VendorsMicrosoftwindows_server_2019any version
Vulnerabilities

Microsoft Windows Server 2019 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5809CVEs
CVE-2023-38545
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255 bytes. If the host name is detected to be longer, curl switches to local name resolving and instead passes on the resolved address only. Due to this bug, the local variable that means "let the host resolve the name" could get the wrong value during a slow SOCKS5 handshake, and contrary to the intention, copy the too long host name to the target buffer instead of copying just the resolved address there. The target buffer being a heap based buffer, and the host name coming from the URL that curl has been told to operate with.
Published 2023-10-18 · Modified
9.8EPSS 0.785
CVE-2022-26937
Windows Network File System Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.8EPSS 0.760
CVE-2024-49112
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2024-12-10 · Analyzed
9.8EPSS 0.719
CVE-2024-38063
Windows TCP/IP Remote Code Execution Vulnerability
Published 2024-08-13 · Analyzed
9.8EPSS 0.706
CVE-2019-0626
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
Published 2019-03-06 · Modified
9.8EPSS 0.686
CVE-2019-0698
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0697, CVE-2019-0726.
Published 2019-04-08 · Modified
9.8EPSS 0.629
CVE-2019-0726
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0697, CVE-2019-0698.
Published 2019-04-08 · Modified
9.8EPSS 0.545
CVE-2022-34718
Windows TCP/IP Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
9.8EPSS 0.544
CVE-2019-0785
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
Published 2019-07-15 · Modified
9.8EPSS 0.496
CVE-2021-34481
Windows Print Spooler Remote Code Execution Vulnerability
Published 2021-07-16 · Modified
9.8EPSS 0.477
CVE-2024-30080
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2024-06-11 · Modified
9.8EPSS 0.431
CVE-2022-24497
Windows Network File System Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.8EPSS 0.346
CVE-2022-24491
Windows Network File System Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.8EPSS 0.335
CVE-2019-0697
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0698, CVE-2019-0726.
Published 2019-04-08 · Modified
9.8EPSS 0.329
CVE-2025-47981
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
Published 2025-07-08 · Analyzed
9.8EPSS 0.326
CVE-2019-0725
A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
Published 2019-05-16 · Modified
9.8EPSS 0.282
CVE-2023-21690
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
9.8EPSS 0.275
CVE-2023-21689
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
9.8EPSS 0.265
CVE-2021-24074
Windows TCP/IP Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
9.8EPSS 0.257
CVE-2021-24094
Windows TCP/IP Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
9.8EPSS 0.221
CVE-2023-21692
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
9.8EPSS 0.212
CVE-2025-55234
Windows SMB Elevation of Privilege Vulnerability
Published 2025-09-09 · Modified
9.8EPSS 0.201
CVE-2023-36397
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Published 2023-11-14 · Modified
9.8EPSS 0.175
CVE-2021-26877
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
9.8EPSS 0.165
CVE-2023-36049
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
Published 2023-11-14 · Modified
9.8EPSS 0.125
CVE-2021-24078
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
9.8EPSS 0.119
CVE-2021-26432
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
Published 2021-08-12 · Modified
9.8EPSS 0.113
CVE-2024-43639
Windows KDC Proxy Remote Code Execution Vulnerability
Published 2024-11-12 · Analyzed
9.8EPSS 0.089
CVE-2025-53766
GDI+ Remote Code Execution Vulnerability
Published 2025-08-12 · Analyzed
9.8EPSS 0.080
CVE-2021-36936
Windows Print Spooler Remote Code Execution Vulnerability
Published 2021-08-12 · Modified
9.8EPSS 0.074
CVE-2021-26893
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
9.8EPSS 0.070
CVE-2019-0786
An elevation of privilege vulnerability exists in the Microsoft Server Message Block (SMB) Server when an attacker with valid credentials attempts to open a specially crafted file over the SMB protocol on the same machine, aka 'SMB Server Elevation of Privilege Vulnerability'.
Published 2019-04-09 · Modified
9.8EPSS 0.070
CVE-2019-1212
Windows DHCP Server Denial of Service Vulnerability
Published 2019-08-14 · Modified
9.8EPSS 0.067
CVE-2021-43217
Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
Published 2021-12-15 · Modified
9.8EPSS 0.064
CVE-2022-21849
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.8EPSS 0.062
CVE-2025-60724
GDI+ Remote Code Execution Vulnerability
Published 2025-11-11 · Analyzed
9.8EPSS 0.059
CVE-2023-24943
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Published 2023-05-09 · Modified
9.8EPSS 0.047
CVE-2021-36965
Windows WLAN AutoConfig Service Remote Code Execution Vulnerability
Published 2021-09-15 · Modified
9.8EPSS 0.046
CVE-2022-22012
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.8EPSS 0.040
CVE-2024-38140
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Published 2024-08-13 · Modified
9.8EPSS 0.038
← Prev2 / 146Next →