cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 1 of 141
CVE-2018-8174P1HIGHCVSS 7.5KEVPoCRansomwarev32-bit SystemsvVersion 1607 for 32-bit Systems+8 more2018-05-09
CVE-2018-8174 [HIGH] CWE-787 CVE-2018-8174: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windo
nvd
CVE-2018-8453P1HIGHCVSS 7.8KEVPoCRansomwarev32-bit SystemsvVersion 1607 for 32-bit Systems+10 more2018-10-10
CVE-2018-8453 [HIGH] CVE-2018-8453: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2,
nvd
CVE-2018-8120P1HIGHCVSS 7.0KEVPoCRansomwarev32-bit SystemsvVersion 1607 for 32-bit Systems+8 more2018-05-09
CVE-2018-8120 [HIGH] CWE-404 CVE-2018-8120: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166.
nvd
CVE-2018-8414P1HIGHCVSS 8.8KEVPoCvVersion 1703 for 32-bit SystemsvVersion 1703 for x64-based Systems+4 more2018-08-15
CVE-2018-8414 [HIGH] CWE-20 CVE-2018-8414: A remote code execution vulnerability exists when the Windows Shell does not properly validate file A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.
nvd
CVE-2018-8639P1HIGHCVSS 7.8KEVPoCRansomwarev32-bit SystemsvVersion 1607 for 32-bit Systems+13 more2018-12-12
CVE-2018-8639 [HIGH] CWE-404 CVE-2018-8639: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server
nvd
CVE-2018-8440P1HIGHCVSS 7.8KEVPoCRansomwarev32-bit SystemsvVersion 1607 for 32-bit Systems+8 more2018-09-13
CVE-2018-8440 [HIGH] CVE-2018-8440: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Loc An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Wind
nvd
CVE-2018-8611P1HIGHCVSS 7.8KEVPoCv32-bit SystemsvVersion 1607 for 32-bit Systems+13 more2018-12-12
CVE-2018-8611 [HIGH] CWE-404 CVE-2018-8611: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008
nvd
CVE-2022-21907P1CRITICALCVSS 9.8ExploitedPoCv20h2v21h1+2 more2022-01-11
CVE-2022-21907 [CRITICAL] CVE-2022-21907: HTTP Protocol Stack Remote Code Execution Vulnerability HTTP Protocol Stack Remote Code Execution Vulnerability
nvd
CVE-2022-26809P1CRITICALCVSS 9.8ExploitedPoCRansomwarev20h2v21h1+4 more2022-04-15
CVE-2022-26809 [CRITICAL] CVE-2022-26809: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2022-34721P1CRITICALCVSS 9.8ExploitedPoCv20h2v21h1+3 more2022-09-13
CVE-2022-34721 [CRITICAL] CVE-2022-34721: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2018-3639P1MEDIUMCVSS 5.5ExploitedPoCRansomwarev1607v1703+3 more2018-05-22
CVE-2018-3639 [MEDIUM] CWE-203 CVE-2018-3639: Systems with microprocessors utilizing speculative execution and speculative execution of memory rea Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
nvd
CVE-2019-1040P1MEDIUMCVSS 5.3ExploitedPoCv1607v1703+4 more2019-06-12
CVE-2019-1040 [MEDIUM] CVE-2019-1040: A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to s A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection. An attacker who successfully exploited this vulnerability could gain the ability to downgrade NTLM security features. To exploit this vulnerability, the attacker would need to tamper with the
nvd
CVE-2016-3225P2HIGHCVSS 7.8ExploitedPoCv15112016-06-16
CVE-2016-3225 [HIGH] CWE-264 CVE-2016-3225: The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application that forwards an authentication request to an unintended service, aka "Windows SMB Server El
nvd
CVE-2020-17103P2HIGHCVSS 7.8ExploitedPoCv20h2v1803+4 more2020-12-10
CVE-2020-17103 [HIGH] CWE-269 CVE-2020-17103: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2020-0624P1HIGHCVSS 7.8ExploitedPoCRansomwarev1903v19092020-01-14
CVE-2020-0624 [HIGH] CVE-2020-0624: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0642.
nvd
CVE-2016-0051P2HIGHCVSS 7.8ExploitedPoCv15112016-02-10
CVE-2016-0051 [HIGH] CWE-264 CVE-2016-0051: The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "WebDAV Elevation of Privilege Vulnerability."
nvd
CVE-2020-0642P1HIGHCVSS 7.8ExploitedPoCRansomwarev1607v1709+4 more2020-01-14
CVE-2020-0642 [HIGH] CVE-2020-0642: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0624.
nvd
CVE-2022-24481P2HIGHCVSS 7.8ExploitedPoCv20h2v21h1+4 more2022-04-15
CVE-2022-24481 [HIGH] CVE-2022-24481: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2020-1048P2HIGHCVSS 7.8ExploitedPoCv1607v1709+4 more2020-05-21
CVE-2020-1048 [HIGH] CWE-669 CVE-2020-1048: An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly all An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Print Spooler Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1070.
nvd
CVE-2016-0095P2HIGHCVSS 7.8ExploitedPoCv15112016-03-09
CVE-2016-0095 [HIGH] CVE-2016-0095: The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0093, CVE-
nvd
1 / 141Next →
Microsoft Windows 10 vulnerabilities | cvebase