VendorsMicrosoftwindows_server_2016all versions
Vulnerabilities

Microsoft Windows Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6168CVEs
CVE-2025-21298
Windows OLE Remote Code Execution Vulnerability
Published 2025-01-14 · Analyzed
9.8EPSS 0.809
CVE-2022-34721
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
9.8EPSS 0.789
CVE-2022-26937
Windows Network File System Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.8EPSS 0.760
CVE-2024-49112
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2024-12-10 · Analyzed
9.8EPSS 0.719
CVE-2024-38063
Windows TCP/IP Remote Code Execution Vulnerability
Published 2024-08-13 · Analyzed
9.8EPSS 0.706
CVE-2019-0626
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
Published 2019-03-06 · Modified
9.8EPSS 0.686
CVE-2019-0698
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0697, CVE-2019-0726.
Published 2019-04-08 · Modified
9.8EPSS 0.629
CVE-2019-0726
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0697, CVE-2019-0698.
Published 2019-04-08 · Modified
9.8EPSS 0.545
CVE-2022-34718
Windows TCP/IP Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
9.8EPSS 0.544
CVE-2019-0785
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
Published 2019-07-15 · Modified
9.8EPSS 0.496
CVE-2021-34481
Windows Print Spooler Remote Code Execution Vulnerability
Published 2021-07-16 · Modified
9.8EPSS 0.477
CVE-2024-30080
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2024-06-11 · Modified
9.8EPSS 0.431
CVE-2022-24497
Windows Network File System Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.8EPSS 0.346
CVE-2022-24491
Windows Network File System Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.8EPSS 0.335
CVE-2019-0697
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0698, CVE-2019-0726.
Published 2019-04-08 · Modified
9.8EPSS 0.329
CVE-2025-47981
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
Published 2025-07-08 · Analyzed
9.8EPSS 0.326
CVE-2019-0725
A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
Published 2019-05-16 · Modified
9.8EPSS 0.282
CVE-2023-21690
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
9.8EPSS 0.275
CVE-2017-8686
The Windows Server DHCP service in Windows Server 2012 Gold and R2, and Windows Server 2016 allows an attacker to either run arbitrary code on the DHCP failover server or cause the DHCP service to become nonresponsive, due to a memory corruption vulnerability in the Windows Server DHCP service, aka "Windows DHCP Server Remote Code Execution Vulnerability".
Published 2017-09-13 · Modified
9.8EPSS 0.275
CVE-2023-21689
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
9.8EPSS 0.265
CVE-2021-24074
Windows TCP/IP Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
9.8EPSS 0.257
CVE-2021-24094
Windows TCP/IP Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
9.8EPSS 0.221
CVE-2023-21692
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
9.8EPSS 0.212
CVE-2025-55234
Windows SMB Elevation of Privilege Vulnerability
Published 2025-09-09 · Modified
9.8EPSS 0.201
CVE-2023-36397
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Published 2023-11-14 · Modified
9.8EPSS 0.175
CVE-2021-26877
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
9.8EPSS 0.165
CVE-2023-36049
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
Published 2023-11-14 · Modified
9.8EPSS 0.125
CVE-2021-24078
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
9.8EPSS 0.119
CVE-2021-26432
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
Published 2021-08-12 · Modified
9.8EPSS 0.113
CVE-2024-43639
Windows KDC Proxy Remote Code Execution Vulnerability
Published 2024-11-12 · Analyzed
9.8EPSS 0.089
CVE-2025-53766
GDI+ Remote Code Execution Vulnerability
Published 2025-08-12 · Analyzed
9.8EPSS 0.080
CVE-2021-36936
Windows Print Spooler Remote Code Execution Vulnerability
Published 2021-08-12 · Modified
9.8EPSS 0.074
CVE-2021-26893
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
9.8EPSS 0.070
CVE-2019-0786
An elevation of privilege vulnerability exists in the Microsoft Server Message Block (SMB) Server when an attacker with valid credentials attempts to open a specially crafted file over the SMB protocol on the same machine, aka 'SMB Server Elevation of Privilege Vulnerability'.
Published 2019-04-09 · Modified
9.8EPSS 0.070
CVE-2019-1212
Windows DHCP Server Denial of Service Vulnerability
Published 2019-08-14 · Modified
9.8EPSS 0.067
CVE-2021-43217
Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
Published 2021-12-15 · Modified
9.8EPSS 0.064
CVE-2022-21849
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.8EPSS 0.062
CVE-2025-60724
GDI+ Remote Code Execution Vulnerability
Published 2025-11-11 · Analyzed
9.8EPSS 0.059
CVE-2017-11899
Device Guard in Windows 10 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerability due to the way untrusted files are handled, aka "Microsoft Windows Security Feature Bypass Vulnerability".
Published 2017-12-12 · Modified
9.8EPSS 0.058
CVE-2023-24943
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Published 2023-05-09 · Modified
9.8EPSS 0.047
← Prev2 / 155Next →