cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
175
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 16 of 227
CVE-2025-53143P2HIGHCVSS 8.8fixed in 10.0.14393.8330≥ 10.0.14393.0, < 10.0.14393.83302025-08-12
CVE-2025-53143 [HIGH] CWE-843 CVE-2025-53143: Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an a Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
nvd
CVE-2023-28302P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.58502023-04-11
CVE-2023-28302 [HIGH] CWE-20 CVE-2023-28302: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-53145P2HIGHCVSS 8.8fixed in 10.0.14393.8330≥ 10.0.14393.0, < 10.0.14393.83302025-08-12
CVE-2025-53145 [HIGH] CWE-843 CVE-2025-53145: Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an a Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
nvd
CVE-2025-53144P2HIGHCVSS 8.8fixed in 10.0.14393.8330≥ 10.0.14393.0, < 10.0.14393.83302025-08-12
CVE-2025-53144 [HIGH] CWE-843 CVE-2025-53144: Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an a Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
nvd
CVE-2018-8626P2CRITICALCVSS 9.8v1709v1803+1 more2018-12-12
CVE-2018-8626 [CRITICAL] CWE-787 CVE-2018-8626: A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they f A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly handle requests, aka "Windows DNS Server Heap Overflow Vulnerability." This affects Windows Server 2012 R2, Windows Server 2019, Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2023-36028P2CRITICALCVSS 9.8≥ 10.0.14393.0, < 10.0.14393.64522023-11-14
CVE-2023-36028 [CRITICAL] CWE-122 CVE-2023-36028: Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
nvd
CVE-2019-0555P3HIGHCVSS 7.8PoCv1709v18032019-01-08
CVE-2019-0555 [HIGH] CWE-862 CVE-2019-0555: An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow a An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft XmlDocument Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 2016, Window
nvd
CVE-2019-1343P3MEDIUMCVSS 6.5PoCv1803v19032019-10-10
CVE-2019-1343 [MEDIUM] CVE-2019-1343: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1346, CVE-2019-1347.
nvd
CVE-2019-1346P3MEDIUMCVSS 6.5PoCv1803v19032019-10-10
CVE-2019-1346 [MEDIUM] CVE-2019-1346: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1343, CVE-2019-1347.
nvd
CVE-2021-26895P2CRITICALCVSS 9.8v20h2v1909+2 more2021-03-11
CVE-2021-26895 [CRITICAL] CVE-2021-26895: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2021-26894P2CRITICALCVSS 9.8v20h2v1909+2 more2021-03-11
CVE-2021-26894 [CRITICAL] CVE-2021-26894: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2021-36936P2CRITICALCVSS 9.8v20h2v2004+1 more2021-08-12
CVE-2021-36936 [CRITICAL] CVE-2021-36936: Windows Print Spooler Remote Code Execution Vulnerability Windows Print Spooler Remote Code Execution Vulnerability
nvd
CVE-2021-26893P2CRITICALCVSS 9.8v20h2v1909+2 more2021-03-11
CVE-2021-26893 [CRITICAL] CVE-2021-26893: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2019-1358P3HIGHCVSS 7.8v1803v19032019-10-10
CVE-2019-1358 [HIGH] CVE-2019-1358: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1359.
nvd
CVE-2023-21769P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.58502023-04-11
CVE-2023-21769 [HIGH] CWE-125 CVE-2023-21769: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2023-24943P2CRITICALCVSS 9.8≥ 10.0.14393.0, < 10.0.14393.59212023-05-09
CVE-2023-24943 [CRITICAL] CWE-122 CVE-2023-24943: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2022-21990P2HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.50062022-03-09
CVE-2022-21990 [HIGH] CVE-2022-21990: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2021-26432P2CRITICALCVSS 9.8v20h2v2004+1 more2021-08-12
CVE-2021-26432 [CRITICAL] CVE-2021-26432: Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
nvd
CVE-2021-34535P2HIGHCVSS 8.8≥ 10.0.0, < 10.0.14393.45832021-08-12
CVE-2021-34535 [HIGH] CVE-2021-34535: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2024-38140P2CRITICALCVSS 9.8fixed in 10.0.14393.7259≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38140 [CRITICAL] CWE-416 CVE-2024-38140: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase