📦

windows_server_2008

Vendor: microsoft

Actively Exploited 141 CISA KEV List
PoC / Exploits 454 Code Available
Total RCEs 810 Remote Access
Total CVEs 16698 Total Indexed
Avg. EPSS 8.39% Exploit Prob.
Latest CVE CVE-2026-20940 Jan 13

Security Vulnerability Index

Page 26 / 1670
8.6 CVSS

Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally.

EPSS: 0.62%
7.8 CVSS

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

EPSS: 0.64%
7.0 CVSS

Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

EPSS: 0.31%
7.8 CVSS

Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.

EPSS: 0.86%
7.5 CVSS

Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over a network.

EPSS: 0.68%
8.8 CVSS

Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

EPSS: 1.07%
7.0 CVSS

Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.

EPSS: 0.40%
8.8 CVSS

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

EPSS: 1.45%
6.5 CVSS

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

EPSS: 1.47%
7.5 CVSS

Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

EPSS: 1.80%