Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27
Vulnerabilities
Page 101 of 141
CVE-2022-22040P3HIGHCVSS 7.3v20h2v21h1+3 more2022-07-12
CVE-2022-22040 [HIGH] CVE-2022-22040: Internet Information Services Dynamic Compression Module Denial of Service Vulnerability
Internet Information Services Dynamic Compression Module Denial of Service Vulnerability
nvd
CVE-2018-8438P4MEDIUMCVSS 6.8v1607v1709+1 more2018-09-13
CVE-2018-8438 [MEDIUM] CVE-2018-8438: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. This C
nvd
CVE-2019-0660P3MEDIUMCVSS 6.5v1607v1703+3 more2019-03-05
CVE-2019-0660 [MEDIUM] CVE-2019-0660: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0602, CVE-2019-0615, CVE-2019-0616, CVE-2019-0619, CVE-2019-0664.
nvd
CVE-2019-0615P3MEDIUMCVSS 6.5v1607v1703+3 more2019-03-05
CVE-2019-0615 [MEDIUM] CVE-2019-0615: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0602, CVE-2019-0616, CVE-2019-0619, CVE-2019-0660, CVE-2019-0664.
nvd
CVE-2019-0602P3MEDIUMCVSS 6.5v1607v1703+3 more2019-03-05
CVE-2019-0602 [MEDIUM] CVE-2019-0602: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0615, CVE-2019-0616, CVE-2019-0619, CVE-2019-0660, CVE-2019-0664.
nvd
CVE-2019-0616P3MEDIUMCVSS 6.5v1607v1703+3 more2019-03-05
CVE-2019-0616 [MEDIUM] CVE-2019-0616: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0602, CVE-2019-0615, CVE-2019-0619, CVE-2019-0660, CVE-2019-0664.
nvd
CVE-2019-0619P3MEDIUMCVSS 6.5v1607v1703+3 more2019-03-05
CVE-2019-0619 [MEDIUM] CVE-2019-0619: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0602, CVE-2019-0615, CVE-2019-0616, CVE-2019-0660, CVE-2019-0664.
nvd
CVE-2017-8582P4MEDIUMCVSS 5.9v1511v1607+1 more2017-07-11
CVE-2017-8582 [MEDIUM] CWE-200 CVE-2017-8582: HTTP.sys in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
HTTP.sys in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when the component improperly handles objects in memory, aka "Https.sys Information Disclosure Vulnerability
nvd
CVE-2019-0821P3MEDIUMCVSS 6.5v1607v1703+3 more2019-04-09
CVE-2019-0821 [MEDIUM] CVE-2019-0821: An information disclosure vulnerability exists in the way that the Windows SMB Server handles certai
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0703, CVE-2019-0704.
nvd
CVE-2022-37973P3HIGHCVSS 7.7v20h2v21h1+1 more2022-10-11
CVE-2022-37973 [HIGH] CVE-2022-37973: Windows Local Session Manager (LSM) Denial of Service Vulnerability
Windows Local Session Manager (LSM) Denial of Service Vulnerability
nvd
CVE-2022-37998P3HIGHCVSS 7.7v20h2v21h1+1 more2022-10-11
CVE-2022-37998 [HIGH] CVE-2022-37998: Windows Local Session Manager (LSM) Denial of Service Vulnerability
Windows Local Session Manager (LSM) Denial of Service Vulnerability
nvd
CVE-2021-31968P3HIGHCVSS 7.5v20h2v21h1+4 more2021-06-08
CVE-2021-31968 [HIGH] CVE-2021-31968: Windows Remote Desktop Services Denial of Service Vulnerability
Windows Remote Desktop Services Denial of Service Vulnerability
nvd
CVE-2017-0274P3MEDIUMCVSS 5.9v1511v1607+1 more2017-05-12
CVE-2017-0274 [MEDIUM] CVE-2017-0274: Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way
Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vul
nvd
CVE-2021-33785P3HIGHCVSS 7.5v20h2v21h1+3 more2021-07-14
CVE-2021-33785 [HIGH] CVE-2021-33785: Windows AF_UNIX Socket Provider Denial of Service Vulnerability
Windows AF_UNIX Socket Provider Denial of Service Vulnerability
nvd
CVE-2022-21889P3HIGHCVSS 7.5v20h2v21h1+4 more2022-01-11
CVE-2022-21889 [HIGH] CVE-2022-21889: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2022-21890P3HIGHCVSS 7.5v20h2v21h1+4 more2022-01-11
CVE-2022-21890 [HIGH] CVE-2022-21890: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2017-8460P4HIGHCVSS 7.3v1511v1607+1 more2017-06-15
CVE-2017-8460 [HIGH] CWE-200 CVE-2017-8460: Windows PDF in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511,
Windows PDF in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows information disclosure when a user opens a specially crafted PDF file, aka "Windows PDF Information Disclosure Vulnerability".
nvd
CVE-2022-35833P3HIGHCVSS 7.5v20h2v21h1+3 more2022-09-13
CVE-2022-35833 [HIGH] CVE-2022-35833: Windows Secure Channel Denial of Service Vulnerability
Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2022-34701P3HIGHCVSS 7.5v20h2v21h1+3 more2022-08-09
CVE-2022-34701 [HIGH] CWE-400 CVE-2022-34701: Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
nvd
CVE-2016-3299P4MEDIUMCVSS 5.3v1511v16072016-08-09
CVE-2016-3299 [MEDIUM] CWE-284 CVE-2016-3299: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow remote attackers to hijack network traffic or bypass intended Enhanced Protected Mode (EPM) or application container protection mechanisms, and consequently render untrusted co
nvd