Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27
Vulnerabilities
Page 103 of 141
CVE-2022-35822P3HIGHCVSS 7.1v20h2v21h1+3 more2022-08-15
CVE-2022-35822 [HIGH] CVE-2022-35822: Windows Defender Credential Guard Security Feature Bypass Vulnerability
Windows Defender Credential Guard Security Feature Bypass Vulnerability
nvd
CVE-2019-1018P4HIGHCVSS 7.0v1607v1703+3 more2019-06-12
CVE-2019-1018 [HIGH] CVE-2019-1018: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would
nvd
CVE-2019-1176P4HIGHCVSS 7.0v1607v1703+4 more2019-08-14
CVE-2019-1176 [HIGH] CVE-2019-1176: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would
nvd
CVE-2022-21863P4HIGHCVSS 7.0v20h2v21h1+4 more2022-01-11
CVE-2022-21863 [HIGH] CVE-2022-21863: Windows StateRepository API Server file Elevation of Privilege Vulnerability
Windows StateRepository API Server file Elevation of Privilege Vulnerability
nvd
CVE-2020-15707P4MEDIUMCVSS 6.4v1607v1709+5 more2020-07-29
CVE-2020-15707 [MEDIUM] CWE-362 CVE-2020-15707: Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efili
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command
nvd
CVE-2019-0961P3MEDIUMCVSS 6.5v1607v1703+4 more2019-05-16
CVE-2019-0961 [MEDIUM] CVE-2019-0961: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0758, CVE-2019-0882.
nvd
CVE-2019-0882P3MEDIUMCVSS 6.5v1607v1703+4 more2019-05-16
CVE-2019-0882 [MEDIUM] CVE-2019-0882: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0758, CVE-2019-0961.
nvd
CVE-2019-0774P3MEDIUMCVSS 6.5v1607v1703+3 more2019-04-09
CVE-2019-0774 [MEDIUM] CVE-2019-0774: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0614.
nvd
CVE-2019-1094P3MEDIUMCVSS 6.5v1607v1703+4 more2019-07-15
CVE-2019-1094 [MEDIUM] CWE-200 CVE-2019-1094: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1095, CVE-2019-1098, CVE-2019-1099, CVE-2019-1100, CVE-2019-1101, CVE-2019-1116.
nvd
CVE-2019-1095P3MEDIUMCVSS 6.5v1607v1703+4 more2019-07-15
CVE-2019-1095 [MEDIUM] CVE-2019-1095: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1098, CVE-2019-1099, CVE-2019-1100, CVE-2019-1101, CVE-2019-1116.
nvd
CVE-2017-0170P4MEDIUMCVSS 6.5v1511v1607+1 more2017-07-11
CVE-2017-0170 [MEDIUM] CWE-611 CVE-2017-0170: Windows Performance Monitor in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windo
Windows Performance Monitor in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability due to the way it parses XML input, aka "Windows Performance Monitor Information Disclosure Vulnerabili
nvd
CVE-2017-8695P3MEDIUMCVSS 5.3v1511v1607+1 more2017-09-13
CVE-2017-8695 [MEDIUM] CWE-200 CVE-2017-8695: Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windo
Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, 1607, 1703, and Server 2016; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live
nvd
CVE-2020-0853P4MEDIUMCVSS 6.5v1607v1709+4 more2020-03-12
CVE-2020-0853 [MEDIUM] CVE-2020-0853: An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails t
An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails to properly handle objects in memory, aka 'Windows Imaging Component Information Disclosure Vulnerability'.
nvd
CVE-2021-38665P4MEDIUMCVSS 6.5v20h2v21h1+4 more2021-11-10
CVE-2021-38665 [MEDIUM] CVE-2021-38665: Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability
nvd
CVE-2019-1230P4MEDIUMCVSS 6.8v1703v1709+2 more2019-10-10
CVE-2019-1230 [MEDIUM] CWE-20 CVE-2019-1230: An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host ope
An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Information Disclosure Vulnerability'.
nvd
CVE-2019-0704P3MEDIUMCVSS 6.5v1607v1703+3 more2019-04-09
CVE-2019-0704 [MEDIUM] CVE-2019-0704: An information disclosure vulnerability exists in the way that the Windows SMB Server handles certai
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0703, CVE-2019-0821.
nvd
CVE-2019-1025P3MEDIUMCVSS 6.5v1607v1703+4 more2019-06-12
CVE-2019-1025 [MEDIUM] CVE-2019-1025: A denial of service vulnerability exists when Windows improperly handles objects in memory. An attac
A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application or to convince a user to open a specif
nvd
CVE-2023-21811P3HIGHCVSS 7.5fixed in 10.0.10240.197472023-02-14
CVE-2023-21811 [HIGH] CWE-126 CVE-2023-21811: Windows iSCSI Service Denial of Service Vulnerability
Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2023-21700P3HIGHCVSS 7.5fixed in 10.0.10240.197472023-02-14
CVE-2023-21700 [HIGH] CWE-476 CVE-2023-21700: Windows iSCSI Discovery Service Denial of Service Vulnerability
Windows iSCSI Discovery Service Denial of Service Vulnerability
nvd
CVE-2023-21702P3HIGHCVSS 7.5fixed in 10.0.10240.197472023-02-14
CVE-2023-21702 [HIGH] CWE-125 CVE-2023-21702: Windows iSCSI Service Denial of Service Vulnerability
Windows iSCSI Service Denial of Service Vulnerability
nvd