Skip to main content

Vendor/product archive

microsoft / windows_server_2022 CVEs

Beta · best-effort

3,175 CVEs tagged to microsoft / windows_server_202278 Critical, 2,261 High, 824 Medium, 12 Low, 0 Unrated.

CVE-2026-49165

Published Jul 14, 2026

Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.

CVSS 7.1 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-44806

Published Jul 14, 2026

Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-42982

Published Jul 14, 2026

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
7
Buzz score
38.3

CVE-2026-42900

Published Jul 14, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a netwo…

CVSS 8.1 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-41087

Published Jul 14, 2026

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-40422

Published Jul 14, 2026

Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-40378

Published Jul 14, 2026

Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

CVSS 7.5 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-34349

Published Jul 14, 2026

Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-34348

Published Jul 14, 2026

Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-34346

Published Jul 14, 2026

Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-34328

Published Jul 14, 2026

Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
29.1
Showing 301-325 of 3,175 CVEsPage 13 of 127