microsoft / windows_server_2025
1,131 known vulnerabilities in microsoft windows_server_2025.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-40409 | Medium | 0.3% | 7.8 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege V… | |
| CVE-2026-49170 | Medium | 0.3% | 7.8 | Insufficient granularity of access control in Windows StateRepository API allows… | |
| CVE-2026-50311 | Medium | 0.3% | 7.8 | Improper access control in Windows Server allows an authorized attacker to eleva… | |
| CVE-2026-50333 | Medium | 0.3% | 7.8 | Missing authentication for critical function in Windows Spaceport.sys allows an … | |
| CVE-2026-50335 | Medium | 0.3% | 7.8 | Improper access control in Windows Operating Systems allows an authorized attack… | |
| CVE-2026-50343 | Medium | 0.3% | 7.8 | Improper privilege management in Microsoft Install Service allows an authorized … | |
| CVE-2026-50344 | Medium | 0.3% | 7.8 | Improper authorization in Windows OLE allows an authorized attacker to elevate p… | |
| CVE-2026-50346 | Medium | 0.3% | 7.8 | Improper authorization in RPC Runtime allows an authorized attacker to elevate p… | |
| CVE-2026-50351 | Medium | 0.3% | 7.8 | Improper access control in Windows Audio Compression Manager (ACM) allows an aut… | |
| CVE-2026-50373 | Medium | 0.3% | 7.8 | Improper access control in Microsoft Windows Search Component allows an authoriz… | |
| CVE-2026-50391 | Medium | 0.3% | 7.8 | Improper privilege management in Windows Group Policy allows an authorized attac… | |
| CVE-2026-50405 | Medium | 0.3% | 7.8 | Insufficient granularity of access control in Windows Filtering Platform (WFP) a… | |
| CVE-2026-50423 | Medium | 0.3% | 7.8 | Improper access control in Windows Kernel allows an authorized attacker to eleva… | |
| CVE-2026-50465 | Medium | 0.3% | 7.1 | Improper access control in Microsoft Windows DNS allows an authorized attacker t… | |
| CVE-2026-55001 | Medium | 0.3% | 7.8 | Improper certificate validation in Windows Active Directory allows an authorized… | |
| CVE-2026-57088 | Medium | 0.3% | 7.8 | Improper access control in Extensible Storage Engine (ESENT) allows an authorize… | |
| CVE-2026-58540 | Medium | 0.3% | 7.8 | Improper authorization in Windows Installer allows an authorized attacker to ele… | |
| CVE-2026-20808 | Medium | 0.3% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20814 | Medium | 0.3% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20815 | Medium | 0.3% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20836 | Medium | 0.3% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20858 | Medium | 0.3% | 7.8 | Use after free in Windows Management Services allows an authorized attacker to e… | |
| CVE-2026-20861 | Medium | 0.3% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20866 | Medium | 0.3% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20867 | Medium | 0.3% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20869 | Medium | 0.3% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20873 | Medium | 0.3% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20874 | Medium | 0.3% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-70354 | Medium | 0.3% | 7.8 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code loca… | |
| CVE-2026-32221 | Medium | 0.3% | 8.4 | Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorize… | |
| CVE-2026-41092 | Medium | 0.3% | 7.8 | Improper access control in Microsoft Kinect allows an authorized attacker to ele… | |
| CVE-2026-56174 | Medium | 0.3% | 7.8 | Untrusted search path in Windows Narrator Braille allows an authorized attacker … | |
| CVE-2026-62812 | Medium | 0.3% | 7.8 | Improper link resolution before file access ('link following') in Windows DHCP S… | |
| CVE-2026-83995 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elev… | |
| CVE-2026-42910 | Medium | 0.3% | 7.8 | Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized … | |
| CVE-2026-42983 | Medium | 0.3% | 7.8 | Use after free in Windows DWM Core Library allows an authorized attacker to elev… | |
| CVE-2026-45592 | Medium | 0.3% | 7.8 | Integer overflow or wraparound in Windows Internet (wininet.dll) allows an autho… | |
| CVE-2026-45593 | Medium | 0.3% | 7.8 | Use after free in Windows SDK allows an authorized attacker to elevate privilege… | |
| CVE-2026-45600 | Medium | 0.3% | 7.8 | Access of resource using incompatible type ('type confusion') in Windows Kernel-… | |
| CVE-2026-45605 | Medium | 0.3% | 7.8 | Use after free in Windows Bluetooth Service allows an authorized attacker to ele… | |
| CVE-2026-45637 | Medium | 0.3% | 7.8 | Use after free in Windows DWM Core Library allows an authorized attacker to elev… | |
| CVE-2026-45638 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allo… | |
| CVE-2026-69911 | Medium | 0.3% | 7.0 | Use after free in Microsoft Windows Search Component allows an authorized attack… | |
| CVE-2026-50307 | Medium | 0.3% | 7.0 | Use after free in Windows TCP/IP allows an authorized attacker to elevate privil… | |
| CVE-2026-50358 | Medium | 0.3% | 7.0 | Use after free in Windows Media allows an authorized attacker to elevate privile… | |
| CVE-2026-50359 | Medium | 0.3% | 7.0 | Use after free in Microsoft XML Core Services allows an authorized attacker to e… | |
| CVE-2026-50390 | Medium | 0.3% | 7.0 | Access of resource using incompatible type ('type confusion') in Windows Kernel … | |
| CVE-2026-50393 | Medium | 0.3% | 7.0 | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to e… | |
| CVE-2026-50396 | Medium | 0.3% | 7.0 | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to e… | |
| CVE-2026-50476 | Medium | 0.3% | 7.8 | Use after free in Microsoft Windows allows an authorized attacker to elevate pri… |