VYPR

Windows Server 2016

by Microsoft

CVEs (5,109)

  • CVE-2026-25181HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Out-of-bounds read in Windows GDI+ allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-23674HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-20846HigFeb 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.

  • CVE-2026-20934HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-20929HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-20926HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-20921HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-20919HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-20875HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.02

    Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

  • CVE-2026-20849HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-20848HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-0386HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.

  • CVE-2025-60704HigNov 11, 2025
    risk 0.49cvss 7.5epss 0.01

    Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-58726HigOct 14, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-55231HigAug 21, 2025
    risk 0.49cvss 7.5epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to execute code over a network.

  • CVE-2025-49744HigJul 8, 2025
    risk 0.49cvss 7.0epss 0.01

    Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

  • CVE-2025-49716HigJul 8, 2025
    risk 0.49cvss 7.5epss 0.01

    Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.

  • CVE-2025-48814HigJul 8, 2025
    risk 0.49cvss 7.5epss 0.01

    Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2025-33068HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

  • CVE-2025-33056HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network.

Page 134 of 256