VendorsMicrosoftwindows_server_2019any version
Vulnerabilities

Microsoft Windows Server 2019 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5825CVEs
CVE-2026-77493
Windows Graphics Component Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.010
CVE-2026-69824
Microsoft Standard XPS Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.010
CVE-2026-69586
Microsoft Windows PDF Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.010
CVE-2026-69408
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.010
CVE-2026-72950
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.009
CVE-2026-73025
Windows iSCSI Security Feature Bypass Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.009
CVE-2026-58594
Remote Desktop Client Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
9.8EPSS 0.008
CVE-2026-57090
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
9.8EPSS 0.008
CVE-2026-54995
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
9.8EPSS 0.008
CVE-2026-50694
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
9.8EPSS 0.008
CVE-2026-50439
Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
9.8EPSS 0.008
CVE-2026-49164
Windows Active Directory Domain Services Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
9.8EPSS 0.008
CVE-2023-33154
Windows Partition Management Driver Elevation of Privilege Vulnerability
Published 2023-07-11 · Modified
9.8EPSS 0.008
CVE-2022-42970
A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)
Published 2023-02-01 · Modified
9.8EPSS 0.007
CVE-2026-57089
Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
9.8EPSS 0.007
CVE-2026-56188
Windows Server Network driver Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
9.8EPSS 0.006
CVE-2026-47304
.NET Security Feature Bypass Vulnerability
Published 2026-07-14 · Analyzed
9.8EPSS 0.003
CVE-2026-50380
Windows GDI+ Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
9.6EPSS 0.008
CVE-2022-30190
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Published 2022-06-01 · Analyzed
9.3KEVEPSS 0.992
CVE-2021-1675
Windows Print Spooler Remote Code Execution Vulnerability
Published 2021-06-08 · Analyzed
9.3KEVEPSS 0.853
CVE-2022-21972
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.3EPSS 0.793
CVE-2019-1358
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1359.
Published 2019-10-10 · Modified
9.3EPSS 0.759
CVE-2020-1421
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
Published 2020-07-14 · Modified
9.3EPSS 0.745
CVE-2022-23270
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.3EPSS 0.704
CVE-2019-0618
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0662.
Published 2019-03-06 · Modified
9.3EPSS 0.670
CVE-2022-21971
Windows Runtime Remote Code Execution Vulnerability
Published 2022-02-09 · Analyzed
9.3KEVEPSS 0.539
CVE-2019-0541
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.
Published 2019-01-08 · Analyzed
9.3KEV1 PoCEPSS 0.532
CVE-2020-1074
Jet Database Engine Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
9.3EPSS 0.484
CVE-2018-8544
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-11-14 · Modified
9.31 PoCEPSS 0.476
CVE-2018-8413
A remote code execution vulnerability exists when "Windows Theme API" does not properly decompress files, aka "Windows Theme API Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-10-10 · Modified
9.31 PoCEPSS 0.463
CVE-2021-34448
Scripting Engine Memory Corruption Vulnerability
Published 2021-07-16 · Analyzed
9.3KEVEPSS 0.401
CVE-2019-1311
A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects in memory, aka 'Windows Imaging API Remote Code Execution Vulnerability'.
Published 2019-10-10 · Modified
9.3EPSS 0.362
CVE-2018-8423
A remote code execution vulnerability exists in the Microsoft JET Database Engine, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-10-10 · Modified
9.3EPSS 0.322
CVE-2019-0853
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
Published 2019-04-09 · Modified
9.3EPSS 0.301
CVE-2019-1150
Microsoft Graphics Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
9.32 PoCEPSS 0.262
CVE-2020-1400
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1401, CVE-2020-1407.
Published 2020-07-14 · Modified
9.3EPSS 0.237
CVE-2019-1118
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123, CVE-2019-1124, CVE-2019-1127, CVE-2019-1128.
Published 2019-07-29 · Modified
9.31 PoCEPSS 0.236
CVE-2019-1117
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123, CVE-2019-1124, CVE-2019-1127, CVE-2019-1128.
Published 2019-07-29 · Modified
9.31 PoCEPSS 0.236
CVE-2018-8256
A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka "Microsoft PowerShell Remote Code Execution Vulnerability." This affects Windows RT 8.1, PowerShell Core 6.0, Microsoft.PowerShell.Archive 1.2.2.0, Windows Server 2016, Windows Server 2012, Windows Server 2008 R2, Windows Server 2019, Windows 7, Windows Server 2012 R2, PowerShell Core 6.1, Windows 10 Servers, Windows 10, Windows 8.1.
Published 2018-11-14 · Modified
9.3EPSS 0.226
CVE-2021-31956
Windows NTFS Elevation of Privilege Vulnerability
Published 2021-06-08 · Analyzed
9.3KEVEPSS 0.223
← Prev5 / 146Next →