VYPR

Windows Server 2016

by Microsoft

CVEs (5,109)

  • CVE-2021-28476CriMay 11, 2021
    risk 0.67cvss 9.9epss 0.39

    Windows Hyper-V Remote Code Execution Vulnerability

  • CVE-2017-0263HigKEVMay 12, 2017
    risk 0.67cvss 7.8epss 0.10

    The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka…

  • CVE-2023-21690CriFeb 14, 2023
    risk 0.66cvss 9.8epss 0.28

    Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

  • CVE-2023-21689CriFeb 14, 2023
    risk 0.66cvss 9.8epss 0.27

    Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

  • CVE-2022-24497CriApr 15, 2022
    risk 0.66cvss 9.8epss 0.35

    Windows Network File System Remote Code Execution Vulnerability

  • CVE-2022-24491CriApr 15, 2022
    risk 0.66cvss 9.8epss 0.33

    Windows Network File System Remote Code Execution Vulnerability

  • CVE-2021-24074CriFeb 25, 2021
    risk 0.66cvss 9.8epss 0.26

    Windows TCP/IP Remote Code Execution Vulnerability

  • CVE-2020-1464HigKEVAug 17, 2020
    risk 0.66cvss 7.8epss 0.39

    A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass security features…

  • CVE-2020-0683HigKEVFeb 11, 2020
    risk 0.66cvss 7.8epss 0.08

    An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686.

  • CVE-2019-0863HigKEVMay 16, 2019
    risk 0.66cvss 7.8epss 0.05

    An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.

  • CVE-2019-0725CriMay 16, 2019
    risk 0.66cvss 9.8epss 0.27

    A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.

  • CVE-2019-0697CriApr 9, 2019
    risk 0.66cvss 9.8epss 0.32

    A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0698, CVE-2019-0726.

  • CVE-2017-8686CriSep 13, 2017
    risk 0.66cvss 9.8epss 0.25

    The Windows Server DHCP service in Windows Server 2012 Gold and R2, and Windows Server 2016 allows an attacker to either run arbitrary code on the DHCP failover server or cause the DHCP service to become nonresponsive, due to a memory corruption vulnerability in the Windows…

  • CVE-2017-8589CriJul 11, 2017
    risk 0.66cvss 9.8epss 0.24

    Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way that Windows Search handles objects in…

  • CVE-2025-47981CriJul 8, 2025
    risk 0.65cvss 9.8epss 0.33

    Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.

  • CVE-2025-30397HigKEVMay 13, 2025
    risk 0.65cvss 7.5epss 0.27

    Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.

  • CVE-2023-36397CriNov 14, 2023
    risk 0.65cvss 9.8epss 0.18

    Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

  • CVE-2023-44487HigKEVOct 10, 2023
    risk 0.65cvss 7.5epss 1.00

    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • CVE-2023-21692CriFeb 14, 2023
    risk 0.65cvss 9.8epss 0.21

    Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

  • CVE-2022-26925HigKEVMay 10, 2022
    risk 0.65cvss 8.1epss 0.11

    Windows LSA Spoofing Vulnerability

Page 6 of 256