VendorsMicrosoftwindows_server_2022all versions
Vulnerabilities

Microsoft Windows Server 2022

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3978CVEs
CVE-2026-50673
Windows Kernel Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.002
CVE-2026-50378
Windows Key Guard Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.002
CVE-2025-58720
Windows Cryptographic Services Information Disclosure Vulnerability
Published 2025-10-14 · Analyzed
7.8EPSS 0.002
CVE-2026-81355
Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
7.8EPSS 0.002
CVE-2026-50450
Windows Network Connections Service Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.002
CVE-2026-54112
Windows Win32k Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.002
CVE-2026-42991
Windows Push Notifications Elevation of Privilege Vulnerability
Published 2026-06-09 · Analyzed
7.8EPSS 0.002
CVE-2026-42977
Windows Push Notifications Elevation of Privilege Vulnerability
Published 2026-06-09 · Analyzed
7.8EPSS 0.002
CVE-2026-42979
Windows Push Notifications Elevation of Privilege Vulnerability
Published 2026-06-09 · Analyzed
7.8EPSS 0.002
CVE-2026-42978
Windows Push Notifications Elevation of Privilege Vulnerability
Published 2026-06-09 · Analyzed
7.8EPSS 0.002
CVE-2026-58628
Windows Wireless Network Manager Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.002
CVE-2026-32164
Windows User Interface Core Elevation of Privilege Vulnerability
Published 2026-04-14 · Analyzed
7.8EPSS 0.002
CVE-2026-32165
Windows User Interface Core Elevation of Privilege Vulnerability
Published 2026-04-14 · Analyzed
7.8EPSS 0.002
CVE-2026-32163
Windows User Interface Core Elevation of Privilege Vulnerability
Published 2026-04-14 · Analyzed
7.8EPSS 0.002
CVE-2026-32160
Windows Push Notifications Elevation of Privilege Vulnerability
Published 2026-04-14 · Analyzed
7.8EPSS 0.002
CVE-2026-32159
Windows Push Notifications Elevation of Privilege Vulnerability
Published 2026-04-14 · Analyzed
7.8EPSS 0.002
CVE-2026-32158
Windows Push Notifications Elevation of Privilege Vulnerability
Published 2026-04-14 · Analyzed
7.8EPSS 0.002
CVE-2026-26172
Windows Push Notifications Elevation of Privilege Vulnerability
Published 2026-04-14 · Analyzed
7.8EPSS 0.002
CVE-2026-26168
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published 2026-04-14 · Analyzed
7.8EPSS 0.002
CVE-2026-27911
Windows User Interface Core Elevation of Privilege Vulnerability
Published 2026-04-14 · Analyzed
7.8EPSS 0.002
CVE-2026-20930
Windows Management Services Elevation of Privilege Vulnerability
Published 2026-04-14 · Analyzed
7.8EPSS 0.002
CVE-2022-42972
A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a local attacker modifies the webroot directory. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)
Published 2023-02-01 · Modified
7.8EPSS 0.002
CVE-2022-42973
A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local attacker connects to the database. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)
Published 2023-02-01 · Modified
7.8EPSS 0.002
CVE-2022-37998
Windows Local Session Manager (LSM) Denial of Service Vulnerability
Published 2022-10-11 · Modified
7.7EPSS 0.030
CVE-2022-37973
Windows Local Session Manager (LSM) Denial of Service Vulnerability
Published 2022-10-11 · Modified
7.7EPSS 0.030
CVE-2021-40463
Windows Network Address Translation (NAT) Denial of Service Vulnerability
Published 2021-10-13 · Modified
7.7EPSS 0.026
CVE-2025-59200
Data Sharing Service Spoofing Vulnerability
Published 2025-10-14 · Analyzed
7.7EPSS 0.008
CVE-2026-20852
Windows Hello Tampering Vulnerability
Published 2026-01-13 · Analyzed
7.7EPSS 0.005
CVE-2026-20804
Windows Hello Tampering Vulnerability
Published 2026-01-13 · Analyzed
7.7EPSS 0.005
CVE-2025-29833
Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
Published 2025-05-13 · Analyzed
7.7EPSS 0.004
CVE-2026-27913
Windows BitLocker Security Feature Bypass Vulnerability
Published 2026-04-14 · Analyzed
7.7EPSS 0.004
CVE-2024-21351
Windows SmartScreen Security Feature Bypass Vulnerability
Published 2024-02-13 · Analyzed
7.6KEVEPSS 0.278
CVE-2022-30142
Windows File History Remote Code Execution Vulnerability
Published 2022-06-15 · Modified
7.6EPSS 0.022
CVE-2023-32022
Windows Server Service Security Feature Bypass Vulnerability
Published 2023-06-13 · Modified
7.6EPSS 0.008
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2023-50387
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
Published 2024-02-14 · Modified
7.5EPSS 1.000
CVE-2023-36884
Windows Search Remote Code Execution Vulnerability
Published 2023-07-11 · Analyzed
7.5KEVEPSS 0.989
CVE-2024-29059
.NET Framework Information Disclosure Vulnerability
Published 2024-03-22 · Analyzed
7.5KEVEPSS 0.986
CVE-2023-28302
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Published 2023-04-11 · Modified
7.5EPSS 0.926
CVE-2023-21758
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Published 2023-01-10 · Modified
7.5EPSS 0.925
← Prev53 / 100Next →