microsoft / windows_server_2025
1,131 known vulnerabilities in microsoft windows_server_2025.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-62725 | Medium | 0.2% | 7.0 | Use after free in Windows Telephony Service allows an authorized attacker to ele… | |
| CVE-2026-62749 | Medium | 0.2% | 7.0 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-62773 | Medium | 0.2% | 7.0 | Use after free in Windows Kerberos allows an authorized attacker to elevate priv… | |
| CVE-2026-62774 | Medium | 0.2% | 7.0 | Use after free in Windows Graphics Kernel allows an authorized attacker to eleva… | |
| CVE-2026-62892 | Medium | 0.2% | 7.0 | Use after free in Capability Access Management Service (camsvc) allows an author… | |
| CVE-2026-69578 | Medium | 0.2% | 7.0 | Numeric truncation error in Windows Kernel allows an authorized attacker to elev… | |
| CVE-2026-73003 | Medium | 0.2% | 7.0 | Use after free in Windows Modern Device Management (MDM) allows an authorized at… | |
| CVE-2026-73022 | Medium | 0.2% | 7.0 | Use after free in Windows Modern Device Management (MDM) allows an authorized at… | |
| CVE-2026-77905 | Medium | 0.2% | 7.0 | Use after free in Windows Management Instrumentation allows an authorized attack… | |
| CVE-2026-78457 | Medium | 0.2% | 7.0 | Use after free in Windows Security Health Service allows an authorized attacker … | |
| CVE-2026-42836 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50349 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-59122 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-59126 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-61927 | Medium | 0.2% | 7.0 | Use after free in Windows Bind Filter Driver allows an authorized attacker to el… | |
| CVE-2026-62690 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-62728 | Medium | 0.2% | 7.0 | Time-of-check time-of-use (toctou) race condition in Windows Common Log File Sys… | |
| CVE-2026-62729 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-62734 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-62748 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-69859 | Medium | 0.2% | 7.0 | Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class dri… | |
| CVE-2026-69319 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-73005 | Medium | 0.2% | 7.0 | Use after free in Windows Authentication Methods allows an authorized attacker t… | |
| CVE-2026-45597 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-42977 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-42979 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-45487 | Medium | 0.2% | 7.8 | Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assis… | |
| CVE-2026-68824 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-62727 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-45596 | Medium | 0.2% | 7.0 | Use after free in Windows Ancillary Function Driver for WinSock allows an author… | |
| CVE-2026-45598 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-45601 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-45603 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-33100 | Medium | 0.2% | 7.0 | Use after free in Windows Ancillary Function Driver for WinSock allows an author… | |
| CVE-2026-42991 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-62908 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-68840 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-77894 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50507 | Low | 5.0% | 6.8 | Missing authentication for critical function in Windows BitLocker allows an unau… | |
| CVE-2026-33829 | Low | 3.4% | 4.3 | Exposure of sensitive information to an unauthorized actor in Windows Snipping T… | |
| CVE-2026-20847 | Low | 1.4% | 6.5 | Exposure of sensitive information to an unauthorized actor in Windows Shell allo… | |
| CVE-2026-45585 | Low | 1.4% | 6.8 | Microsoft is aware of a security feature bypass vulnerability in Windows publicl… | |
| CVE-2026-44806 | Low | 1.2% | 5.3 | Missing release of memory after effective lifetime in Windows Cryptographic Serv… | |
| CVE-2026-20812 | Low | 1.1% | 6.5 | Improper input validation in Windows LDAP - Lightweight Directory Access Protoco… | |
| CVE-2026-49799 | Low | 1.1% | 6.5 | Uncontrolled resource consumption in Windows Local Security Authority Subsystem … | |
| CVE-2026-50366 | Low | 1.1% | 6.5 | Null pointer dereference in Active Directory Domain Services allows an authorize… | |
| CVE-2026-56168 | Low | 1.1% | 6.5 | Null pointer dereference in Windows SMB Server allows an authorized attacker to … | |
| CVE-2026-57976 | Low | 1.1% | 6.5 | Null pointer dereference in Active Directory Domain Services allows an authorize… | |
| CVE-2026-69497 | Low | 1.1% | 6.5 | Missing release of memory after effective lifetime in Windows DHCP Server allows… | |
| CVE-2026-69839 | Low | 1.1% | 6.5 | Uncaught exception in Windows iSCSI Target Service allows an authorized attacker… |