Skip to main content

Vendor/product archive

microsoft / windows_server_2025 CVEs

Beta · best-effort

1,699 CVEs tagged to microsoft / windows_server_202531 Critical, 1,202 High, 457 Medium, 9 Low, 0 Unrated.

CVE-2026-54993

Published Jul 14, 2026

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

CVSS 7.8 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-54983

Published Jul 14, 2026

Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

CVSS 7.5 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-54982

Published Jul 14, 2026

Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.

CVSS 8.8 · High
evidence mentions
7
Buzz score
38.3

CVE-2026-54119

Published Jul 14, 2026

Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.

CVSS 7.5 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-54112

Published Jul 14, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-54109

Published Jul 14, 2026

Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

CVSS 7.8 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-54107

Published Jul 14, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVSS 8.8 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-50697

Published Jul 14, 2026

Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-50696

Published Jul 14, 2026

Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.

CVSS 7.5 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-50384

Published Jul 14, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate privileges locally.

CVSS 7.0 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-50356

Published Jul 14, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges loca…

CVSS 7.0 · High
evidence mentions
4
Buzz score
29.1
Showing 276-300 of 1,699 CVEsPage 12 of 68