VendorsMicrosoftwindows_server_2019all versions
Vulnerabilities

Microsoft Windows Server 2019

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5825CVEs
CVE-2019-1471
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'.
Published 2019-12-10 · Modified
8.2EPSS 0.082
CVE-2022-30196
Windows Secure Channel Denial of Service Vulnerability
Published 2022-09-13 · Modified
8.2EPSS 0.021
CVE-2026-50429
Windows Kernel Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
8.2EPSS 0.011
CVE-2022-26932
Storage Spaces Direct Elevation of Privilege Vulnerability
Published 2022-05-10 · Modified
8.2EPSS 0.007
CVE-2026-81354
Windows Hello Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
8.2EPSS 0.003
CVE-2026-72962
Windows USB Video Driver Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
8.2EPSS 0.003
CVE-2026-72961
Windows Hyper-V Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
8.2EPSS 0.003
CVE-2026-69906
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
8.2EPSS 0.003
CVE-2026-69846
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
8.2EPSS 0.003
CVE-2026-50680
Windows Hyper-V Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
8.2EPSS 0.003
CVE-2026-69874
Windows ALPC Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
8.2EPSS 0.003
CVE-2024-21412
Internet Shortcut Files Security Feature Bypass Vulnerability
Published 2024-02-13 · Analyzed
8.1KEVEPSS 0.994
CVE-2023-35628
Windows MSHTML Platform Remote Code Execution Vulnerability
Published 2023-12-12 · Modified
8.1EPSS 0.928
CVE-2020-0601
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.
Published 2020-01-14 · Analyzed
8.1KEV1 PoCEPSS 0.894
CVE-2022-37958
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
8.1EPSS 0.860
CVE-2024-43573
Windows MSHTML Platform Spoofing Vulnerability
Published 2024-10-08 · Analyzed
8.1KEVEPSS 0.461
CVE-2024-21357
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Published 2024-02-13 · Modified
8.1EPSS 0.269
CVE-2023-36005
Windows Telephony Server Elevation of Privilege Vulnerability
Published 2023-12-12 · Modified
8.1EPSS 0.239
CVE-2025-33071
Windows KDC Proxy Service (KPSSVC) Remote Code Execution Vulnerability
Published 2025-06-10 · Analyzed
8.1EPSS 0.232
CVE-2024-49122
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2024-12-10 · Analyzed
8.1EPSS 0.207
CVE-2024-21407
Windows Hyper-V Remote Code Execution Vulnerability
Published 2024-03-12 · Modified
8.1EPSS 0.163
CVE-2023-28219
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Published 2023-04-11 · Modified
8.1EPSS 0.150
CVE-2023-28220
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Published 2023-04-11 · Modified
8.1EPSS 0.150
CVE-2025-21309
Windows Remote Desktop Services Remote Code Execution Vulnerability
Published 2025-01-14 · Analyzed
8.1EPSS 0.149
CVE-2020-17140
Windows SMB Information Disclosure Vulnerability
Published 2020-12-09 · Modified
8.1EPSS 0.131
CVE-2025-27480
Windows Remote Desktop Services Remote Code Execution Vulnerability
Published 2025-04-08 · Analyzed
8.1EPSS 0.125
CVE-2022-33679
Windows Kerberos Elevation of Privilege Vulnerability
Published 2022-09-13 · Modified
8.1EPSS 0.111
CVE-2025-26670
Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability
Published 2025-04-08 · Analyzed
8.1EPSS 0.111
CVE-2022-26925
Windows LSA Spoofing Vulnerability
Published 2022-05-10 · Analyzed
8.1KEVEPSS 0.107
CVE-2024-49116
Windows Remote Desktop Services Remote Code Execution Vulnerability
Published 2024-12-10 · Analyzed
8.1EPSS 0.102
CVE-2025-33070
Windows Netlogon Elevation of Privilege Vulnerability
Published 2025-06-10 · Analyzed
8.1EPSS 0.099
CVE-2025-21376
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2025-02-11 · Analyzed
8.1EPSS 0.094
CVE-2021-26435
Windows Scripting Engine Memory Corruption Vulnerability
Published 2021-09-15 · Modified
8.1EPSS 0.053
CVE-2022-22029
Windows Network File System Remote Code Execution Vulnerability
Published 2022-07-12 · Modified
8.1EPSS 0.053
CVE-2020-0665
An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privilege Vulnerability'.
Published 2020-02-11 · Modified
8.1EPSS 0.044
CVE-2025-50177
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2025-08-12 · Analyzed
8.1EPSS 0.044
CVE-2019-0649
A vulnerability exists in Microsoft Chakra JIT server, aka 'Scripting Engine Elevation of Privileged Vulnerability'.
Published 2019-03-06 · Modified
8.1EPSS 0.043
CVE-2022-24490
Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability
Published 2022-04-15 · Modified
8.1EPSS 0.033
CVE-2024-43582
Remote Desktop Protocol Server Remote Code Execution Vulnerability
Published 2024-10-08 · Analyzed
8.1EPSS 0.032
CVE-2019-1424
A security feature bypass vulnerability exists when Windows Netlogon improperly handles a secure communications channel, aka 'NetLogon Security Feature Bypass Vulnerability'.
Published 2019-11-12 · Modified
8.1EPSS 0.031
← Prev26 / 146Next →