VYPR

Windows Server 2016

by Microsoft

CVEs (5,109)

  • CVE-2020-16910MedOct 16, 2020
    risk 0.41cvss 6.2epss 0.03

    A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location. To exploit this vulnerability, an…

  • CVE-2019-0975MedJul 15, 2019
    risk 0.41cvss 6.3epss 0.02

    A security feature bypass vulnerability exists when Active Directory Federation Services (ADFS) improperly updates its list of banned IP addresses. To exploit this vulnerability, an attacker would have to convince a victim ADFS administrator to update the list of banned IP…

  • CVE-2019-1053MedJun 12, 2019
    risk 0.41cvss 6.3epss 0.01

    An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the vulnerability could elevate privileges by escaping a sandbox. To exploit this vulnerability, an attacker would require…

  • CVE-2019-0986MedJun 12, 2019
    risk 0.41cvss 6.3epss 0.02

    An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. To exploit this vulnerability, an attacker…

  • CVE-2017-0055MedMar 17, 2017
    risk 0.41cvss 6.1epss 0.16

    Microsoft Internet Information Server (IIS) in Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to perform cross-site…

  • CVE-2026-40380MedMay 12, 2026
    risk 0.40cvss 6.2epss 0.00

    Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack.

  • CVE-2026-32072MedApr 14, 2026
    risk 0.40cvss 6.2epss 0.00

    Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.

  • CVE-2026-26169MedApr 14, 2026
    risk 0.40cvss 6.1epss 0.02

    Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally.

  • CVE-2026-25169MedMar 10, 2026
    risk 0.40cvss 6.2epss 0.00

    Divide by zero in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.

  • CVE-2026-25168MedMar 10, 2026
    risk 0.40cvss 6.2epss 0.00

    Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.

  • CVE-2026-20821MedJan 13, 2026
    risk 0.40cvss 6.2epss 0.01

    Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally.

  • CVE-2026-20818MedJan 13, 2026
    risk 0.40cvss 6.2epss 0.01

    Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally.

  • CVE-2025-59258MedOct 14, 2025
    risk 0.40cvss 6.2epss 0.01

    Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally.

  • CVE-2025-55338MedOct 14, 2025
    risk 0.40cvss 6.1epss 0.03

    Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2025-55333MedOct 14, 2025
    risk 0.40cvss 6.1epss 0.01

    Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2025-47980MedJul 8, 2025
    risk 0.40cvss 6.2epss 0.01

    Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker to disclose information locally.

  • CVE-2025-30394MedMay 13, 2025
    risk 0.40cvss 5.9epss 0.30

    Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.

  • CVE-2025-29957MedMay 13, 2025
    risk 0.40cvss 6.2epss 0.01

    Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally.

  • CVE-2025-21278MedJan 14, 2025
    risk 0.40cvss 6.2epss 0.01

    Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability

  • CVE-2025-21202MedJan 14, 2025
    risk 0.40cvss 6.1epss 0.01

    Windows Recovery Environment Agent Elevation of Privilege Vulnerability

Page 197 of 256