Skip to main content

Vendor/product archive

microsoft / windows_server_2025 CVEs

Beta · best-effort

1,709 CVEs tagged to microsoft / windows_server_202531 Critical, 1,210 High, 459 Medium, 9 Low, 0 Unrated.

CVE-2026-49787

Published Jul 14, 2026

Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

CVSS 7.5 · High
evidence mentions
5
Buzz score
32.4

CVE-2026-49784

Published Jul 14, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges loca…

CVSS 7.0 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-49783

Published Jul 14, 2026

Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVSS 7.8 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-49183

Published Jul 14, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.

CVSS 7.0 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-49180

Published Jul 14, 2026

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-49174

Published Jul 14, 2026

Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

CVSS 6.1 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-49172

Published Jul 14, 2026

Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
29.1

CVE-2026-49170

Published Jul 14, 2026

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
6
Buzz score
35.5

CVE-2026-49168

Published Jul 14, 2026

Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.

CVSS 6.8 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-49165

Published Jul 14, 2026

Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.

CVSS 7.1 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-44806

Published Jul 14, 2026

Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
29.1
Showing 351-375 of 1,709 CVEsPage 15 of 69