microsoft / windows_server_2019
1,452 known vulnerabilities in microsoft windows_server_2019.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2022-41091 | Act now | 1.8% | 5.4 | ● | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2026-85880 | Act now | 0.6% | 7.8 | ● | Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elev… |
| CVE-2023-36899 | High | 76.7% | 8.8 | ASP.NET Elevation of Privilege Vulnerability | |
| CVE-2021-26424 | High | 61.1% | 9.9 | Windows TCP/IP Remote Code Execution Vulnerability | |
| CVE-2026-49160 | High | 53.8% | 7.5 | Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to d… | |
| CVE-2021-34481 | Medium | 47.7% | 8.8 | A remote code execution vulnerability exists when the Windows Print Spooler serv… | |
| CVE-2023-21818 | Medium | 43.2% | 7.5 | Windows Secure Channel Denial of Service Vulnerability | |
| CVE-2021-34480 | Medium | 33.9% | 6.8 | Scripting Engine Memory Corruption Vulnerability | |
| CVE-2023-21819 | Medium | 30.8% | 7.5 | Windows Secure Channel Denial of Service Vulnerability | |
| CVE-2023-21690 | Medium | 27.5% | 9.8 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execut… | |
| CVE-2024-21357 | Medium | 26.9% | 8.1 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | |
| CVE-2023-21689 | Medium | 26.5% | 9.8 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execut… | |
| CVE-2026-47291 | Medium | 22.8% | 9.8 | Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attack… | |
| CVE-2024-43454 | Medium | 21.9% | 7.1 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | |
| CVE-2021-34535 | Medium | 21.7% | 8.8 | Remote Desktop Client Remote Code Execution Vulnerability | |
| CVE-2023-21692 | Medium | 21.2% | 9.8 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execut… | |
| CVE-2026-20872 | Medium | 20.1% | 6.5 | External control of file name or path in Windows NTLM allows an unauthorized att… | |
| CVE-2026-20925 | Medium | 18.2% | 6.5 | External control of file name or path in Windows NTLM allows an unauthorized att… | |
| CVE-2021-26877 | Medium | 16.5% | 9.8 | Windows DNS Server Remote Code Execution Vulnerability | |
| CVE-2020-1048 | Medium | 16.4% | 7.8 | An elevation of privilege vulnerability exists when the Windows Print Spooler se… | |
| CVE-2020-1118 | Medium | 16.2% | 8.6 | A denial of service vulnerability exists in the Windows implementation of Transp… | |
| CVE-2021-38666 | Medium | 15.1% | 8.8 | Remote Desktop Client Remote Code Execution Vulnerability | |
| CVE-2021-26863 | Medium | 11.8% | 7.0 | Windows Win32k Elevation of Privilege Vulnerability | |
| CVE-2021-26897 | Medium | 11.6% | 9.8 | Windows DNS Server Remote Code Execution Vulnerability | |
| CVE-2021-26432 | Medium | 11.3% | 9.8 | Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability | |
| CVE-2024-21371 | Medium | 10.9% | 7.0 | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2023-36900 | Medium | 10.6% | 7.8 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2023-35359 | Medium | 9.9% | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2022-41113 | Medium | 8.7% | 7.8 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | |
| CVE-2026-20860 | Medium | 8.4% | 7.8 | Access of resource using incompatible type ('type confusion') in Windows Ancilla… | |
| CVE-2022-41109 | Medium | 8.1% | 7.8 | Windows Win32k Elevation of Privilege Vulnerability | |
| CVE-2021-36947 | Medium | 7.5% | 8.8 | Windows Print Spooler Remote Code Execution Vulnerability | |
| CVE-2021-36936 | Medium | 7.4% | 8.8 | Windows Print Spooler Remote Code Execution Vulnerability | |
| CVE-2021-26896 | Medium | 7.4% | 7.5 | Windows DNS Server Denial of Service Vulnerability | |
| CVE-2021-26894 | Medium | 7.3% | 9.8 | Windows DNS Server Remote Code Execution Vulnerability | |
| CVE-2021-26895 | Medium | 7.3% | 9.8 | Windows DNS Server Remote Code Execution Vulnerability | |
| CVE-2021-26893 | Medium | 7.0% | 9.8 | Windows DNS Server Remote Code Execution Vulnerability | |
| CVE-2021-38665 | Medium | 7.0% | 7.4 | Remote Desktop Protocol Client Information Disclosure Vulnerability | |
| CVE-2026-42980 | Medium | 6.9% | 7.8 | Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authori… | |
| CVE-2021-27063 | Medium | 6.3% | 7.5 | Windows DNS Server Denial of Service Vulnerability | |
| CVE-2020-1108 | Medium | 6.3% | 7.5 | A denial of service vulnerability exists when .NET Core or .NET Framework improp… | |
| CVE-2020-1062 | Medium | 6.2% | 7.5 | A remote code execution vulnerability exists when Internet Explorer improperly a… | |
| CVE-2024-38244 | Medium | 6.2% | 7.8 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | |
| CVE-2024-38241 | Medium | 6.0% | 7.8 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | |
| CVE-2023-35382 | Medium | 5.6% | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2023-35386 | Medium | 5.5% | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2021-26435 | Medium | 5.3% | 8.1 | Windows Scripting Engine Memory Corruption Vulnerability | |
| CVE-2026-20840 | Medium | 4.7% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to exec… | |
| CVE-2021-36965 | Medium | 4.6% | 8.8 | Windows WLAN AutoConfig Service Remote Code Execution Vulnerability | |
| CVE-2020-0909 | Medium | 4.6% | 7.5 | A denial of service vulnerability exists when Hyper-V on a Windows Server fails … |