cbcvebase.

Microsoft Windows Server 2019 vulnerabilities

3,952 known vulnerabilities affecting microsoft/windows_server_2019.

Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16

Vulnerabilities

Page 21 of 198
CVE-2021-31962P3CRITICALCVSS 9.8≥ 10.0.0, < 10.0.17763.19992021-06-08
CVE-2021-31962 [CRITICAL] CVE-2021-31962: Kerberos AppContainer Security Feature Bypass Vulnerability Kerberos AppContainer Security Feature Bypass Vulnerability
nvd
CVE-2026-27928P3HIGHCVSS 8.7fixed in 10.0.17763.8644≥ 10.0.17763.0, < 10.0.17763.86442026-04-14
CVE-2026-27928 [HIGH] CWE-20 CVE-2026-27928: Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feat Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2023-35630P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.52062023-12-12
CVE-2023-35630 [HIGH] CWE-122 CVE-2023-35630: Internet Connection Sharing (ICS) Remote Code Execution Vulnerability Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
nvd
CVE-2026-33827P3HIGHCVSS 8.1fixed in 10.0.17763.8644≥ 10.0.17763.0, < 10.0.17763.86442026-04-14
CVE-2026-33827 [HIGH] CWE-362 CVE-2026-33827: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-26230P3HIGHCVSS 7.8fixed in 10.0.17763.5696≥ 10.0.17763.0, < 10.0.17763.56962024-04-09
CVE-2024-26230 [HIGH] CWE-416 CVE-2024-26230: Windows Telephony Server Elevation of Privilege Vulnerability Windows Telephony Server Elevation of Privilege Vulnerability
nvd
CVE-2025-21285P3HIGHCVSS 7.5fixed in 10.0.17763.6775≥ 10.0.17763.0, < 10.0.17763.67752025-01-14
CVE-2025-21285 [HIGH] CWE-476 CVE-2025-21285: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2021-28445P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-04-13
CVE-2021-28445 [HIGH] CVE-2021-28445: Windows Network File System Remote Code Execution Vulnerability Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2026-50380P3CRITICALCVSS 9.6fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50380 [CRITICAL] CWE-122 CVE-2026-50380: Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a ne Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21371P3HIGHCVSS 8.8fixed in 10.0.17763.6893≥ 10.0.17763.0, < 10.0.17763.68932025-02-11
CVE-2025-21371 [HIGH] CWE-122 CVE-2025-21371: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2021-33780P3HIGHCVSS 8.8≥ 10.0.0, < 10.0.17763.20612021-07-14
CVE-2021-33780 [HIGH] CVE-2021-33780: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2018-8634P3HIGHCVSS 8.8v(Server Core installation)2018-12-12
CVE-2018-8634 [HIGH] CVE-2018-8634: A remote code execution vulnerability exists in Windows where Microsoft text-to-speech fails to prop A remote code execution vulnerability exists in Windows where Microsoft text-to-speech fails to properly handle objects in the memory, aka "Microsoft Text-To-Speech Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers.
nvd
CVE-2022-23294P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.26862022-03-09
CVE-2022-23294 [HIGH] CVE-2022-23294: Windows Event Tracing Remote Code Execution Vulnerability Windows Event Tracing Remote Code Execution Vulnerability
nvd
CVE-2021-24088P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-02-25
CVE-2021-24088 [HIGH] CVE-2021-24088: Windows Local Spooler Remote Code Execution Vulnerability Windows Local Spooler Remote Code Execution Vulnerability
nvd
CVE-2026-24294P3HIGHCVSS 7.8fixed in 10.0.17763.8511≥ 10.0.17763.0, < 10.0.17763.85112026-03-10
CVE-2026-24294 [HIGH] CWE-287 CVE-2026-24294: Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges lo Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50177P3HIGHCVSS 8.1fixed in 10.0.17763.7678≥ 10.0.17763.0, < 10.0.17763.76782025-08-12
CVE-2025-50177 [HIGH] CWE-362 CVE-2025-50177: Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a net Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
nvd
CVE-2021-28455P3HIGHCVSS 8.8≥ 10.0.0, < 10.0.17763.19352021-05-11
CVE-2021-28455 [HIGH] CVE-2021-28455: Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability
nvd
CVE-2022-24487P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.28032022-04-15
CVE-2022-24487 [HIGH] CVE-2022-24487: Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
nvd
CVE-2021-34525P3HIGHCVSS 8.8≥ 10.0.0, < 10.0.17763.20612021-07-14
CVE-2021-34525 [HIGH] CVE-2021-34525: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2021-34508P3HIGHCVSS 8.8≥ 10.0.0, < 10.0.17763.20612021-07-14
CVE-2021-34508 [HIGH] CVE-2021-34508: Windows Kernel Remote Code Execution Vulnerability Windows Kernel Remote Code Execution Vulnerability
nvd
CVE-2025-21407P3HIGHCVSS 8.8fixed in 10.0.17763.6893≥ 10.0.17763.0, < 10.0.17763.68932025-02-11
CVE-2025-21407 [HIGH] CWE-122 CVE-2025-21407: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2019 vulnerabilities | cvebase