cbcvebase.

Microsoft Windows Server 2019 vulnerabilities

3,952 known vulnerabilities affecting microsoft/windows_server_2019.

Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16

Vulnerabilities

Page 77 of 198
CVE-2022-35793P3HIGHCVSS 7.3≥ 10.0.17763.0, < 10.0.17763.32872022-08-09
CVE-2022-35793 [HIGH] CVE-2022-35793: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-26931P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.29282022-05-10
CVE-2022-26931 [HIGH] CVE-2022-26931: Windows Kerberos Elevation of Privilege Vulnerability Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2024-38127P3HIGHCVSS 7.8fixed in 10.0.17763.6189≥ 10.0.17763.0, < 10.0.17763.61892024-08-13
CVE-2024-38127 [HIGH] CWE-126 CVE-2024-38127: Windows Hyper-V Elevation of Privilege Vulnerability Windows Hyper-V Elevation of Privilege Vulnerability
nvd
CVE-2024-38062P3HIGHCVSS 7.8fixed in 10.0.17763.6054≥ 10.0.17763.0, < 10.0.17763.60542024-07-09
CVE-2024-38062 [HIGH] CWE-125 CVE-2024-38062: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
nvd
CVE-2021-28315P3HIGHCVSS 7.8≥ 10.0.0, < publication2021-04-13
CVE-2021-28315 [HIGH] CVE-2021-28315: Windows Media Video Decoder Remote Code Execution Vulnerability Windows Media Video Decoder Remote Code Execution Vulnerability
nvd
CVE-2022-30209P3HIGHCVSS 7.4≥ 10.0.17763.0, < 10.0.17763.31652022-07-12
CVE-2022-30209 [HIGH] CVE-2022-30209: Windows IIS Server Elevation of Privilege Vulnerability Windows IIS Server Elevation of Privilege Vulnerability
nvd
CVE-2025-27470P3HIGHCVSS 7.5fixed in 10.0.17763.7136≥ 10.0.17763.0, < 10.0.17763.71362025-04-08
CVE-2025-27470 [HIGH] CWE-400 CVE-2025-27470: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-26652P3HIGHCVSS 7.5fixed in 10.0.17763.7136≥ 10.0.17763.0, < 10.0.17763.71362025-04-08
CVE-2025-26652 [HIGH] CWE-400 CVE-2025-26652: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-27479P3HIGHCVSS 7.5fixed in 10.0.17763.7136≥ 10.0.17763.0, < 10.0.17763.71362025-04-08
CVE-2025-27479 [HIGH] CWE-410 CVE-2025-27479: Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-21174P3HIGHCVSS 7.5fixed in 10.0.17763.7136≥ 10.0.17763.0, < 10.0.17763.71362025-04-08
CVE-2025-21174 [HIGH] CWE-400 CVE-2025-21174: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-27486P3HIGHCVSS 7.5fixed in 10.0.17763.7136≥ 10.0.17763.0, < 10.0.17763.71362025-04-08
CVE-2025-27486 [HIGH] CWE-400 CVE-2025-27486: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-27485P3HIGHCVSS 7.5fixed in 10.0.17763.7136≥ 10.0.17763.0, < 10.0.17763.71362025-04-08
CVE-2025-27485 [HIGH] CWE-400 CVE-2025-27485: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-26680P3HIGHCVSS 7.5fixed in 10.0.17763.7136≥ 10.0.17763.0, < 10.0.17763.71362025-04-08
CVE-2025-26680 [HIGH] CWE-400 CVE-2025-26680: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2024-38245P3HIGHCVSS 7.8fixed in 10.0.17763.6293≥ 10.0.17763.0, < 10.0.17763.62932024-09-10
CVE-2024-38245 [HIGH] CWE-20 CVE-2024-38245: Kernel Streaming Service Driver Elevation of Privilege Vulnerability Kernel Streaming Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-33050P3HIGHCVSS 7.5fixed in 10.0.17763.7434≥ 10.0.17763.0, < 10.0.17763.74342025-06-10
CVE-2025-33050 [HIGH] CWE-693 CVE-2025-33050: Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-32725P3HIGHCVSS 7.5fixed in 10.0.17763.7434≥ 10.0.17763.0, < 10.0.17763.74342025-06-10
CVE-2025-32725 [HIGH] CWE-693 CVE-2025-32725: Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-33068P3HIGHCVSS 7.5fixed in 10.0.17763.7434≥ 10.0.17763.0, < 10.0.17763.74342025-06-10
CVE-2025-33068 [HIGH] CWE-400 CVE-2025-33068: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2024-21363P3HIGHCVSS 7.8fixed in 10.0.17763.5458≥ 10.0.17763.0, < 10.0.17763.54582024-02-13
CVE-2024-21363 [HIGH] CWE-843 CVE-2024-21363: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2026-20875P3HIGHCVSS 7.5fixed in 10.0.17763.8276≥ 10.0.17763.0, < 10.0.17763.82762026-01-13
CVE-2026-20875 [HIGH] CWE-476 CVE-2026-20875: Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an una Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2024-38243P3HIGHCVSS 7.8fixed in 10.0.17763.6293≥ 10.0.17763.0, < 10.0.17763.62932024-09-10
CVE-2024-38243 [HIGH] CWE-20 CVE-2024-38243: Kernel Streaming Service Driver Elevation of Privilege Vulnerability Kernel Streaming Service Driver Elevation of Privilege Vulnerability
nvd
Microsoft Windows Server 2019 vulnerabilities | cvebase