VendorsMicrosoftwindows_server_2016any version
Vulnerabilities

Microsoft Windows Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5805CVEs
CVE-2026-54128
Windows DHCP Client Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
8.4EPSS 0.004
CVE-2026-54122
Windows GDI+ Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
8.4EPSS 0.004
CVE-2026-69638
Windows NTFS Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
8.4EPSS 0.004
CVE-2026-49184
Windows NTFS Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
8.4EPSS 0.003
CVE-2026-77503
Windows NTFS Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
8.4EPSS 0.003
CVE-2026-54992
Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
8.4EPSS 0.003
CVE-2026-45607
Windows Hyper-V Remote Code Execution Vulnerability
Published 2026-06-09 · Analyzed
8.4EPSS 0.003
CVE-2026-32091
Microsoft Brokering File System Elevation of Privilege Vulnerability
Published 2026-04-14 · Analyzed
8.4EPSS 0.002
CVE-2018-8357
An elevation of privilege vulnerability exists in Microsoft browsers allowing sandbox escape, aka "Microsoft Browser Elevation of Privilege Vulnerability." This affects Internet Explorer 11, Microsoft Edge.
Published 2018-08-15 · Modified
8.3EPSS 0.078
CVE-2026-50429
Windows Kernel Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
8.2EPSS 0.011
CVE-2022-26932
Storage Spaces Direct Elevation of Privilege Vulnerability
Published 2022-05-10 · Modified
8.2EPSS 0.007
CVE-2026-72961
Windows Hyper-V Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
8.2EPSS 0.003
CVE-2026-69906
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
8.2EPSS 0.003
CVE-2026-69846
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
8.2EPSS 0.003
CVE-2023-35628
Windows MSHTML Platform Remote Code Execution Vulnerability
Published 2023-12-12 · Modified
8.1EPSS 0.928
CVE-2020-0601
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.
Published 2020-01-14 · Analyzed
8.1KEV1 PoCEPSS 0.894
CVE-2022-37958
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
8.1EPSS 0.860
CVE-2023-29325
Windows OLE Remote Code Execution Vulnerability
Published 2023-05-09 · Modified
8.1EPSS 0.839
CVE-2017-0037
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element.
Published 2017-02-26 · Analyzed
8.1KEV3 PoCEPSS 0.804
CVE-2024-43573
Windows MSHTML Platform Spoofing Vulnerability
Published 2024-10-08 · Analyzed
8.1KEVEPSS 0.461
CVE-2024-21357
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Published 2024-02-13 · Modified
8.1EPSS 0.269
CVE-2023-36005
Windows Telephony Server Elevation of Privilege Vulnerability
Published 2023-12-12 · Modified
8.1EPSS 0.239
CVE-2025-33071
Windows KDC Proxy Service (KPSSVC) Remote Code Execution Vulnerability
Published 2025-06-10 · Analyzed
8.1EPSS 0.232
CVE-2024-49122
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2024-12-10 · Analyzed
8.1EPSS 0.207
CVE-2024-21407
Windows Hyper-V Remote Code Execution Vulnerability
Published 2024-03-12 · Modified
8.1EPSS 0.163
CVE-2023-28219
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Published 2023-04-11 · Modified
8.1EPSS 0.150
CVE-2023-28220
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Published 2023-04-11 · Modified
8.1EPSS 0.150
CVE-2025-21309
Windows Remote Desktop Services Remote Code Execution Vulnerability
Published 2025-01-14 · Analyzed
8.1EPSS 0.149
CVE-2020-17140
Windows SMB Information Disclosure Vulnerability
Published 2020-12-09 · Modified
8.1EPSS 0.131
CVE-2025-27480
Windows Remote Desktop Services Remote Code Execution Vulnerability
Published 2025-04-08 · Analyzed
8.1EPSS 0.125
CVE-2017-0161
The Windows NetBT Session Services component on Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to maintain certain sequencing requirements, aka "NetBIOS Remote Code Execution Vulnerability".
Published 2017-09-13 · Modified
8.1EPSS 0.112
CVE-2022-33679
Windows Kerberos Elevation of Privilege Vulnerability
Published 2022-09-13 · Modified
8.1EPSS 0.111
CVE-2025-26670
Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability
Published 2025-04-08 · Analyzed
8.1EPSS 0.111
CVE-2022-26925
Windows LSA Spoofing Vulnerability
Published 2022-05-10 · Analyzed
8.1KEVEPSS 0.107
CVE-2024-49116
Windows Remote Desktop Services Remote Code Execution Vulnerability
Published 2024-12-10 · Analyzed
8.1EPSS 0.102
CVE-2025-33070
Windows Netlogon Elevation of Privilege Vulnerability
Published 2025-06-10 · Analyzed
8.1EPSS 0.099
CVE-2025-21376
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2025-02-11 · Analyzed
8.1EPSS 0.094
CVE-2017-8563
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Kerberos falling back to NT LAN Manager (NTLM) Authentication Protocol as the default authentication protocol, aka "Windows Elevation of Privilege Vulnerability".
Published 2017-07-11 · Modified
8.1EPSS 0.072
CVE-2021-26435
Windows Scripting Engine Memory Corruption Vulnerability
Published 2021-09-15 · Modified
8.1EPSS 0.053
CVE-2022-22029
Windows Network File System Remote Code Execution Vulnerability
Published 2022-07-12 · Modified
8.1EPSS 0.053
← Prev27 / 146Next →