📦

windows_server_2008

Vendor: microsoft

Actively Exploited 141 CISA KEV List
PoC / Exploits 454 Code Available
Total RCEs 857 Remote Access
Total CVEs 15418 Total Indexed
Avg. EPSS 8.38% Exploit Prob.
Latest CVE CVE-2026-20940 Jan 13

Security Vulnerability Index

Page 1 / 1542
7.8 CVSS

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

EPSS: 0.45%
4.3 CVSS

Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.

EPSS: 0.44%
8.0 CVSS

External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.

EPSS: 0.75%
7.5 CVSS

Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.

EPSS: 1.14%
5.3 CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service over a network.

EPSS: 0.89%
6.5 CVSS

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

EPSS: 17.31%
7.8 CVSS

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

EPSS: 0.57%
7.5 CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

EPSS: 1.15%
7.5 CVSS

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

EPSS: 1.53%
6.5 CVSS

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

EPSS: 19.11%