microsoft / windows_server_2025
1,131 known vulnerabilities in microsoft windows_server_2025.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-72979 | Medium | 1.0% | 9.8 | Use after free in Windows DHCP Server allows an unauthorized attacker to execute… | |
| CVE-2026-47289 | Medium | 1.0% | 8.8 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac… | |
| CVE-2026-70296 | Medium | 1.0% | 9.8 | Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker… | |
| CVE-2026-77493 | Medium | 1.0% | 9.8 | Double free in Microsoft Graphics Component allows an unauthorized attacker to e… | |
| CVE-2026-62784 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv)… | |
| CVE-2026-62800 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker t… | |
| CVE-2026-69845 | Medium | 0.9% | 9.8 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacke… | |
| CVE-2026-50682 | Medium | 0.9% | 7.1 | Out-of-bounds read in Windows Active Directory allows an authorized attacker to … | |
| CVE-2026-69551 | Medium | 0.9% | 8.8 | Use after free in Windows DNS allows an authorized attacker to execute code over… | |
| CVE-2026-49178 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Active Directory Domain Services allows an authori… | |
| CVE-2026-50666 | Medium | 0.9% | 8.8 | Use after free in Windows Remote Access Connection Manager allows an authorized … | |
| CVE-2026-56194 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Windows Network File System allows an authorized a… | |
| CVE-2026-56647 | Medium | 0.9% | 8.8 | Integer overflow or wraparound in Windows Remote Access Service Infrastructure a… | |
| CVE-2026-57092 | Medium | 0.9% | 9.9 | Use after free in Windows VMSwitch allows an authorized attacker to elevate priv… | |
| CVE-2026-58626 | Medium | 0.9% | 8.8 | Use after free in Windows Remote Desktop Services allows an authorized attacker … | |
| CVE-2026-69463 | Medium | 0.9% | 9.8 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to ex… | |
| CVE-2026-73025 | Medium | 0.9% | 9.8 | Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a… | |
| CVE-2026-69491 | Medium | 0.9% | 9.8 | Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthoriz… | |
| CVE-2026-78445 | Medium | 0.9% | 9.8 | Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthori… | |
| CVE-2026-73009 | Medium | 0.9% | 9.8 | Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unau… | |
| CVE-2026-73010 | Medium | 0.9% | 9.8 | Use after free in Windows Failover Cluster allows an unauthorized attacker to ex… | |
| CVE-2026-65681 | Medium | 0.9% | 7.5 | Null pointer dereference in Windows iSCSI Target Service allows an unauthorized … | |
| CVE-2026-42908 | Medium | 0.9% | 7.5 | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose in… | |
| CVE-2026-45639 | Medium | 0.9% | 7.5 | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose in… | |
| CVE-2026-83989 | Medium | 0.9% | 7.5 | Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unaut… | |
| CVE-2026-40400 | Medium | 0.9% | 8.0 | Relative path traversal in Windows PowerShell allows an authorized attacker to e… | |
| CVE-2026-20931 | Medium | 0.9% | 8.0 | External control of file name or path in Windows Telephony Service allows an aut… | |
| CVE-2026-77499 | Medium | 0.9% | 7.5 | Access of resource using incompatible type ('type confusion') in Windows DHCP Se… | |
| CVE-2026-77890 | Medium | 0.9% | 7.5 | Access of resource using incompatible type ('type confusion') in Windows DHCP Se… | |
| CVE-2026-71336 | Medium | 0.9% | 8.8 | Integer overflow or wraparound in Windows Work Folder Service allows an authoriz… | |
| CVE-2026-77888 | Medium | 0.9% | 7.5 | Access of resource using incompatible type ('type confusion') in Windows DHCP Se… | |
| CVE-2026-77889 | Medium | 0.9% | 7.5 | Access of resource using incompatible type ('type confusion') in Windows DHCP Se… | |
| CVE-2026-70563 | Medium | 0.8% | 8.1 | Improper link resolution before file access ('link following') in Windows Shell … | |
| CVE-2026-70342 | Medium | 0.8% | 8.1 | Use after free in Windows Ancillary Function Driver for WinSock allows an unauth… | |
| CVE-2026-33827 | Medium | 0.8% | 8.1 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-62785 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protoc… | |
| CVE-2026-49179 | Medium | 0.8% | 8.8 | Improper neutralization of special elements used in a command ('command injectio… | |
| CVE-2026-50380 | Medium | 0.8% | 9.6 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to ex… | |
| CVE-2026-50474 | Medium | 0.8% | 8.8 | Use after free in Remote Desktop Client allows an unauthorized attacker to execu… | |
| CVE-2026-54990 | Medium | 0.8% | 9.8 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac… | |
| CVE-2026-57090 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unaut… | |
| CVE-2026-57094 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unaut… | |
| CVE-2026-58594 | Medium | 0.8% | 8.8 | Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to… | |
| CVE-2026-69669 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to … | |
| CVE-2026-77501 | Medium | 0.8% | 7.5 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to den… | |
| CVE-2026-68887 | Medium | 0.8% | 7.5 | Out-of-bounds read in Windows Message Queuing Queue Manager allows an unauthoriz… | |
| CVE-2026-77498 | Medium | 0.8% | 7.5 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to den… | |
| CVE-2026-77502 | Medium | 0.8% | 7.5 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to den… | |
| CVE-2026-77886 | Medium | 0.8% | 7.5 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to den… | |
| CVE-2026-77893 | Medium | 0.8% | 7.5 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to den… |