cbcvebase.

Microsoft Windows Server 2019 vulnerabilities

3,952 known vulnerabilities affecting microsoft/windows_server_2019.

Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16

Vulnerabilities

Page 180 of 198
CVE-2023-35326P4MEDIUMCVSS 5.5≥ 10.0.17763.0, < 10.0.17763.46452023-07-11
CVE-2023-35326 [MEDIUM] CWE-908 CVE-2023-35326: Windows CDP User Components Information Disclosure Vulnerability Windows CDP User Components Information Disclosure Vulnerability
nvd
CVE-2021-40454P4MEDIUMCVSS 5.5≥ 10.0.0, < 10.0.17763.22372021-10-13
CVE-2021-40454 [MEDIUM] CWE-312 CVE-2021-40454: Rich Text Edit Control Information Disclosure Vulnerability Rich Text Edit Control Information Disclosure Vulnerability
nvd
CVE-2021-28447P4MEDIUMCVSS 4.4≥ 10.0.0, < publication2021-04-13
CVE-2021-28447 [MEDIUM] CVE-2021-28447: Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability
nvd
CVE-2020-1578P4MEDIUMCVSS 4.7≥ 10.0.0, < publication2020-08-17
CVE-2020-1578 [MEDIUM] CVE-2020-1578: An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass. An attacker who successfully exploited the vulnerability could retrieve the memory address of a kernel object. To exploit the vulnerability, an attacker would ha
nvd
CVE-2025-48813P4MEDIUMCVSS 4.7fixed in 10.0.17763.7919≥ 10.0.17763.0, < 10.0.17763.79192025-10-14
CVE-2025-48813 [MEDIUM] CWE-324 CVE-2025-48813: Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perfor Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.
nvd
CVE-2026-20928P4MEDIUMCVSS 4.6fixed in 10.0.17763.8644≥ 10.0.17763.0, < 10.0.17763.86442026-04-14
CVE-2026-20928 [MEDIUM] CWE-212 CVE-2026-20928: Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2022-21918P4MEDIUMCVSS 6.5≥ 10.0.17763.0, < 10.0.17763.24522022-01-11
CVE-2022-21918 [MEDIUM] CVE-2022-21918: DirectX Graphics Kernel File Denial of Service Vulnerability DirectX Graphics Kernel File Denial of Service Vulnerability
nvd
CVE-2024-38027P4MEDIUMCVSS 6.5fixed in 10.0.17763.6054≥ 10.0.17763.0, < 10.0.17763.60542024-07-09
CVE-2024-38027 [MEDIUM] CWE-400 CVE-2024-38027: Windows Line Printer Daemon Service Denial of Service Vulnerability Windows Line Printer Daemon Service Denial of Service Vulnerability
nvd
CVE-2023-35331P4MEDIUMCVSS 6.5≥ 10.0.17763.0, < 10.0.17763.46452023-07-11
CVE-2023-35331 [MEDIUM] CVE-2023-35331: Windows Local Security Authority (LSA) Denial of Service Vulnerability Windows Local Security Authority (LSA) Denial of Service Vulnerability
nvd
CVE-2023-36717P4MEDIUMCVSS 6.5≥ 10.0.17763.0, < 10.0.17763.49742023-10-10
CVE-2023-36717 [MEDIUM] CVE-2023-36717: Windows Virtual Trusted Platform Module Denial of Service Vulnerability Windows Virtual Trusted Platform Module Denial of Service Vulnerability
nvd
CVE-2021-42274P4MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.17763.23002021-11-10
CVE-2021-42274 [MEDIUM] CVE-2021-42274: Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability
nvd
CVE-2021-26886P4MEDIUMCVSS 6.1≥ 10.0.0, < publication2021-03-11
CVE-2021-26886 [MEDIUM] CVE-2021-26886: User Profile Service Denial of Service Vulnerability User Profile Service Denial of Service Vulnerability
nvd
CVE-2021-28326P4MEDIUMCVSS 6.1≥ 10.0.0, < publication2021-04-13
CVE-2021-28326 [MEDIUM] CVE-2021-28326: Windows AppX Deployment Server Denial of Service Vulnerability Windows AppX Deployment Server Denial of Service Vulnerability
nvd
CVE-2018-8649P4MEDIUMCVSS 5.5v(Server Core installation)2018-12-12
CVE-2018-8649 [MEDIUM] CVE-2018-8649: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Win A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Windows Denial of Service Vulnerability." This affects Windows 10, Windows Server 2019.
nvd
CVE-2022-21839P4MEDIUMCVSS 5.5≥ 10.0.17763.0, < 10.0.17763.24522022-01-11
CVE-2022-21839 [MEDIUM] CVE-2022-21839: Windows Event Tracing Discretionary Access Control List Denial of Service Vulnerability Windows Event Tracing Discretionary Access Control List Denial of Service Vulnerability
nvd
CVE-2020-17045P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-11-11
CVE-2020-17045 [MEDIUM] CVE-2020-17045: Windows KernelStream Information Disclosure Vulnerability Windows KernelStream Information Disclosure Vulnerability
nvd
CVE-2021-36962P4MEDIUMCVSS 5.5≥ 10.0.0, < 10.0.17763.21832021-09-15
CVE-2021-36962 [MEDIUM] CVE-2021-36962: Windows Installer Information Disclosure Vulnerability Windows Installer Information Disclosure Vulnerability
nvd
CVE-2022-29140P4MEDIUMCVSS 5.5≥ 10.0.17763.0, < 10.0.17763.29282022-05-10
CVE-2022-29140 [MEDIUM] CVE-2022-29140: Windows Print Spooler Information Disclosure Vulnerability Windows Print Spooler Information Disclosure Vulnerability
nvd
CVE-2020-0921P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-09-11
CVE-2020-0921 [MEDIUM] CVE-2020-0921: Microsoft Graphics Component Denial of Service Vulnerability Microsoft Graphics Component Denial of Service Vulnerability
nvd
CVE-2023-21776P4MEDIUMCVSS 5.5≥ 10.0.17763.0, < 10.0.17763.38872023-01-10
CVE-2023-21776 [MEDIUM] CWE-125 CVE-2023-21776: Windows Kernel Information Disclosure Vulnerability Windows Kernel Information Disclosure Vulnerability
nvd
Microsoft Windows Server 2019 vulnerabilities | cvebase