📦

windows_server_2008

Vendor: microsoft

Actively Exploited 141 CISA KEV List
PoC / Exploits 454 Code Available
Total RCEs 810 Remote Access
Total CVEs 16698 Total Indexed
Avg. EPSS 8.39% Exploit Prob.
Latest CVE CVE-2026-20940 Jan 13

Security Vulnerability Index

Page 19 / 1670
7.8 CVSS

Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.

EPSS: 0.37%
5.5 CVSS

Out-of-bounds read in Windows TDX.sys allows an authorized attacker to disclose information locally.

EPSS: 0.45%
8.8 CVSS

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

EPSS: 0.92%
8.8 CVSS

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

EPSS: 0.90%
7.1 CVSS

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network.

EPSS: 0.44%
7.1 CVSS

Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network.

EPSS: 0.33%
7.8 CVSS

Integer overflow or wraparound in HID class driver allows an authorized attacker to elevate privileges locally.

EPSS: 0.35%
7.8 CVSS

Access of resource using incompatible type ('type confusion') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

EPSS: 0.38%
7.5 CVSS

Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker to bypass a security feature over a network.

EPSS: 1.01%
5.5 CVSS

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

EPSS: 0.49%