cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 157 of 227
CVE-2023-33172P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-33172 [HIGH] CWE-126 CVE-2023-33172: Remote Procedure Call Runtime Denial of Service Vulnerability Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-33168P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-33168 [HIGH] CWE-126 CVE-2023-33168: Remote Procedure Call Runtime Denial of Service Vulnerability Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-33167P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-33167 [HIGH] CWE-126 CVE-2023-33167: Remote Procedure Call Runtime Denial of Service Vulnerability Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-33166P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-33166 [HIGH] CWE-126 CVE-2023-33166: Remote Procedure Call Runtime Denial of Service Vulnerability Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-32034P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-32034 [HIGH] CWE-125 CVE-2023-32034: Remote Procedure Call Runtime Denial of Service Vulnerability Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-32035P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-32035 [HIGH] CWE-125 CVE-2023-32035: Remote Procedure Call Runtime Denial of Service Vulnerability Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-33169P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-33169 [HIGH] CWE-126 CVE-2023-33169: Remote Procedure Call Runtime Denial of Service Vulnerability Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2019-0802P3MEDIUMCVSS 6.5v1709v18032019-04-09
CVE-2019-0802 [MEDIUM] CVE-2019-0802: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0849.
nvd
CVE-2019-0849P3MEDIUMCVSS 6.5v1709v18032019-04-09
CVE-2019-0849 [MEDIUM] CVE-2019-0849: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0802.
nvd
CVE-2022-22040P3HIGHCVSS 7.3v20h2≥ 10.0.14393.0, < 10.0.14393.52462022-07-12
CVE-2022-22040 [HIGH] CVE-2022-22040: Internet Information Services Dynamic Compression Module Denial of Service Vulnerability Internet Information Services Dynamic Compression Module Denial of Service Vulnerability
nvd
CVE-2023-24948P3HIGHCVSS 7.4≥ 10.0.14393.0, < 10.0.14393.59212023-05-09
CVE-2023-24948 [HIGH] CWE-122 CVE-2023-24948: Windows Bluetooth Driver Elevation of Privilege Vulnerability Windows Bluetooth Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-32054P3HIGHCVSS 7.3≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-32054 [HIGH] CWE-36 CVE-2023-32054: Volume Shadow Copy Elevation of Privilege Vulnerability Volume Shadow Copy Elevation of Privilege Vulnerability
nvd
CVE-2024-21302P3MEDIUMCVSS 6.7fixed in 10.0.14393.7259≥ 10.0.14393.0, < 10.0.14393.82462024-08-08
CVE-2024-21302 [MEDIUM] CWE-284 CVE-2024-21302: Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See K Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtualization-based security related updates and the Recommended Actions section of this CVE for guidance on how to protect your systems from this vulnerability. An elevation of privilege vulnerability exis
nvd
CVE-2025-59208P3HIGHCVSS 7.1≤ 10.0.14393.8519≥ 10.0.14393.0, < 10.0.14393.85192025-10-14
CVE-2025-59208 [HIGH] CWE-125 CVE-2025-59208: Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information o Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2018-8438P4MEDIUMCVSS 6.8v1709v18032018-09-13
CVE-2018-8438 [MEDIUM] CVE-2018-8438: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. This C
nvd
CVE-2025-59282P3HIGHCVSS 7.0fixed in 10.0.14393.8519≥ 10.0.14393.0, < 10.0.14393.85192025-10-14
CVE-2025-59282 [HIGH] CWE-362 CVE-2025-59282: Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-48819P3HIGHCVSS 7.1fixed in 10.0.14393.8246≥ 10.0.14393.0, < 10.0.14393.82462025-07-08
CVE-2025-48819 [HIGH] CWE-591 CVE-2025-48819: Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network.
nvd
CVE-2024-26226P3MEDIUMCVSS 6.5fixed in 10.0.14393.6897≥ 10.0.14393.0, < 10.0.14393.68972024-04-09
CVE-2024-26226 [MEDIUM] CWE-125 CVE-2024-26226: Windows Distributed File System (DFS) Information Disclosure Vulnerability Windows Distributed File System (DFS) Information Disclosure Vulnerability
nvd
CVE-2019-0660P3MEDIUMCVSS 6.5v1709v18032019-03-05
CVE-2019-0660 [MEDIUM] CVE-2019-0660: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0602, CVE-2019-0615, CVE-2019-0616, CVE-2019-0619, CVE-2019-0664.
nvd
CVE-2019-0615P3MEDIUMCVSS 6.5v1709v18032019-03-05
CVE-2019-0615 [MEDIUM] CVE-2019-0615: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0602, CVE-2019-0616, CVE-2019-0619, CVE-2019-0660, CVE-2019-0664.
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase