VendorsMicrosoftwindows_server_2019all versions
Vulnerabilities

Microsoft Windows Server 2019

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5771CVEs
CVE-2020-1472
Netlogon Elevation of Privilege Vulnerability
Published 2020-08-17 · Analyzed
10.0KEV1 PoCEPSS 0.994
CVE-2020-0646
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.
Published 2020-01-14 · Analyzed
10.0KEV1 PoCEPSS 0.992
CVE-2022-21907
HTTP Protocol Stack Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
10.01 PoCEPSS 0.928
CVE-2020-1350
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'.
Published 2020-07-14 · Analyzed
10.0KEVEPSS 0.914
CVE-2022-26809
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
10.0EPSS 0.910
CVE-2019-1181
Remote Desktop Services Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
10.0EPSS 0.758
CVE-2020-0609
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0610.
Published 2020-01-14 · Modified
10.02 PoCEPSS 0.749
CVE-2022-30136
Windows Network File System Remote Code Execution Vulnerability
Published 2022-06-15 · Modified
10.0EPSS 0.732
CVE-2020-0610
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0609.
Published 2020-01-14 · Modified
10.02 PoCEPSS 0.676
CVE-2018-8476
A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory, aka "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability." This affects Windows Server 2012 R2, Windows Server 2008, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows Server 2008 R2, Windows 10 Servers.
Published 2018-11-14 · Modified
10.0EPSS 0.648
CVE-2018-8540
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 4.6.2.
Published 2018-12-12 · Modified
10.0EPSS 0.216
CVE-2018-8626
A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly handle requests, aka "Windows DNS Server Heap Overflow Vulnerability." This affects Windows Server 2012 R2, Windows Server 2019, Windows Server 2016, Windows 10, Windows 10 Servers.
Published 2018-12-12 · Modified
10.0EPSS 0.212
CVE-2019-1182
Remote Desktop Services Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
10.0EPSS 0.168
CVE-2021-26897
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
10.0EPSS 0.116
CVE-2020-17051
Windows Network File System Remote Code Execution Vulnerability
Published 2020-11-11 · Modified
10.0EPSS 0.106
CVE-2019-1226
Remote Desktop Services Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
10.0EPSS 0.082
CVE-2019-1222
Remote Desktop Services Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
10.0EPSS 0.076
CVE-2021-26894
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
10.0EPSS 0.073
CVE-2021-26895
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
10.0EPSS 0.073
CVE-2020-0690
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.
Published 2020-03-12 · Modified
10.0EPSS 0.070
CVE-2020-1467
Windows Hard Link Elevation of Privilege Vulnerability
Published 2020-08-17 · Modified
10.0EPSS 0.035
CVE-2019-14678
SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME engine when the AUTOMAP option is used.
Published 2019-11-14 · Modified
10.0EPSS 0.030
CVE-2022-21898
DirectX Graphics Kernel Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
10.0EPSS 0.024
CVE-2022-21874
Windows Security Center API Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
10.0EPSS 0.023
CVE-2021-26424
Windows TCP/IP Remote Code Execution Vulnerability
Published 2021-08-12 · Modified
9.9EPSS 0.611
CVE-2021-28476
Windows Hyper-V Remote Code Execution Vulnerability
Published 2021-05-11 · Modified
9.9EPSS 0.386
CVE-2019-1384
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an attacker could send a specially crafted authentication request, aka 'Microsoft Windows Security Feature Bypass Vulnerability'.
Published 2019-11-12 · Modified
9.9EPSS 0.076
CVE-2020-17095
Windows Hyper-V Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
9.9EPSS 0.050
CVE-2019-1365
An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the context of NT AUTHORITY\system escaping the Sandbox.The security update addresses the vulnerability by correcting how Microsoft IIS Server sanitizes web requests., aka 'Microsoft IIS Server Elevation of Privilege Vulnerability'.
Published 2019-10-10 · Modified
9.9EPSS 0.044
CVE-2020-1112
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
Published 2020-05-21 · Modified
9.9EPSS 0.033
CVE-2021-34458
Windows Kernel Remote Code Execution Vulnerability
Published 2021-07-16 · Modified
9.9EPSS 0.026
CVE-2021-34450
Windows Hyper-V Remote Code Execution Vulnerability
Published 2021-07-16 · Modified
9.9EPSS 0.025
CVE-2025-49708
Microsoft Graphics Component Elevation of Privilege Vulnerability
Published 2025-10-14 · Analyzed
9.9EPSS 0.012
CVE-2026-57092
Microsoft Windows VMSwitch Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
9.9EPSS 0.009
CVE-2025-59287
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
Published 2025-10-14 · Analyzed
9.8KEVEPSS 1.000
CVE-2023-21554
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-04-11 · Modified
9.8EPSS 0.955
CVE-2023-24941
Windows Network File System Remote Code Execution Vulnerability
Published 2023-05-09 · Modified
9.8EPSS 0.947
CVE-2024-38077
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
Published 2024-07-09 · Modified
9.8EPSS 0.841
CVE-2025-21298
Windows OLE Remote Code Execution Vulnerability
Published 2025-01-14 · Analyzed
9.8EPSS 0.809
CVE-2026-41089
Windows Netlogon Remote Code Execution Vulnerability
Published 2026-05-12 · Analyzed
9.8EPSS 0.796
1 / 145Next →