cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 186 of 227
CVE-2025-21228P4MEDIUMCVSS 6.6fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21228 [MEDIUM] CWE-125 CVE-2025-21228: Windows Digital Media Elevation of Privilege Vulnerability Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21258P4MEDIUMCVSS 6.6fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21258 [MEDIUM] CWE-125 CVE-2025-21258: Windows Digital Media Elevation of Privilege Vulnerability Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21232P4MEDIUMCVSS 6.6fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21232 [MEDIUM] CWE-125 CVE-2025-21232: Windows Digital Media Elevation of Privilege Vulnerability Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21255P4MEDIUMCVSS 6.6fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21255 [MEDIUM] CWE-125 CVE-2025-21255: Windows Digital Media Elevation of Privilege Vulnerability Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21324P4MEDIUMCVSS 6.6fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21324 [MEDIUM] CWE-125 CVE-2025-21324: Windows Digital Media Elevation of Privilege Vulnerability Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21227P4MEDIUMCVSS 6.6fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21227 [MEDIUM] CWE-125 CVE-2025-21227: Windows Digital Media Elevation of Privilege Vulnerability Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21229P4MEDIUMCVSS 6.6fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21229 [MEDIUM] CWE-125 CVE-2025-21229: Windows Digital Media Elevation of Privilege Vulnerability Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21310P4MEDIUMCVSS 6.6fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21310 [MEDIUM] CWE-125 CVE-2025-21310: Windows Digital Media Elevation of Privilege Vulnerability Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21263P4MEDIUMCVSS 6.6fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21263 [MEDIUM] CWE-125 CVE-2025-21263: Windows Digital Media Elevation of Privilege Vulnerability Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21327P4MEDIUMCVSS 6.6fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21327 [MEDIUM] CWE-125 CVE-2025-21327: Windows Digital Media Elevation of Privilege Vulnerability Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21265P4MEDIUMCVSS 6.6fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21265 [MEDIUM] CWE-125 CVE-2025-21265: Windows Digital Media Elevation of Privilege Vulnerability Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21261P4MEDIUMCVSS 6.6fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21261 [MEDIUM] CWE-125 CVE-2025-21261: Windows Digital Media Elevation of Privilege Vulnerability Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21341P4MEDIUMCVSS 6.6fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21341 [MEDIUM] CWE-125 CVE-2025-21341: Windows Digital Media Elevation of Privilege Vulnerability Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2020-1055P4MEDIUMCVSS 6.1v1903v19092020-05-21
CVE-2020-1055 [MEDIUM] CWE-79 CVE-2020-1055: A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) d A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize user inputs, aka 'Microsoft Active Directory Federation Services Cross-Site Scripting Vulnerability'.
nvd
CVE-2019-1187P4MEDIUMCVSS 5.5v1803v1903+1 more2019-08-14
CVE-2019-1187 [MEDIUM] CWE-611 CVE-2019-1187: A denial of service vulnerability exists when the XmlLite runtime (XmlLite.dll) improperly parses XM A denial of service vulnerability exists when the XmlLite runtime (XmlLite.dll) improperly parses XML input. An attacker who successfully exploited this vulnerability could cause a denial of service against an XML application. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to an XML application
nvd
CVE-2021-26866P4MEDIUMCVSS 6.1v20h2v1909+2 more2021-03-11
CVE-2021-26866 [MEDIUM] CWE-59 CVE-2021-26866: Windows Update Service Elevation of Privilege Vulnerability Windows Update Service Elevation of Privilege Vulnerability
nvd
CVE-2022-41086P4MEDIUMCVSS 6.4≥ 10.0.14393.0, < 10.0.14393.55012022-11-09
CVE-2022-41086 [MEDIUM] CWE-362 CVE-2022-41086: Windows Group Policy Elevation of Privilege Vulnerability Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2020-16938P4MEDIUMCVSS 5.5v20042020-10-16
CVE-2020-16938 [MEDIUM] CVE-2020-16938: <p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.
nvd
CVE-2018-0754P4MEDIUMCVSS 5.5v17092018-01-04
CVE-2018-0754 [MEDIUM] CVE-2018-0754: The Windows Adobe Type Manager Font Driver (Atmfd.dll) in Windows 7 SP1, Windows 8.1 and RT 8.1, Win The Windows Adobe Type Manager Font Driver (Atmfd.dll) in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way objects are handled in memory, aka "OpenT
nvd
CVE-2022-24503P4MEDIUMCVSS 5.3≥ 10.0.14393.0, < 10.0.14393.50062022-03-09
CVE-2022-24503 [MEDIUM] CVE-2022-24503: Remote Desktop Protocol Client Information Disclosure Vulnerability Remote Desktop Protocol Client Information Disclosure Vulnerability
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase