microsoft / windows_server_2022
1,272 known vulnerabilities in microsoft windows_server_2022.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-20860 | Medium | 8.4% | 7.8 | Access of resource using incompatible type ('type confusion') in Windows Ancilla… | |
| CVE-2022-41109 | Medium | 8.1% | 7.8 | Windows Win32k Elevation of Privilege Vulnerability | |
| CVE-2021-38665 | Medium | 7.0% | 7.4 | Remote Desktop Protocol Client Information Disclosure Vulnerability | |
| CVE-2026-42980 | Medium | 6.9% | 7.8 | Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authori… | |
| CVE-2024-38244 | Medium | 6.2% | 7.8 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | |
| CVE-2024-38241 | Medium | 6.0% | 7.8 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | |
| CVE-2023-35382 | Medium | 5.6% | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2023-35386 | Medium | 5.5% | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2026-20817 | Medium | 5.5% | 7.8 | Improper handling of insufficient permissions or privileges in Windows Error Rep… | |
| CVE-2021-26435 | Medium | 5.3% | 8.1 | Windows Scripting Engine Memory Corruption Vulnerability | |
| CVE-2026-20840 | Medium | 4.7% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to exec… | |
| CVE-2021-36965 | Medium | 4.6% | 8.8 | Windows WLAN AutoConfig Service Remote Code Execution Vulnerability | |
| CVE-2024-38257 | Medium | 4.5% | 7.5 | Microsoft AllJoyn API Information Disclosure Vulnerability | |
| CVE-2026-20871 | Medium | 4.2% | 7.8 | Use after free in Desktop Windows Manager allows an authorized attacker to eleva… | |
| CVE-2021-42282 | Medium | 4.2% | 7.5 | Active Directory Domain Services Elevation of Privilege Vulnerability | |
| CVE-2021-42291 | Medium | 4.2% | 7.5 | Active Directory Domain Services Elevation of Privilege Vulnerability | |
| CVE-2022-37967 | Medium | 4.1% | 7.2 | Windows Kerberos Elevation of Privilege Vulnerability | |
| CVE-2026-61358 | Medium | 3.7% | 7.8 | Improper link resolution before file access ('link following') in Windows Access… | |
| CVE-2026-45586 | Medium | 3.6% | 7.8 | Improper link resolution before file access ('link following') in Windows Collab… | |
| CVE-2023-21688 | Medium | 3.6% | 7.8 | NT OS Kernel Elevation of Privilege Vulnerability | |
| CVE-2023-35380 | Medium | 3.5% | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2026-20843 | Medium | 3.5% | 7.8 | Improper access control in Windows Routing and Remote Access Service (RRAS) allo… | |
| CVE-2026-62696 | Medium | 3.4% | 7.8 | Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistan… | |
| CVE-2024-38237 | Medium | 3.4% | 7.8 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | |
| CVE-2024-38242 | Medium | 3.4% | 7.8 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | |
| CVE-2023-21812 | Medium | 3.3% | 7.8 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2026-62832 | Medium | 3.3% | 7.8 | Improper link resolution before file access ('link following') in Windows User P… | |
| CVE-2021-36960 | Medium | 3.3% | 7.5 | Windows SMB Information Disclosure Vulnerability | |
| CVE-2023-35383 | Medium | 3.0% | 7.5 | Microsoft Message Queuing Information Disclosure Vulnerability | |
| CVE-2021-41356 | Medium | 3.0% | 7.5 | Windows Denial of Service Vulnerability | |
| CVE-2026-20929 | Medium | 2.9% | 7.5 | Improper access control in Windows HTTP.sys allows an authorized attacker to ele… | |
| CVE-2026-62893 | Medium | 2.7% | 9.8 | Use after free in Windows Deployment Services allows an unauthorized attacker to… | |
| CVE-2026-65775 | Medium | 2.6% | 7.8 | Use after free in Windows Win32K allows an authorized attacker to elevate privil… | |
| CVE-2026-20820 | Medium | 2.6% | 7.8 | Heap-based buffer overflow in Windows Common Log File System Driver allows an au… | |
| CVE-2022-37966 | Medium | 2.5% | 8.1 | Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability | |
| CVE-2023-36910 | Medium | 2.5% | 9.8 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | |
| CVE-2026-20816 | Medium | 2.5% | 7.8 | Time-of-check time-of-use (toctou) race condition in Windows Installer allows an… | |
| CVE-2021-42276 | Medium | 2.5% | 7.8 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | |
| CVE-2023-35385 | Medium | 2.5% | 9.8 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | |
| CVE-2022-38023 | Medium | 2.4% | 8.1 | Netlogon RPC Elevation of Privilege Vulnerability | |
| CVE-2024-38236 | Medium | 2.3% | 7.5 | DHCP Server Service Denial of Service Vulnerability | |
| CVE-2026-42989 | Medium | 2.3% | 7.8 | Improper link resolution before file access ('link following') in Winlogon allow… | |
| CVE-2024-21348 | Medium | 2.2% | 7.5 | Internet Connection Sharing (ICS) Denial of Service Vulnerability | |
| CVE-2026-33116 | Medium | 2.1% | 7.5 | Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, … | |
| CVE-2026-61930 | Medium | 2.1% | 7.8 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to el… | |
| CVE-2026-62741 | Medium | 2.1% | 7.8 | Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized … | |
| CVE-2022-41056 | Medium | 2.1% | 7.5 | Network Policy Server (NPS) RADIUS Protocol Denial of Service Vulnerability | |
| CVE-2021-42275 | Medium | 2.1% | 8.8 | Microsoft COM for Windows Remote Code Execution Vulnerability | |
| CVE-2022-41053 | Medium | 2.1% | 7.5 | Windows Kerberos Denial of Service Vulnerability | |
| CVE-2022-41058 | Medium | 2.1% | 7.5 | Windows Network Address Translation (NAT) Denial of Service Vulnerability |