← microsoft

microsoft / windows_server_2025

1,131 known vulnerabilities in microsoft windows_server_2025.

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-33824 Act now 72.7% 9.8 Double free in Windows IKE Extension allows an unauthorized attacker to execute …
CVE-2026-32202 Act now 63.7% 4.3 Protection mechanism failure in Windows Shell allows an unauthorized attacker to…
CVE-2025-26633 Act now 30.4% 7.0 Improper neutralization in Microsoft Management Console allows an unauthorized a…
CVE-2024-49039 Act now 14.2% 8.8 Windows Task Scheduler Elevation of Privilege Vulnerability
CVE-2026-68820 Act now 6.2% 7.0 Use after free in Windows Ancillary Function Driver for WinSock allows an author…
CVE-2026-20805 Act now 5.2% 5.5 Exposure of sensitive information to an unauthorized actor in Desktop Windows Ma…
CVE-2026-81963 Act now 0.6% 7.8 Improper link resolution before file access ('link following') in Windows Update…
CVE-2026-49160 High 53.8% 7.5 Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to d…
CVE-2026-47291 Medium 22.8% 9.8 Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attack…
CVE-2026-20872 Medium 20.1% 6.5 External control of file name or path in Windows NTLM allows an unauthorized att…
CVE-2026-20925 Medium 18.2% 6.5 External control of file name or path in Windows NTLM allows an unauthorized att…
CVE-2026-45657 Medium 15.5% 9.8 Use after free in Windows Kernel allows an unauthorized attacker to execute code…
CVE-2026-20860 Medium 8.4% 7.8 Access of resource using incompatible type ('type confusion') in Windows Ancilla…
CVE-2026-42980 Medium 6.9% 7.8 Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authori…
CVE-2026-20817 Medium 5.5% 7.8 Improper handling of insufficient permissions or privileges in Windows Error Rep…
CVE-2026-20840 Medium 4.7% 7.8 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to exec…
CVE-2026-20871 Medium 4.2% 7.8 Use after free in Desktop Windows Manager allows an authorized attacker to eleva…
CVE-2026-61358 Medium 3.7% 7.8 Improper link resolution before file access ('link following') in Windows Access…
CVE-2026-45586 Medium 3.6% 7.8 Improper link resolution before file access ('link following') in Windows Collab…
CVE-2026-50509 Medium 3.5% 7.8 Deserialization of untrusted data in Windows Wireless Wide Area Network Service …
CVE-2026-20843 Medium 3.5% 7.8 Improper access control in Windows Routing and Remote Access Service (RRAS) allo…
CVE-2026-62696 Medium 3.4% 7.8 Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistan…
CVE-2026-62832 Medium 3.3% 7.8 Improper link resolution before file access ('link following') in Windows User P…
CVE-2026-62737 Medium 2.8% 7.8 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to…
CVE-2026-62893 Medium 2.7% 9.8 Use after free in Windows Deployment Services allows an unauthorized attacker to…
CVE-2026-65775 Medium 2.6% 7.8 Use after free in Windows Win32K allows an authorized attacker to elevate privil…
CVE-2026-20820 Medium 2.6% 7.8 Heap-based buffer overflow in Windows Common Log File System Driver allows an au…
CVE-2026-20816 Medium 2.5% 7.8 Time-of-check time-of-use (toctou) race condition in Windows Installer allows an…
CVE-2026-42989 Medium 2.3% 7.8 Improper link resolution before file access ('link following') in Winlogon allow…
CVE-2026-33116 Medium 2.1% 7.5 Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, …
CVE-2026-61930 Medium 2.1% 7.8 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to el…
CVE-2026-62741 Medium 2.1% 7.8 Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized …
CVE-2026-42905 Medium 2.0% 7.8 Use after free in Windows DWM Core Library allows an authorized attacker to elev…
CVE-2026-42986 Medium 2.0% 7.8 Use after free in Microsoft Graphics Component allows an authorized attacker to …
CVE-2026-62783 Medium 2.0% 7.8 Heap-based buffer overflow in Windows Remote Access Connection Manager allows an…
CVE-2026-62888 Medium 2.0% 7.8 Use after free in Windows DWM Core Library allows an authorized attacker to elev…
CVE-2026-62713 Medium 2.0% 7.8 Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an a…
CVE-2026-54121 Medium 1.8% 8.8 Improper authorization in Active Directory Certificate Services (AD CS) allows a…
CVE-2026-59132 Medium 1.7% 7.5 Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to de…
CVE-2026-61929 Medium 1.7% 7.0 Use after free in Windows Kernel allows an authorized attacker to elevate privil…
CVE-2026-65788 Medium 1.7% 7.0 Use after free in Desktop Window Manager allows an authorized attacker to elevat…
CVE-2026-61348 Medium 1.6% 7.0 Use after free in Windows Ancillary Function Driver for WinSock allows an author…
CVE-2026-20875 Medium 1.6% 7.5 Null pointer dereference in Windows Local Security Authority Subsystem Service (…
CVE-2026-62766 Medium 1.5% 7.0 Double free in Windows Kerberos allows an authorized attacker to elevate privile…
CVE-2026-20868 Medium 1.4% 8.8 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) a…
CVE-2026-20846 Medium 1.4% 7.5 Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service…
CVE-2026-42985 Medium 1.3% 8.8 Use after free in Remote Desktop Client allows an unauthorized attacker to execu…
CVE-2026-62878 Medium 1.3% 9.8 Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to ex…
CVE-2026-50330 Medium 1.3% 7.5 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac…
CVE-2026-33096 Medium 1.2% 7.5 Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny s…
Page 1 of 23 Next →