Microsoft Windows vulnerabilities
459 known vulnerabilities affecting microsoft/windows.
Total CVEs
459
CISA KEV
22
actively exploited
Public exploits
29
Exploited in wild
30
Severity breakdown
CRITICAL12HIGH301MEDIUM144LOW2
Vulnerabilities
Page 23 of 23
CVE-2020-0617P4MEDIUMCVSS 6.0v10 Version 1803 for x64-based Systemsv10 Version 1809 for x64-based Systems+3 more2020-01-14
CVE-2020-0617 [MEDIUM] CWE-20 CVE-2020-0617: A denial of service vulnerability exists when Microsoft Hyper-V Virtual PCI on a host server fails t
A denial of service vulnerability exists when Microsoft Hyper-V Virtual PCI on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Hyper-V Denial of Service Vulnerability'.
nvd
CVE-2020-0714P4MEDIUMCVSS 5.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+4 more2020-02-11
CVE-2020-0714 [MEDIUM] CVE-2020-0714: An information disclosure vulnerability exists when DirectX improperly handles objects in memory, ak
An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Information Disclosure Vulnerability'.
nvd
CVE-2019-1325P4MEDIUMCVSS 5.5v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-10-10
CVE-2019-1325 [MEDIUM] CVE-2019-1325: An elevation of privilege vulnerability exists in the Windows redirected drive buffering system (rdb
An elevation of privilege vulnerability exists in the Windows redirected drive buffering system (rdbss.sys) when the operating system improperly handles specific local calls within Windows 7 for 32-bit systems, aka 'Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1016P4MEDIUMCVSS 5.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+14 more2020-04-15
CVE-2020-1016 [MEDIUM] CVE-2020-1016: An information disclosure vulnerability exists when the Windows Push Notification Service improperly
An information disclosure vulnerability exists when the Windows Push Notification Service improperly handles objects in memory, aka 'Windows Push Notification Service Information Disclosure Vulnerability'.
nvd
CVE-2019-1294P4MEDIUMCVSS 4.6v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+4 more2019-09-11
CVE-2019-1294 [MEDIUM] CVE-2019-1294: A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging f
A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging functionality, aka 'Windows Secure Boot Security Feature Bypass Vulnerability'.
nvd
CVE-2020-0885P4MEDIUMCVSS 4.3v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-03-12
CVE-2020-0885 [MEDIUM] CVE-2020-0885: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows Graphics Component Information Disclosure Vulnerability'.
nvd
CVE-2020-1261P4MEDIUMCVSS 5.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-06-09
CVE-2020-1261 [MEDIUM] CVE-2020-1261: An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles obje
An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka 'Windows Error Reporting Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1263.
nvd
CVE-2020-1120P4MEDIUMCVSS 5.5v10 Version 1809 for 32-bit Systemsv10 Version 1809 for x64-based Systems+1 more2020-06-09
CVE-2020-1120 [MEDIUM] CVE-2020-1120: A denial of service vulnerability exists when Connected User Experiences and Telemetry Service impro
A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-1244.
nvd
CVE-2019-1368P4MEDIUMCVSS 4.6v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+4 more2019-10-10
CVE-2019-1368 [MEDIUM] CVE-2019-1368: A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging f
A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging functionality, aka 'Windows Secure Boot Security Feature Bypass Vulnerability'.
nvd
CVE-2020-0616P4MEDIUMCVSS 5.5v10 Version 1809 for 32-bit Systemsv10 Version 1809 for x64-based Systems+1 more2020-01-14
CVE-2020-0616 [MEDIUM] CWE-59 CVE-2020-0616: A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft
A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.
nvd
CVE-2019-0754P4MEDIUMCVSS 5.5v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-04-09
CVE-2019-0754 [MEDIUM] CVE-2019-0754: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.
nvd
CVE-2020-1084P4MEDIUMCVSS 5.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+11 more2020-05-21
CVE-2020-1084 [MEDIUM] CWE-20 CVE-2020-1084: A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails
A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values.An attacker who successfully exploited this vulnerability could deny dependent security feature functionality.To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially c
nvd
CVE-2019-0600P4MEDIUMCVSS 4.7v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-03-05
CVE-2019-0600 [MEDIUM] CVE-2019-0600: An information disclosure vulnerability exists when the Human Interface Devices (HID) component impr
An information disclosure vulnerability exists when the Human Interface Devices (HID) component improperly handles objects in memory, aka 'HID Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0601.
nvd
CVE-2020-0794P4MEDIUMCVSS 5.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+7 more2020-04-15
CVE-2020-0794 [MEDIUM] CVE-2020-0794: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.
nvd
CVE-2020-1194P4MEDIUMCVSS 5.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-06-09
CVE-2020-1194 [MEDIUM] CVE-2020-1194: A denial of service vulnerability exists when Windows Registry improperly handles filesystem operati
A denial of service vulnerability exists when Windows Registry improperly handles filesystem operations, aka 'Windows Registry Denial of Service Vulnerability'.
nvd
CVE-2020-0621P4MEDIUMCVSS 4.4v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+7 more2020-01-14
CVE-2020-0621 [MEDIUM] CWE-613 CVE-2020-0621: A security feature bypass vulnerability exists in Windows 10 when third party filters are called dur
A security feature bypass vulnerability exists in Windows 10 when third party filters are called during a password update, aka 'Windows Security Feature Bypass Vulnerability'.
nvd
CVE-2020-1076P4MEDIUMCVSS 5.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+14 more2020-05-21
CVE-2020-1076 [MEDIUM] CVE-2020-1076: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.
nvd
CVE-2019-1418P4LOWCVSS 3.3v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+16 more2019-11-12
CVE-2019-1418 [LOW] CWE-200 CVE-2019-1418: An information vulnerability exists when Windows Modules Installer Service improperly discloses file
An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules Installer Service Information Disclosure Vulnerability'.
nvd
CVE-2019-1488P4LOWCVSS 3.3v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2019-12-10
CVE-2019-1488 [LOW] CVE-2019-1488: A security feature bypass vulnerability exists when Microsoft Defender improperly handles specific b
A security feature bypass vulnerability exists when Microsoft Defender improperly handles specific buffers, aka 'Microsoft Defender Security Feature Bypass Vulnerability'.
nvd
← Previous23 / 23