1238.
Published 2020-06-09 · Modified
8.8EPSS 0.059
CVE-2018-8126
A security feature bypass vulnerability exists when Internet Explorer fails to validate User Mode Code Integrity (UMCI) policies, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11.
Published 2018-05-09 · Modified
8.8EPSS 0.056
CVE-2020-0801
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0807, CVE-2020-0809, CVE-2020-0869.
Published 2020-03-12 · Modified
8.8EPSS 0.053
CVE-2024-30078
Windows Wi-Fi Driver Remote Code Execution Vulnerability
Published 2024-06-11 · Modified
8.8EPSS 0.052
CVE-2022-30165
Windows Kerberos Elevation of Privilege Vulnerability
Published 2022-06-15 · Modified
8.8EPSS 0.049
CVE-2020-0869
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0801, CVE-2020-0807, CVE-2020-0809.
Published 2020-03-12 · Modified
8.8EPSS 0.047
CVE-2023-36400
Windows HMAC Key Derivation Elevation of Privilege Vulnerability
Published 2023-11-14 · Modified
8.8EPSS 0.043
CVE-2020-1129
Microsoft Windows Codecs Library Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
8.8EPSS 0.042
CVE-2021-42291
Active Directory Domain Services Elevation of Privilege Vulnerability
Published 2021-11-10 · Modified
8.8EPSS 0.042
← Prev14 / 146Next →