cbcvebase.

Microsoft Windows Server 2019 vulnerabilities

3,952 known vulnerabilities affecting microsoft/windows_server_2019.

Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16

Vulnerabilities

Page 35 of 198
CVE-2022-30165P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.30462022-06-15
CVE-2022-30165 [HIGH] CVE-2022-30165: Windows Kerberos Elevation of Privilege Vulnerability Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2023-21818P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.40102023-02-14
CVE-2023-21818 [HIGH] CWE-20 CVE-2023-21818: Windows Secure Channel Denial of Service Vulnerability Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2026-20921P3HIGHCVSS 7.5fixed in 10.0.17763.8276≥ 10.0.17763.0, < 10.0.17763.82762026-01-13
CVE-2026-20921 [HIGH] CWE-362 CVE-2026-20921: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2020-17049P3HIGHCVSS 7.2≥ 10.0.0, < 10.0.17763.20612020-11-11
CVE-2020-17049 [HIGH] CWE-863 CVE-2020-17049: A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines i A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines if a service ticket can be used for delegation via Kerberos Constrained Delegation (KCD). To exploit the vulnerability, a compromised service that is configured to use KCD could tamper with a service ticket that is not valid for delegation to force the K
nvd
CVE-2025-58726P3HIGHCVSS 7.5fixed in 10.0.17763.7919≥ 10.0.17763.0, < 10.0.17763.79192025-10-14
CVE-2025-58726 [HIGH] CWE-284 CVE-2025-58726: Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges ov Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-20926P3HIGHCVSS 7.5fixed in 10.0.17763.8276≥ 10.0.17763.0, < 10.0.17763.82762026-01-13
CVE-2026-20926 [HIGH] CWE-362 CVE-2026-20926: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-20919P3HIGHCVSS 7.5fixed in 10.0.17763.8276≥ 10.0.17763.0, < 10.0.17763.82762026-01-13
CVE-2026-20919 [HIGH] CWE-362 CVE-2026-20919: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-20934P3HIGHCVSS 7.5fixed in 10.0.17763.8276≥ 10.0.17763.0, < 10.0.17763.82762026-01-13
CVE-2026-20934 [HIGH] CWE-362 CVE-2026-20934: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2021-24091P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-02-25
CVE-2021-24091 [HIGH] CWE-787 CVE-2021-24091: Windows Camera Codec Pack Remote Code Execution Vulnerability Windows Camera Codec Pack Remote Code Execution Vulnerability
nvd
CVE-2024-38071P3HIGHCVSS 7.5fixed in 10.0.17763.6054≥ 10.0.17763.0, < 10.0.17763.60542024-07-09
CVE-2024-38071 [HIGH] CWE-126 CVE-2024-38071: Windows Remote Desktop Licensing Service Denial of Service Vulnerability Windows Remote Desktop Licensing Service Denial of Service Vulnerability
nvd
CVE-2023-35639P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.52062023-12-12
CVE-2023-35639 [HIGH] CWE-122 CVE-2023-35639: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2024-26214P3HIGHCVSS 8.8fixed in 10.0.17763.5696≥ 10.0.17763.0, < 10.0.17763.56962024-04-09
CVE-2024-26214 [HIGH] CWE-122 CVE-2024-26214: Microsoft WDAC SQL Server ODBC Driver Remote Code Execution Vulnerability Microsoft WDAC SQL Server ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2022-30221P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.31652022-07-12
CVE-2022-30221 [HIGH] CVE-2022-30221: Windows Graphics Component Remote Code Execution Vulnerability Windows Graphics Component Remote Code Execution Vulnerability
nvd
CVE-2023-36006P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.52062023-12-12
CVE-2023-36006 [HIGH] CWE-121 CVE-2023-36006: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2023-36402P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.51222023-11-14
CVE-2023-36402 [HIGH] CWE-122 CVE-2023-36402: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2023-36577P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.49742023-10-10
CVE-2023-36577 [HIGH] CWE-122 CVE-2023-36577: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2023-28297P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.38872023-04-11
CVE-2023-28297 [HIGH] CWE-416 CVE-2023-28297: Windows Remote Procedure Call Service (RPCSS) Elevation of Privilege Vulnerability Windows Remote Procedure Call Service (RPCSS) Elevation of Privilege Vulnerability
nvd
CVE-2024-21367P3HIGHCVSS 8.8fixed in 10.0.17763.5458≥ 10.0.17763.0, < 10.0.17763.54582024-02-13
CVE-2024-21367 [HIGH] CWE-122 CVE-2024-21367: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21375P3HIGHCVSS 8.8fixed in 10.0.17763.5458≥ 10.0.17763.0, < 10.0.17763.54582024-02-13
CVE-2024-21375 [HIGH] CWE-416 CVE-2024-21375: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21361P3HIGHCVSS 8.8fixed in 10.0.17763.5458≥ 10.0.17763.0, < 10.0.17763.54582024-02-13
CVE-2024-21361 [HIGH] CWE-122 CVE-2024-21361: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2019 vulnerabilities | cvebase