windows_server_2019 vulnerabilities
CVEs whose affected-version data names the windows_server_2019 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
1547 CVEsRSS
CVE-2026-56175High· 7.8Windows NTFS Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-56173High· 7.0Windows WebView Elevation of Privilege Vulnerability
Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.
CVE-2026-56159Critical· 9.8DHCP Server Service Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVE-2026-56644High· 7.8DirectX Graphics Kernel Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-56643High· 7.8DirectX Graphics Kernel Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-56194High· 8.8Windows NFS Server Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.
CVE-2026-56189High· 7.8Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.
CVE-2026-57095Medium· 6.2Win32k Elevation of Privilege Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.
CVE-2026-57096High· 7.8Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
CVE-2026-57982Medium· 6.5Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.
CVE-2026-58546Medium· 6.5Windows Remote Desktop Client Information Disclosure Vulnerability
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-58539Medium· 6.5Windows Remote Desktop Client Information Disclosure Vulnerability
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-58538High· 7.8Windows Bluetooth Service Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
CVE-2026-58535Medium· 6.5Windows Remote Desktop Client Information Disclosure Vulnerability
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-58534High· 8.8Windows Input Method Editor (IME) Elevation of Privilege Vulnerability
Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
CVE-2026-58533Medium· 6.5Windows Remote Desktop Client Information Disclosure Vulnerability
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-58532High· 7.8Windows Kernel Elevation of Privilege Vulnerability
Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-58531High· 7.5Windows SMB Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.
CVE-2026-58530High· 7.8Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
CVE-2026-58528Medium· 6.8Windows USB Audio Class Driver Information Disclosure Vulnerability
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-58594High· 8.8Remote Desktop Client Remote Code Execution Vulnerability
Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.
CVE-2026-58547Medium· 5.5Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability
Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.
CVE-2026-58545Medium· 5.5Windows Kernel Security Feature Bypass Vulnerability
Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.
CVE-2026-58540High· 7.8Windows Installer Elevation of Privilege Vulnerability
Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-58536High· 7.8Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-58627High· 7.5Windows DHCP Server Denial of Service Vulnerability
Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2026-58619High· 7.0Windows Sensor Data Service Elevation of Privilege Vulnerability
Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
CVE-2026-58613High· 7.8Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-58541High· 7.8Microsoft DWM Core Library Elevation of Privilege Vulnerability
Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.
CVE-2026-58638Medium· 6.0Windows Boot Loader Security Feature Bypass Vulnerability
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.