cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 10 of 141
CVE-2019-1347P3MEDIUMCVSS 6.5PoCv1607v1703+4 more2019-10-10
CVE-2019-1347 [MEDIUM] CVE-2019-1347: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1343, CVE-2019-1346.
nvd
CVE-2016-7188P3HIGHCVSS 7.8PoCv1511v16072016-10-14
CVE-2016-7188 [HIGH] CWE-264 CVE-2016-7188: The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 16 The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Windows Diagnostics Hub Elevation of Privilege Vulnerability."
nvd
CVE-2017-0165P3HIGHCVSS 7.8PoCv15112017-04-12
CVE-2017-0165 [HIGH] CVE-2017-0165: An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 fails to properly sanitize handles in memory, aka "Windows Elevation of Privilege Vulnerability."
nvd
CVE-2018-8411P3HIGHCVSS 7.8PoCv1607v1703+15 more2018-10-10
CVE-2018-8411 [HIGH] CWE-732 CVE-2018-8411: An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevati An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2019-0570P3HIGHCVSS 7.8PoCv1607v1703+18 more2019-01-08
CVE-2019-0570 [HIGH] CWE-416 CVE-2019-0570: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects i An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka "Windows Runtime Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
nvd
CVE-2019-0805P3HIGHCVSS 7.8PoCv1607v1703+3 more2019-04-09
CVE-2019-0805 [HIGH] CVE-2019-0805: An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV dr An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0836, CVE-2019-0841.
nvd
CVE-2019-0881P3HIGHCVSS 7.8PoCv1607v1703+4 more2019-05-16
CVE-2019-0881 [HIGH] CWE-522 CVE-2019-0881: An elevation of privilege vulnerability exists when the Windows Kernel improperly handles key enumer An elevation of privilege vulnerability exists when the Windows Kernel improperly handles key enumeration, aka 'Windows Kernel Elevation of Privilege Vulnerability'.
nvd
CVE-2019-0943P3HIGHCVSS 7.8PoCv1607v1703+4 more2019-06-12
CVE-2019-0943 [HIGH] CVE-2019-0943: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Loc An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user
nvd
CVE-2016-3238P2HIGHCVSS 8.1v15112016-07-13
CVE-2016-3238 [HIGH] CWE-254 CVE-2016-3238: The Print Spooler service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Window The Print Spooler service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows man-in-the-middle attackers to execute arbitrary code by providing a crafted print driver during printer installation, aka "Windows Print Spooler Re
nvd
CVE-2016-3219P3HIGHCVSS 7.8PoCv15112016-06-16
CVE-2016-3219 [HIGH] CWE-264 CVE-2016-3219: The kernel-mode driver in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges v The kernel-mode driver in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
nvd
CVE-2020-17095P2CRITICALCVSS 9.9v20h2v1607+5 more2020-12-10
CVE-2020-17095 [CRITICAL] CVE-2020-17095: Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2020-0729P2HIGHCVSS 8.8v1607v1709+4 more2020-02-11
CVE-2020-0729 [HIGH] CVE-2020-0729: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
nvd
CVE-2018-8626P2CRITICALCVSS 9.8v1607v1709+13 more2018-12-12
CVE-2018-8626 [CRITICAL] CWE-787 CVE-2018-8626: A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they f A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly handle requests, aka "Windows DNS Server Heap Overflow Vulnerability." This affects Windows Server 2012 R2, Windows Server 2019, Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2016-0006P3HIGHCVSS 7.3PoCv15112016-01-13
CVE-2016-0006 [HIGH] CWE-264 CVE-2016-0006: The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windo The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles reparse points, which allows local users to gain privileges via a crafted application, aka "Windows Mount Point Elevation o
nvd
CVE-2019-0555P3HIGHCVSS 7.8PoCv1607v1703+3 more2019-01-08
CVE-2019-0555 [HIGH] CWE-862 CVE-2019-0555: An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow a An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft XmlDocument Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 2016, Window
nvd
CVE-2019-1343P3MEDIUMCVSS 6.5PoCv1607v1703+4 more2019-10-10
CVE-2019-1343 [MEDIUM] CVE-2019-1343: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1346, CVE-2019-1347.
nvd
CVE-2019-1346P3MEDIUMCVSS 6.5PoCv1607v1703+4 more2019-10-10
CVE-2019-1346 [MEDIUM] CVE-2019-1346: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1343, CVE-2019-1347.
nvd
CVE-2021-36936P2CRITICALCVSS 9.8v20h2v21h1+4 more2021-08-12
CVE-2021-36936 [CRITICAL] CVE-2021-36936: Windows Print Spooler Remote Code Execution Vulnerability Windows Print Spooler Remote Code Execution Vulnerability
nvd
CVE-2019-1358P3HIGHCVSS 7.8v1607v1703+4 more2019-10-10
CVE-2019-1358 [HIGH] CVE-2019-1358: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1359.
nvd
CVE-2022-21990P2HIGHCVSS 8.8v20h2v21h1+4 more2022-03-09
CVE-2022-21990 [HIGH] CVE-2022-21990: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
Microsoft Windows 10 vulnerabilities | cvebase