Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 163 of 227
CVE-2019-0961P3MEDIUMCVSS 6.5v1803v19032019-05-16
CVE-2019-0961 [MEDIUM] CVE-2019-0961: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0758, CVE-2019-0882.
nvd
CVE-2019-0882P3MEDIUMCVSS 6.5v1803v19032019-05-16
CVE-2019-0882 [MEDIUM] CVE-2019-0882: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0758, CVE-2019-0961.
nvd
CVE-2019-0774P3MEDIUMCVSS 6.5v1709v18032019-04-09
CVE-2019-0774 [MEDIUM] CVE-2019-0774: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0614.
nvd
CVE-2025-49681P3MEDIUMCVSS 6.5fixed in 10.0.14393.8246≥ 10.0.14393.0, < 10.0.14393.82462025-07-08
CVE-2025-49681 [MEDIUM] CWE-125 CVE-2025-49681: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2019-1094P3MEDIUMCVSS 6.5v1803v19032019-07-15
CVE-2019-1094 [MEDIUM] CWE-200 CVE-2019-1094: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1095, CVE-2019-1098, CVE-2019-1099, CVE-2019-1100, CVE-2019-1101, CVE-2019-1116.
nvd
CVE-2019-1095P3MEDIUMCVSS 6.5v1803v19032019-07-15
CVE-2019-1095 [MEDIUM] CVE-2019-1095: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1098, CVE-2019-1099, CVE-2019-1100, CVE-2019-1101, CVE-2019-1116.
nvd
CVE-2020-0853P4MEDIUMCVSS 6.5v1803v1903+1 more2020-03-12
CVE-2020-0853 [MEDIUM] CVE-2020-0853: An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails t
An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails to properly handle objects in memory, aka 'Windows Imaging Component Information Disclosure Vulnerability'.
nvd
CVE-2019-1230P4MEDIUMCVSS 6.8v18032019-10-10
CVE-2019-1230 [MEDIUM] CWE-20 CVE-2019-1230: An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host ope
An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Information Disclosure Vulnerability'.
nvd
CVE-2026-27925P4MEDIUMCVSS 6.5fixed in 10.0.14393.9060≥ 10.0.14393.0, < 10.0.14393.90602026-04-14
CVE-2026-27925 [MEDIUM] CWE-416 CVE-2026-27925: Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network.
nvd
CVE-2021-38665P4MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.14393.47702021-11-10
CVE-2021-38665 [MEDIUM] CVE-2021-38665: Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability
nvd
CVE-2019-0704P3MEDIUMCVSS 6.5v1709v18032019-04-09
CVE-2019-0704 [MEDIUM] CVE-2019-0704: An information disclosure vulnerability exists in the way that the Windows SMB Server handles certai
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0703, CVE-2019-0821.
nvd
CVE-2019-1025P3MEDIUMCVSS 6.5v1803v1903+1 more2019-06-12
CVE-2019-1025 [MEDIUM] CVE-2019-1025: A denial of service vulnerability exists when Windows improperly handles objects in memory. An attac
A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application or to convince a user to open a specif
nvd
CVE-2023-21677P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.56482023-01-10
CVE-2023-21677 [HIGH] CWE-822 CVE-2023-21677: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2023-21683P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.56482023-01-10
CVE-2023-21683 [HIGH] CWE-476 CVE-2023-21683: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2023-21527P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.56482023-01-10
CVE-2023-21527 [HIGH] CWE-191 CVE-2023-21527: Windows iSCSI Service Denial of Service Vulnerability
Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2023-35330P4HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-35330 [HIGH] CWE-126 CVE-2023-35330: Windows Extended Negotiation Denial of Service Vulnerability
Windows Extended Negotiation Denial of Service Vulnerability
nvd
CVE-2023-21811P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.57172023-02-14
CVE-2023-21811 [HIGH] CWE-126 CVE-2023-21811: Windows iSCSI Service Denial of Service Vulnerability
Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2023-21700P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.57172023-02-14
CVE-2023-21700 [HIGH] CWE-476 CVE-2023-21700: Windows iSCSI Discovery Service Denial of Service Vulnerability
Windows iSCSI Discovery Service Denial of Service Vulnerability
nvd
CVE-2023-21702P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.57172023-02-14
CVE-2023-21702 [HIGH] CWE-125 CVE-2023-21702: Windows iSCSI Service Denial of Service Vulnerability
Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2023-20588P4MEDIUMCVSS 5.5fixed in 10.0.14393.65292023-08-08
CVE-2023-20588 [MEDIUM] CWE-369 CVE-2023-20588: A division-by-zero error on some AMD processors can potentially return speculative data resulting i
A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality.
nvd