VYPR

Windows Server 2025

by Microsoft

CVEs (1,879)

  • CVE-2026-32081MedApr 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

  • CVE-2026-32079MedApr 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

  • CVE-2026-27931MedApr 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

  • CVE-2026-27930MedApr 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

  • CVE-2026-20806MedApr 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.

  • CVE-2026-25186MedMar 10, 2026
    risk 0.36cvss 5.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to disclose information locally.

  • CVE-2026-25180MedMar 10, 2026
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.

  • CVE-2026-2636MedFeb 25, 2026
    risk 0.36cvss 5.5epss 0.00

    This vulnerability is caused by a CWE‑159: "Improper Handling of Invalid Use of Special Elements" weakness, which leads to an unrecoverable inconsistency in the CLFS.sys driver. This condition forces a call to the KeBugCheckEx function, allowing an unprivileged user to trigger…

  • CVE-2026-21222MedFeb 10, 2026
    risk 0.36cvss 5.5epss 0.01

    Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

  • CVE-2026-20939MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.00

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

  • CVE-2026-20937MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.00

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

  • CVE-2026-20932MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

  • CVE-2026-20862MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally.

  • CVE-2026-20839MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.

  • CVE-2026-20838MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

  • CVE-2026-20835MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally.

  • CVE-2026-20833MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally.

  • CVE-2026-20829MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.

  • CVE-2026-20827MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally.

  • CVE-2026-20824MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.

Page 68 of 94