VendorsMicrosoftwindows_server_2022all versions
Vulnerabilities

Microsoft Windows Server 2022

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3954CVEs
CVE-2023-36434
Windows IIS Server Elevation of Privilege Vulnerability
Published 2023-10-10 · Modified
9.8EPSS 0.024
CVE-2024-38199
Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
Published 2024-08-13 · Analyzed
9.8EPSS 0.022
CVE-2023-32057
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-07-11 · Modified
9.8EPSS 0.022
CVE-2024-38074
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
Published 2024-07-09 · Modified
9.8EPSS 0.022
CVE-2024-38076
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
Published 2024-07-09 · Modified
9.8EPSS 0.022
CVE-2023-32015
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Published 2023-06-13 · Analyzed
9.8EPSS 0.020
CVE-2023-28250
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Published 2023-04-11 · Modified
9.8EPSS 0.020
CVE-2022-35744
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
Published 2023-05-31 · Modified
9.8EPSS 0.020
CVE-2023-32014
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Published 2023-06-13 · Analyzed
9.8EPSS 0.019
CVE-2023-29363
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Published 2023-06-13 · Analyzed
9.8EPSS 0.019
CVE-2025-21307
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Published 2025-01-14 · Analyzed
9.8EPSS 0.019
CVE-2023-35365
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2023-07-11 · Modified
9.8EPSS 0.018
CVE-2023-36911
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-08-08 · Modified
9.8EPSS 0.017
CVE-2023-35367
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2023-07-11 · Modified
9.8EPSS 0.017
CVE-2023-35366
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2023-07-11 · Modified
9.8EPSS 0.017
CVE-2024-43455
Windows Remote Desktop Licensing Service Spoofing Vulnerability
Published 2024-09-10 · Analyzed
9.8EPSS 0.017
CVE-2023-23392
HTTP Protocol Stack Remote Code Execution Vulnerability
Published 2023-03-14 · Modified
9.8EPSS 0.017
CVE-2026-33824
Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
Published 2026-04-14 · Analyzed
9.8KEVEPSS 0.016
CVE-2023-36903
Windows System Assessment Tool Elevation of Privilege Vulnerability
Published 2023-08-08 · Modified
9.8EPSS 0.016
CVE-2024-38240
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Published 2024-09-10 · Analyzed
9.8EPSS 0.015
CVE-2023-21708
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2023-03-14 · Modified
9.8EPSS 0.015
CVE-2024-21416
Windows TCP/IP Remote Code Execution Vulnerability
Published 2024-09-10 · Analyzed
9.8EPSS 0.014
CVE-2023-29411
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface.
Published 2023-04-18 · Modified
9.8EPSS 0.013
CVE-2023-38186
Windows Mobile Device Management Elevation of Privilege Vulnerability
Published 2023-08-08 · Modified
9.8EPSS 0.013
CVE-2026-50330
Windows Remote Desktop Client Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
9.8EPSS 0.013
CVE-2023-32056
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
Published 2023-07-11 · Modified
9.8EPSS 0.012
CVE-2023-29412
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface.
Published 2023-04-18 · Modified
9.8EPSS 0.012
CVE-2026-49181
Windows DHCP Client Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
9.8EPSS 0.012
CVE-2022-42971
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)
Published 2023-02-01 · Modified
9.8EPSS 0.011
CVE-2026-69845
Windows DHCP Server Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.010
CVE-2026-68839
Windows USB Mass Storage Class Driver Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
9.8EPSS 0.010
CVE-2026-42990
SQL Server ODBC driver Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
9.8EPSS 0.010
CVE-2026-47291
HTTP.sys Remote Code Execution Vulnerability
Published 2026-06-09 · Analyzed
9.8EPSS 0.010
CVE-2026-45657
Windows Kernel Remote Code Execution Vulnerability
Published 2026-06-09 · Analyzed
9.8EPSS 0.010
CVE-2026-56190
Remote Desktop Protocol Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
9.8EPSS 0.010
CVE-2026-56159
DHCP Server Service Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
9.8EPSS 0.010
CVE-2026-50518
Windows DHCP Server Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
9.8EPSS 0.010
CVE-2026-50447
Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
9.8EPSS 0.010
CVE-2026-41089
Windows Netlogon Remote Code Execution Vulnerability
Published 2026-05-12 · Analyzed
9.8EPSS 0.010
CVE-2026-62815
Microsoft QUIC Remote Code Execution Vulnerability
Published 2026-08-11 · Analyzed
9.8EPSS 0.010
← Prev2 / 99Next →