cbcvebase.

Microsoft Windows Server 2019 vulnerabilities

3,952 known vulnerabilities affecting microsoft/windows_server_2019.

Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
170
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16

Vulnerabilities

Page 9 of 198
CVE-2021-28442P2MEDIUMCVSS 6.5Exploited≥ 10.0.0, < publication2021-04-13
CVE-2021-28442 [MEDIUM] CVE-2021-28442: Windows TCP/IP Information Disclosure Vulnerability Windows TCP/IP Information Disclosure Vulnerability
nvd
CVE-2018-8638P2MEDIUMCVSS 5.5Exploitedv(Server Core installation)2018-12-12
CVE-2018-8638 [MEDIUM] CVE-2018-8638: An information disclosure vulnerability exists when DirectX improperly handles objects in memory, ak An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Information Disclosure Vulnerability." This affects Windows 10, Windows Server 2019.
nvd
CVE-2022-21874P2CRITICALCVSS 9.8Exploited≥ 10.0.17763.0, < 10.0.17763.24522022-01-11
CVE-2022-21874 [CRITICAL] CVE-2022-21874: Windows Security Center API Remote Code Execution Vulnerability Windows Security Center API Remote Code Execution Vulnerability
nvd
CVE-2018-8544P2HIGHCVSS 8.8PoCv(Server Core installation)2018-11-14
CVE-2018-8544 [HIGH] CWE-416 CVE-2018-8544: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008
nvd
CVE-2022-21898P3CRITICALCVSS 9.8Exploited≥ 10.0.17763.0, < 10.0.17763.24522022-01-11
CVE-2022-21898 [CRITICAL] CVE-2022-21898: DirectX Graphics Kernel Remote Code Execution Vulnerability DirectX Graphics Kernel Remote Code Execution Vulnerability
nvd
CVE-2019-1150P2HIGHCVSS 8.8PoC≥ 10.0.0, < publication2019-08-14
CVE-2019-1150 [HIGH] CWE-787 CVE-2019-1150: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whos
nvd
CVE-2023-24941P2CRITICALCVSS 9.8≥ 10.0.17763.0, < 10.0.17763.43772023-05-09
CVE-2023-24941 [CRITICAL] CWE-908 CVE-2023-24941: Windows Network File System Remote Code Execution Vulnerability Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2025-21293P2HIGHCVSS 8.8PoCfixed in 10.0.17763.6775≥ 10.0.17763.0, < 10.0.17763.67752025-01-14
CVE-2025-21293 [HIGH] CWE-284 CVE-2025-21293: Active Directory Domain Services Elevation of Privilege Vulnerability Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2024-38077P1CRITICALCVSS 9.8fixed in 10.0.17763.6054≥ 10.0.17763.0, < 10.0.17763.60542024-07-09
CVE-2024-38077 [CRITICAL] CWE-122 CVE-2024-38077: Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
nvd
CVE-2019-1151P2HIGHCVSS 8.8PoC≥ 10.0.0, < publication2019-08-14
CVE-2019-1151 [HIGH] CWE-787 CVE-2019-1151: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whos
nvd
CVE-2024-49112P1CRITICALCVSS 9.8fixed in 10.0.17763.6659≥ 10.0.17763.0, < 10.0.17763.66592024-12-12
CVE-2024-49112 [CRITICAL] CWE-190 CVE-2024-49112: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2019-1181P2CRITICALCVSS 9.8≥ 10.0.0, < publication2019-08-14
CVE-2019-1181 [CRITICAL] CVE-2019-1181: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability cou
nvd
CVE-2022-26937P2CRITICALCVSS 9.8≥ 10.0.17763.0, < 10.0.17763.29282022-05-10
CVE-2022-26937 [CRITICAL] CVE-2022-26937: Windows Network File System Remote Code Execution Vulnerability Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2018-8413P2HIGHCVSS 7.8PoCv(Server Core installation)2018-10-10
CVE-2018-8413 [HIGH] CVE-2018-8413: A remote code execution vulnerability exists when "Windows Theme API" does not properly decompress f A remote code execution vulnerability exists when "Windows Theme API" does not properly decompress files, aka "Windows Theme API Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2019-1149P2HIGHCVSS 8.8PoC≥ 10.0.0, < publication2019-08-14
CVE-2019-1149 [HIGH] CWE-787 CVE-2019-1149: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whos
nvd
CVE-2019-1144P2HIGHCVSS 8.8PoC≥ 10.0.0, < publication2019-08-14
CVE-2019-1144 [HIGH] CWE-415 CVE-2019-1144: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whos
nvd
CVE-2019-1152P2HIGHCVSS 8.8PoC≥ 10.0.0, < publication2019-08-14
CVE-2019-1152 [HIGH] CWE-787 CVE-2019-1152: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whos
nvd
CVE-2019-1145P2HIGHCVSS 8.8PoC≥ 10.0.0, < publication2019-08-14
CVE-2019-1145 [HIGH] CWE-119 CVE-2019-1145: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whos
nvd
CVE-2019-1184P3MEDIUMCVSS 6.7PoC≥ 10.0.0, < publication2019-08-14
CVE-2019-1184 [MEDIUM] CVE-2019-1184: An elevation of privilege vulnerability exists when Windows Core Shell COM Server Registrar improper An elevation of privilege vulnerability exists when Windows Core Shell COM Server Registrar improperly handles COM calls. An attacker who successfully exploited this vulnerability could potentially set certain items to run at a higher level and thereby elevate permissions. To exploit this vulnerability, an attacker would first have to log on to the system. An
nvd
CVE-2023-38545P2CRITICALCVSS 9.8fixed in 10.0.17763.51222023-10-18
CVE-2023-38545 [CRITICAL] CWE-787 CVE-2023-38545: This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255 bytes. If the host name is detected to be longer, curl switches to local
nvd
Microsoft Windows Server 2019 vulnerabilities | cvebase