VYPR

Windows Server 2019

by Microsoft

CVEs (4,947)

  • CVE-2026-49183HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-49181HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-49180MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

  • CVE-2026-49178HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.

  • CVE-2026-49176HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

  • CVE-2026-49174MedJul 14, 2026
    risk 0.00cvss 6.1epss 0.00

    Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

  • CVE-2026-49172CriJul 14, 2026
    risk 0.00cvss 9.8epss 0.01

    Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.

  • CVE-2026-49171HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

  • CVE-2026-49170HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

  • CVE-2026-49168MedJul 14, 2026
    risk 0.00cvss 6.8epss 0.00

    Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.

  • CVE-2026-49167MedJul 14, 2026
    risk 0.00cvss 4.7epss 0.00

    Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2026-49165HigJul 14, 2026
    risk 0.00cvss 7.1epss 0.00

    Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.

  • CVE-2026-49164HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.01

    Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

  • CVE-2026-48564HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.

  • CVE-2026-44806MedJul 14, 2026
    risk 0.00cvss 5.3epss 0.01

    Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

  • CVE-2026-42990CriJul 14, 2026
    risk 0.00cvss 9.8epss 0.01

    Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.

  • CVE-2026-42982HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42975HigJul 14, 2026
    risk 0.00cvss 8.0epss 0.01

    Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.

  • CVE-2026-42900HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-41087MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Page 247 of 248