cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 100 of 141
CVE-2021-43219P3HIGHCVSS 7.5v20h2v21h1+3 more2021-12-15
CVE-2021-43219 [HIGH] CVE-2021-43219: DirectX Graphics Kernel File Denial of Service Vulnerability DirectX Graphics Kernel File Denial of Service Vulnerability
nvd
CVE-2017-0275P3MEDIUMCVSS 5.9v1511v1607+1 more2017-05-12
CVE-2017-0275 [MEDIUM] CVE-2017-0275: Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vul
nvd
CVE-2021-31183P3HIGHCVSS 7.5v20h2v21h1+4 more2021-07-14
CVE-2021-31183 [HIGH] CVE-2021-31183: Windows TCP/IP Driver Denial of Service Vulnerability Windows TCP/IP Driver Denial of Service Vulnerability
nvd
CVE-2021-26879P3HIGHCVSS 7.5v20h2v1607+4 more2021-03-11
CVE-2021-26879 [HIGH] CVE-2021-26879: Windows Network Address Translation (NAT) Denial of Service Vulnerability Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2019-0972P3MEDIUMCVSS 6.5v1607v1703+4 more2019-06-12
CVE-2019-0972 [MEDIUM] CVE-2019-0972: This security update corrects a denial of service in the Local Security Authority Subsystem Service This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could cause a denial of service on the target system's LSASS service, which triggers an automatic rebo
nvd
CVE-2022-34720P3HIGHCVSS 7.5v20h2v21h1+3 more2022-09-13
CVE-2022-34720 [HIGH] CVE-2022-34720: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2017-0270P3MEDIUMCVSS 5.9v1511v1607+1 more2017-05-12
CVE-2017-0270 [MEDIUM] CVE-2017-0270: Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vul
nvd
CVE-2017-0276P3MEDIUMCVSS 5.9v1511v1607+1 more2017-05-12
CVE-2017-0276 [MEDIUM] CVE-2017-0276: Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vul
nvd
CVE-2017-0268P3MEDIUMCVSS 5.9v1511v1607+1 more2017-05-12
CVE-2017-0268 [MEDIUM] CVE-2017-0268: Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vul
nvd
CVE-2022-26915P3HIGHCVSS 7.5v20h2v21h1+4 more2022-04-15
CVE-2022-26915 [HIGH] CVE-2022-26915: Windows Secure Channel Denial of Service Vulnerability Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2022-30202P3HIGHCVSS 7.0v20h2v21h1+3 more2022-07-12
CVE-2022-30202 [HIGH] CVE-2022-30202: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
nvd
CVE-2021-34490P3HIGHCVSS 7.5v20h2v21h1+3 more2021-07-14
CVE-2021-34490 [HIGH] CVE-2021-34490: Windows TCP/IP Driver Denial of Service Vulnerability Windows TCP/IP Driver Denial of Service Vulnerability
nvd
CVE-2021-33772P3HIGHCVSS 7.5v20h2v21h1+1 more2021-07-14
CVE-2021-33772 [HIGH] CVE-2021-33772: Windows TCP/IP Driver Denial of Service Vulnerability Windows TCP/IP Driver Denial of Service Vulnerability
nvd
CVE-2022-30152P3HIGHCVSS 7.5v20h2v21h1+3 more2022-06-15
CVE-2022-30152 [HIGH] CVE-2022-30152: Windows Network Address Translation (NAT) Denial of Service Vulnerability Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2023-36581P3HIGHCVSS 7.5fixed in 10.0.10240.202322023-10-10
CVE-2023-36581 [HIGH] CWE-126 CVE-2023-36581: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2020-1256P3MEDIUMCVSS 6.5v1607v1709+4 more2020-09-11
CVE-2020-1256 [MEDIUM] CVE-2020-1256: <p>An information disclosure vulnerability exists when the Windows GDI component improperly disclose An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a spe
nvd
CVE-2016-3250P3HIGHCVSS 7.3v15112016-07-13
CVE-2016-3250 [HIGH] CWE-264 CVE-2016-3250: The kernel-mode drivers in Microsoft Windows Server 2012 and Windows 10 Gold and 1511 allow local us The kernel-mode drivers in Microsoft Windows Server 2012 and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
nvd
CVE-2017-8494P3HIGHCVSS 7.3v1511v16072017-06-15
CVE-2017-8494 [HIGH] CWE-281 CVE-2017-8494: Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a locally-authenticat Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a locally-authenticated attacker to run a specially crafted application on a targeted system when Windows Secure Kernel Mode fails to properly handle objects in memory, aka "Windows Elevation of Privilege Vulnerability".
nvd
CVE-2019-0802P3MEDIUMCVSS 6.5v1607v1703+3 more2019-04-09
CVE-2019-0802 [MEDIUM] CVE-2019-0802: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0849.
nvd
CVE-2019-0849P3MEDIUMCVSS 6.5v1607v1703+3 more2019-04-09
CVE-2019-0849 [MEDIUM] CVE-2019-0849: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0802.
nvd
Microsoft Windows 10 vulnerabilities | cvebase