Windows Server 2019
by Microsoft
CVEs (4,947)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-0712 | Med | 0.45 | 6.8 | 0.06 | Nov 12, 2019 | A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1309,… | ||
| CVE-2019-1230 | Med | 0.45 | 6.8 | 0.06 | Oct 10, 2019 | An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Information Disclosure Vulnerability'. | ||
| CVE-2026-70330 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-70304 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65799 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65798 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65797 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65795 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62883 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62881 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62769 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62699 | Med | 0.44 | 6.8 | 0.00 | Aug 11, 2026 | Null pointer dereference in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to execute code locally. | ||
| CVE-2026-50507 | Med | 0.44 | 6.8 | 0.00 | Jun 9, 2026 | Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | ||
| CVE-2026-45608 | Med | 0.44 | 6.8 | 0.00 | Jun 9, 2026 | Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally. | ||
| CVE-2026-41097 | Med | 0.44 | 6.7 | 0.02 | May 12, 2026 | Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2026-32170 | Med | 0.44 | 6.7 | 0.00 | May 12, 2026 | Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-21530 | Med | 0.44 | 6.7 | 0.00 | May 12, 2026 | Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-0390 | Med | 0.44 | 6.7 | 0.00 | Apr 14, 2026 | Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2026-20925 | Med | 0.44 | 6.5 | 0.18 | Jan 13, 2026 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-20872 | Med | 0.44 | 6.5 | 0.20 | Jan 13, 2026 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. |
- risk 0.45cvss 6.8epss 0.06
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1309,…
- risk 0.45cvss 6.8epss 0.06
An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Information Disclosure Vulnerability'.
- risk 0.44cvss 6.7epss 0.00
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.8epss 0.00
Null pointer dereference in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to execute code locally.
- risk 0.44cvss 6.8epss 0.00
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- risk 0.44cvss 6.8epss 0.00
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.
- risk 0.44cvss 6.7epss 0.02
Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
- risk 0.44cvss 6.7epss 0.00
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
- risk 0.44cvss 6.5epss 0.18
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
- risk 0.44cvss 6.5epss 0.20
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
Page 171 of 248