cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 207 of 227
CVE-2026-45606P4MEDIUMCVSS 5.5fixed in 10.0.14393.9234≥ 10.0.14393.0, < 10.0.14393.92342026-06-09
CVE-2026-45606 [MEDIUM] CWE-125 CVE-2026-45606: Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.
nvd
CVE-2018-8201P4MEDIUMCVSS 4.5v1709v1803+1 more2018-06-14
CVE-2018-8201 [MEDIUM] CVE-2018-8201: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to injec A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8211, CVE-2018-8212, CVE-20
nvd
CVE-2026-50684P4MEDIUMCVSS 4.8fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50684 [MEDIUM] CWE-79 CVE-2026-50684: Improper neutralization of input during web page generation ('cross-site scripting') in Active Direc Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2025-58719P4MEDIUMCVSS 4.7fixed in 10.0.14393.8519≥ 10.0.14393.0, < 10.0.14393.85192025-10-14
CVE-2025-58719 [MEDIUM] CWE-416 CVE-2025-58719: Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to eleva Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-29056P4MEDIUMCVSS 4.3≤ 10.0.14393.6897≥ 10.0.14393.0, < 10.0.14393.68972024-04-09
CVE-2024-29056 [MEDIUM] CWE-327 CVE-2024-29056: Windows Authentication Elevation of Privilege Vulnerability Windows Authentication Elevation of Privilege Vulnerability
nvd
CVE-2026-32209P4MEDIUMCVSS 4.4fixed in 10.0.14393.9140≥ 10.0.14393.0, < 10.0.14393.91402026-05-12
CVE-2026-32209 [MEDIUM] CWE-284 CVE-2026-32209: Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2024-38234P4MEDIUMCVSS 6.5fixed in 10.0.14393.7336≥ 10.0.14393.0, < 10.0.14393.73362024-09-10
CVE-2024-38234 [MEDIUM] CWE-20 CVE-2024-38234: Windows Networking Denial of Service Vulnerability Windows Networking Denial of Service Vulnerability
nvd
CVE-2020-0617P4MEDIUMCVSS 6.0v18032020-01-14
CVE-2020-0617 [MEDIUM] CWE-20 CVE-2020-0617: A denial of service vulnerability exists when Microsoft Hyper-V Virtual PCI on a host server fails t A denial of service vulnerability exists when Microsoft Hyper-V Virtual PCI on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Hyper-V Denial of Service Vulnerability'.
nvd
CVE-2025-21347P4MEDIUMCVSS 6.0fixed in 10.0.14393.7785≥ 10.0.14393.0, < 10.0.14393.77852025-02-11
CVE-2025-21347 [MEDIUM] CWE-59 CVE-2025-21347: Windows Deployment Services Denial of Service Vulnerability Windows Deployment Services Denial of Service Vulnerability
nvd
CVE-2018-8309P4MEDIUMCVSS 5.5v1709v1803+1 more2018-07-11
CVE-2018-8309 [MEDIUM] CVE-2018-8309: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Win A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Windows Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8205P4MEDIUMCVSS 5.5v1709v1803+1 more2018-06-14
CVE-2018-8205 [MEDIUM] CVE-2018-8205: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Win A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Windows Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2022-34710P4MEDIUMCVSS 5.5v20h2≥ 10.0.14393.0, < 10.0.14393.52912022-08-09
CVE-2022-34710 [MEDIUM] CWE-200 CVE-2022-34710: Windows Defender Credential Guard Information Disclosure Vulnerability Windows Defender Credential Guard Information Disclosure Vulnerability
nvd
CVE-2022-34712P4MEDIUMCVSS 5.5v20h22022-08-09
CVE-2022-34712 [MEDIUM] CWE-200 CVE-2022-34712: Windows Defender Credential Guard Information Disclosure Vulnerability Windows Defender Credential Guard Information Disclosure Vulnerability
nvd
CVE-2019-1325P4MEDIUMCVSS 5.5v1803v19032019-10-10
CVE-2019-1325 [MEDIUM] CVE-2019-1325: An elevation of privilege vulnerability exists in the Windows redirected drive buffering system (rdb An elevation of privilege vulnerability exists in the Windows redirected drive buffering system (rdbss.sys) when the operating system improperly handles specific local calls within Windows 7 for 32-bit systems, aka 'Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0714P4MEDIUMCVSS 5.5v1803v1903+1 more2020-02-11
CVE-2020-0714 [MEDIUM] CVE-2020-0714: An information disclosure vulnerability exists when DirectX improperly handles objects in memory, ak An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Information Disclosure Vulnerability'.
nvd
CVE-2022-34708P4MEDIUMCVSS 5.5v20h2≥ 10.0.14393.0, < 10.0.14393.52912022-08-09
CVE-2022-34708 [MEDIUM] CWE-200 CVE-2022-34708: Windows Kernel Information Disclosure Vulnerability Windows Kernel Information Disclosure Vulnerability
nvd
CVE-2020-17094P4MEDIUMCVSS 5.5v20h2v1903+2 more2020-12-10
CVE-2020-17094 [MEDIUM] CVE-2020-17094: Windows Error Reporting Information Disclosure Vulnerability Windows Error Reporting Information Disclosure Vulnerability
nvd
CVE-2020-17030P4MEDIUMCVSS 5.5v20h2v1903+2 more2020-11-11
CVE-2020-17030 [MEDIUM] CVE-2020-17030: Windows MSCTF Server Information Disclosure Vulnerability Windows MSCTF Server Information Disclosure Vulnerability
nvd
CVE-2020-17036P4MEDIUMCVSS 5.5v20h2v1903+3 more2020-11-11
CVE-2020-17036 [MEDIUM] CVE-2020-17036: Windows Function Discovery SSDP Provider Information Disclosure Vulnerability Windows Function Discovery SSDP Provider Information Disclosure Vulnerability
nvd
CVE-2020-1016P4MEDIUMCVSS 5.5v1803v1903+1 more2020-04-15
CVE-2020-1016 [MEDIUM] CVE-2020-1016: An information disclosure vulnerability exists when the Windows Push Notification Service improperly An information disclosure vulnerability exists when the Windows Push Notification Service improperly handles objects in memory, aka 'Windows Push Notification Service Information Disclosure Vulnerability'.
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase