📦

windows_server_2008

Vendor: microsoft

Actively Exploited 141 CISA KEV List
PoC / Exploits 454 Code Available
Total RCEs 810 Remote Access
Total CVEs 16698 Total Indexed
Avg. EPSS 8.39% Exploit Prob.
Latest CVE CVE-2026-20940 Jan 13

Security Vulnerability Index

Page 6 / 1670
8.8 CVSS

Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.

EPSS: 1.81%
7.0 CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.

EPSS: 0.58%
3.1 CVSS

Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.

EPSS: 0.41%
7.8 CVSS

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

EPSS: 0.25%
7.8 CVSS

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

EPSS: 0.34%
7.8 CVSS

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

EPSS: 0.25%
7.8 CVSS

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

EPSS: 0.37%
7.8 CVSS

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

EPSS: 2.61%
6.5 CVSS

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

EPSS: 1.82%
7.1 CVSS

Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network.

EPSS: 0.46%