← Back to Products

windows_server_2022

Vendor: microsoft

1,321
Total CVEs
19
Critical
935
High
220
Medium
147
Low

Recent CVEs

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

8.1

CVSS

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

8.0

CVSS

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

9.8

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.0

CVSS

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.0

CVSS

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.0

CVSS

Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.8

CVSS

Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.5

CVSS

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

8.8

CVSS

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

5.5

CVSS

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

5.5

CVSS

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

5.5

CVSS

Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

5.5

CVSS

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

5.5

CVSS

Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an unauthorized attacker to execute code locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.8

CVSS

Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

5.5

CVSS

Use after free in Windows User Interface Core allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.8

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.8

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.8

CVSS

Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

8.4

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.8

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.8

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.8

CVSS

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.8

CVSS

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

6.5

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.0

CVSS

Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.3

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.0

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.0

CVSS

Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

5.5

CVSS

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

5.5

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.0

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.0

CVSS

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

5.5

CVSS

Use after free in Windows WalletService allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.0

CVSS

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

5.5

CVSS

Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.8

CVSS

Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.8

CVSS

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.0

CVSS

Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

6.2

CVSS

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.5

CVSS

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.0

CVSS

Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.8

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.0

CVSS

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

5.5

CVSS

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

5.5

CVSS

Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.0

CVSS

Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

8.7

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Projected File System allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.8

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.20348.1006 10.0.20348.1070 10.0.20348.1129 10.0.20348.1131 10.0.20348.1194 +83 more

Published: Apr 14, 2026

7.0

CVSS