Skip to main content

Vendor/product archive

microsoft / windows_server_2025 CVEs

Beta · best-effort

1,709 CVEs tagged to microsoft / windows_server_202531 Critical, 1,210 High, 459 Medium, 9 Low, 0 Unrated.

CVE-2026-48563

Published Jun 9, 2026

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVSS 7.5 · High
evidence mentions
6
Buzz score
32.0

CVE-2026-45642

Published Jun 9, 2026

Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.

CVSS 3.9 · Low
evidence mentions
3
Buzz score
21.9

CVE-2026-45637

Published Jun 9, 2026

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
3
Buzz score
21.9

CVE-2026-45635

Published Jun 9, 2026

Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.

CVSS 8.1 · High
evidence mentions
4
Buzz score
25.6
Showing 401-425 of 1,709 CVEsPage 17 of 69