cbcvebase.

Microsoft Windows Server 2019 vulnerabilities

3,952 known vulnerabilities affecting microsoft/windows_server_2019.

Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16

Vulnerabilities

Page 54 of 198
CVE-2023-21555P3HIGHCVSS 8.1≥ 10.0.17763.0, < 10.0.17763.38872023-01-10
CVE-2023-21555 [HIGH] CWE-367 CVE-2023-21555: Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
nvd
CVE-2023-21548P3HIGHCVSS 8.1≥ 10.0.17763.0, < 10.0.17763.38872023-01-10
CVE-2023-21548 [HIGH] CWE-591 CVE-2023-21548: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2023-21535P3HIGHCVSS 8.1≥ 10.0.17763.0, < 10.0.17763.38872023-01-10
CVE-2023-21535 [HIGH] CWE-591 CVE-2023-21535: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2022-44676P3HIGHCVSS 8.1≥ 10.0.17763.0, < 10.0.17763.37702022-12-13
CVE-2022-44676 [HIGH] CWE-362 CVE-2022-44676: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2022-41039P3HIGHCVSS 8.1≥ 10.0.17763.0, < 10.0.17763.36502022-11-09
CVE-2022-41039 [HIGH] CWE-362 CVE-2022-41039: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2026-50429P3HIGHCVSS 8.2fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50429 [HIGH] CWE-125 CVE-2026-50429: Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2023-23405P3HIGHCVSS 8.1≥ 10.0.17763.0, < 10.0.17763.41312023-03-14
CVE-2023-23405 [HIGH] CWE-190 CVE-2023-23405: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2023-24908P3HIGHCVSS 8.1≥ 10.0.17763.0, < 10.0.17763.41312023-03-14
CVE-2023-24908 [HIGH] CWE-190 CVE-2023-24908: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2023-24869P3HIGHCVSS 8.1≥ 10.0.17763.0, < 10.0.17763.41312023-03-14
CVE-2023-24869 [HIGH] CWE-190 CVE-2023-24869: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2023-21712P3HIGHCVSS 8.1≥ 10.0.17763.0, < 10.0.17763.36502023-04-27
CVE-2023-21712 [HIGH] CWE-362 CVE-2023-21712: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2022-41088P3HIGHCVSS 8.1≥ 10.0.17763.0, < 10.0.17763.36502022-11-09
CVE-2022-41088 [HIGH] CWE-362 CVE-2022-41088: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-24903P3HIGHCVSS 8.1≥ 10.0.17763.0, < 10.0.17763.43772023-05-09
CVE-2023-24903 [HIGH] CWE-415 CVE-2023-24903: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2023-23404P3HIGHCVSS 8.1≥ 10.0.17763.0, < 10.0.17763.41312023-03-14
CVE-2023-23404 [HIGH] CWE-416 CVE-2023-23404: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2022-30145P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.30462022-06-15
CVE-2022-30145 [HIGH] CVE-2022-30145: Windows Encrypting File System (EFS) Remote Code Execution Vulnerability Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
nvd
CVE-2026-27912P3HIGHCVSS 8.0fixed in 10.0.17763.8644≥ 10.0.17763.0, < 10.0.17763.86442026-04-14
CVE-2026-27912 [HIGH] CWE-285 CVE-2026-27912: Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
nvd
CVE-2025-53149P3HIGHCVSS 7.8fixed in 10.0.17763.7678≥ 10.0.17763.0, < 10.0.17763.76782025-08-12
CVE-2025-53149 [HIGH] CWE-122 CVE-2025-53149: Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacke Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24067P3HIGHCVSS 7.8fixed in 10.0.17763.7009≥ 10.0.17763.0, < 10.0.17763.70092025-03-11
CVE-2025-24067 [HIGH] CWE-122 CVE-2025-24067: Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate p Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24066P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.70092025-03-11
CVE-2025-24066 [HIGH] CWE-122 CVE-2025-24066: Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate p Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24063P3HIGHCVSS 7.8fixed in 10.0.17763.7314≥ 10.0.17763.0, < 10.0.17763.73142025-05-13
CVE-2025-24063 [HIGH] CWE-122 CVE-2025-24063: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-26666P3HIGHCVSS 7.8fixed in 10.0.17763.7136≥ 10.0.17763.0, < 10.0.17763.71362025-04-08
CVE-2025-26666 [HIGH] CWE-122 CVE-2025-26666: Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
nvd
Microsoft Windows Server 2019 vulnerabilities | cvebase