cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 69 of 227
CVE-2025-27484P3HIGHCVSS 7.5fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-27484 [HIGH] CWE-591 CVE-2025-27484: Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-50470P3HIGHCVSS 7.5fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50470 [HIGH] CWE-125 CVE-2026-50470: Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2019-1247P3HIGHCVSS 7.8v1803v19032019-09-11
CVE-2019-1247 [HIGH] CVE-2019-1247: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1240, CVE-2019-1241, CVE-2019-1242, CVE-2019-1243, CVE-2019-1246, CVE-2019-1248, CVE-2019-1249, CVE-2019-1250.
nvd
CVE-2019-1240P3HIGHCVSS 7.8v1803v19032019-09-11
CVE-2019-1240 [HIGH] CVE-2019-1240: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1241, CVE-2019-1242, CVE-2019-1243, CVE-2019-1246, CVE-2019-1247, CVE-2019-1248, CVE-2019-1249, CVE-2019-1250.
nvd
CVE-2019-1249P3HIGHCVSS 7.8v1803v19032019-09-11
CVE-2019-1249 [HIGH] CVE-2019-1249: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1240, CVE-2019-1241, CVE-2019-1242, CVE-2019-1243, CVE-2019-1246, CVE-2019-1247, CVE-2019-1248, CVE-2019-1250.
nvd
CVE-2019-1242P3HIGHCVSS 7.8v1803v19032019-09-11
CVE-2019-1242 [HIGH] CVE-2019-1242: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1240, CVE-2019-1241, CVE-2019-1243, CVE-2019-1246, CVE-2019-1247, CVE-2019-1248, CVE-2019-1249, CVE-2019-1250.
nvd
CVE-2019-1248P3HIGHCVSS 7.8v1803v19032019-09-11
CVE-2019-1248 [HIGH] CVE-2019-1248: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1240, CVE-2019-1241, CVE-2019-1242, CVE-2019-1243, CVE-2019-1246, CVE-2019-1247, CVE-2019-1249, CVE-2019-1250.
nvd
CVE-2018-8439P3HIGHCVSS 8.4v1709v18032018-09-13
CVE-2018-8439 [HIGH] CVE-2018-8439: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. This CVE ID i
nvd
CVE-2018-8489P3HIGHCVSS 8.4v1709v1803+1 more2018-10-10
CVE-2018-8489 [HIGH] CWE-20 CVE-2018-8489: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012
nvd
CVE-2023-38144P3HIGHCVSS 7.8fixed in 10.0.14393.6252≥ 10.0.14393.0, < 10.0.14393.62522023-09-12
CVE-2023-38144 [HIGH] CWE-126 CVE-2023-38144: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-21557P3CRITICALCVSS 9.1≥ 10.0.14393.0, < 10.0.14393.56482023-01-10
CVE-2023-21557 [CRITICAL] CWE-190 CVE-2023-21557: Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
nvd
CVE-2024-38085P3HIGHCVSS 7.8fixed in 10.0.14393.7159≥ 10.0.14393.0, < 10.0.14393.71592024-07-09
CVE-2024-38085 [HIGH] CWE-416 CVE-2024-38085: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2022-30220P3HIGHCVSS 7.8v20h2≥ 10.0.14393.0, < 10.0.14393.52462022-07-12
CVE-2022-30220 [HIGH] CVE-2022-30220: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-21974P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.49462022-02-09
CVE-2022-21974 [HIGH] CVE-2022-21974: Roaming Security Rights Management Services Remote Code Execution Vulnerability Roaming Security Rights Management Services Remote Code Execution Vulnerability
nvd
CVE-2020-16894P3HIGHCVSS 7.7≥ 10.0.0, < publication2020-10-16
CVE-2020-16894 [HIGH] CVE-2020-16894: <p>A denial of service vulnerability exists when Windows Network Address Translation (NAT) on a host A denial of service vulnerability exists when Windows Network Address Translation (NAT) on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. To exploit the vulnerability, an attacker who already has a privileged accou
nvd
CVE-2024-30032P3HIGHCVSS 7.8fixed in 10.0.14393.6981≥ 10.0.14393.0, < 10.0.14393.69812024-05-14
CVE-2024-30032 [HIGH] CWE-416 CVE-2024-30032: Windows DWM Core Library Elevation of Privilege Vulnerability Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2024-20653P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.66142024-01-09
CVE-2024-20653 [HIGH] CWE-125 CVE-2024-20653: Microsoft Common Log File System Elevation of Privilege Vulnerability Microsoft Common Log File System Elevation of Privilege Vulnerability
nvd
CVE-2023-38143P3HIGHCVSS 7.8fixed in 10.0.14393.6252≥ 10.0.14393.0, < 10.0.14393.62522023-09-12
CVE-2023-38143 [HIGH] CWE-122 CVE-2023-38143: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-23388P3HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.57862023-03-14
CVE-2023-23388 [HIGH] CWE-681 CVE-2023-23388: Windows Bluetooth Driver Elevation of Privilege Vulnerability Windows Bluetooth Driver Elevation of Privilege Vulnerability
nvd
CVE-2020-1355P3HIGHCVSS 7.8v1903v1909+1 more2020-07-14
CVE-2020-1355 [HIGH] CWE-20 CVE-2020-1355: A remote code execution vulnerability exists when the Windows Font Driver Host improperly handles me A remote code execution vulnerability exists when the Windows Font Driver Host improperly handles memory.An attacker who successfully exploited the vulnerability would gain execution on a victim system.The security update addresses the vulnerability by correcting how the Windows Font Driver Host handles memory., aka 'Windows Font Driver Host Remote Code
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase