cbcvebase.

Microsoft Windows Server 2019 vulnerabilities

3,952 known vulnerabilities affecting microsoft/windows_server_2019.

Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16

Vulnerabilities

Page 29 of 198
CVE-2021-28358P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-04-13
CVE-2021-28358 [HIGH] CVE-2021-28358: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28357P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-04-13
CVE-2021-28357 [HIGH] CVE-2021-28357: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28336P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-04-13
CVE-2021-28336 [HIGH] CVE-2021-28336: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28353P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-04-13
CVE-2021-28353 [HIGH] CVE-2021-28353: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-26881P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-03-11
CVE-2021-26881 [HIGH] CVE-2021-26881: Microsoft Windows Media Foundation Remote Code Execution Vulnerability Microsoft Windows Media Foundation Remote Code Execution Vulnerability
nvd
CVE-2023-35381P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.47372023-08-08
CVE-2023-35381 [HIGH] CWE-190 CVE-2023-35381: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2023-21727P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.42522023-04-11
CVE-2023-21727 [HIGH] CWE-122 CVE-2023-21727: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2024-38128P3HIGHCVSS 8.8fixed in 10.0.17763.6189≥ 10.0.17763.0, < 10.0.17763.61892024-08-13
CVE-2024-38128 [HIGH] CWE-190 CVE-2024-38128: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-38121P3HIGHCVSS 8.8fixed in 10.0.17763.6189≥ 10.0.17763.0, < 10.0.17763.61892024-08-13
CVE-2024-38121 [HIGH] CWE-122 CVE-2024-38121: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-38115P3HIGHCVSS 8.8fixed in 10.0.17763.6189≥ 10.0.17763.0, < 10.0.17763.61892024-08-13
CVE-2024-38115 [HIGH] CWE-122 CVE-2024-38115: Windows IP Routing Management Snapin Remote Code Execution Vulnerability Windows IP Routing Management Snapin Remote Code Execution Vulnerability
nvd
CVE-2024-38130P3HIGHCVSS 8.8fixed in 10.0.17763.6189≥ 10.0.17763.0, < 10.0.17763.61892024-08-13
CVE-2024-38130 [HIGH] CWE-122 CVE-2024-38130: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-38120P3HIGHCVSS 8.8fixed in 10.0.17763.6189≥ 10.0.17763.0, < 10.0.17763.61892024-08-13
CVE-2024-38120 [HIGH] CWE-122 CVE-2024-38120: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-30013P3HIGHCVSS 8.8fixed in 10.0.17763.6054≥ 10.0.17763.0, < 10.0.17763.60542024-07-09
CVE-2024-30013 [HIGH] CWE-415 CVE-2024-30013: Windows MultiPoint Services Remote Code Execution Vulnerability Windows MultiPoint Services Remote Code Execution Vulnerability
nvd
CVE-2024-38154P3HIGHCVSS 8.8fixed in 10.0.17763.6189≥ 10.0.17763.0, < 10.0.17763.61892024-08-13
CVE-2024-38154 [HIGH] CWE-122 CVE-2024-38154: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-38114P3HIGHCVSS 8.8fixed in 10.0.17763.6189≥ 10.0.17763.0, < 10.0.17763.61892024-08-13
CVE-2024-38114 [HIGH] CWE-122 CVE-2024-38114: Windows IP Routing Management Snapin Remote Code Execution Vulnerability Windows IP Routing Management Snapin Remote Code Execution Vulnerability
nvd
CVE-2024-49086P3HIGHCVSS 8.8fixed in 10.0.17763.6659≥ 10.0.17763.0, < 10.0.17763.66592024-12-12
CVE-2024-49086 [HIGH] CWE-122 CVE-2024-49086: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-49085P3HIGHCVSS 8.8fixed in 10.0.17763.6659≥ 10.0.17763.0, < 10.0.17763.66592024-12-12
CVE-2024-49085 [HIGH] CWE-122 CVE-2024-49085: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2025-27477P3HIGHCVSS 8.8fixed in 10.0.17763.7136≥ 10.0.17763.0, < 10.0.17763.71362025-04-08
CVE-2025-27477 [HIGH] CWE-122 CVE-2025-27477: Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute c Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2019-1125P3MEDIUMCVSS 5.6PoC≥ 10.0.0, < publication2019-09-03
CVE-2019-1125 [MEDIUM] CVE-2019-1125: An information disclosure vulnerability exists when certain central processing units (CPU) speculati An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The v
nvd
CVE-2024-43622P3HIGHCVSS 8.8fixed in 10.0.17763.6532≥ 10.0.17763.0, < 10.0.17763.65322024-11-12
CVE-2024-43622 [HIGH] CWE-122 CVE-2024-43622: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2019 vulnerabilities | cvebase