Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27
Vulnerabilities
Page 105 of 141
CVE-2020-0880P4MEDIUMCVSS 6.5v1607v1709+4 more2020-03-12
CVE-2020-0880 [MEDIUM] CVE-2020-0880: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0774, CVE-2020-0874, CVE-2020-0879, CVE-2020-0882.
nvd
CVE-2020-0882P4MEDIUMCVSS 6.5v1607v1709+4 more2020-03-12
CVE-2020-0882 [MEDIUM] CVE-2020-0882: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0774, CVE-2020-0874, CVE-2020-0879, CVE-2020-0880.
nvd
CVE-2018-8422P4MEDIUMCVSS 6.5v32-bit SystemsvVersion 1607 for 32-bit Systems+8 more2018-09-13
CVE-2018-8422 [MEDIUM] CWE-200 CVE-2018-8422: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8424.
nvd
CVE-2020-1179P4MEDIUMCVSS 6.5v1607v1709+4 more2020-05-21
CVE-2020-1179 [MEDIUM] CVE-2020-1179: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0963, CVE-2020-1141, CVE-2020-1145.
nvd
CVE-2019-0712P4MEDIUMCVSS 6.8v1607v1709+3 more2019-11-12
CVE-2019-0712 [MEDIUM] CWE-20 CVE-2019-0712: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1309, CVE-2019-1310, CVE-2019-1399.
nvd
CVE-2019-1309P4MEDIUMCVSS 6.8v1709v1803+2 more2019-11-12
CVE-2019-1309 [MEDIUM] CVE-2019-1309: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0712, CVE-2019-1310, CVE-2019-1399.
nvd
CVE-2019-1310P4MEDIUMCVSS 6.8v1803v1809+1 more2019-11-12
CVE-2019-1310 [MEDIUM] CVE-2019-1310: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0712, CVE-2019-1309, CVE-2019-1399.
nvd
CVE-2020-1232P4MEDIUMCVSS 6.5v1607v1709+5 more2020-06-09
CVE-2020-1232 [MEDIUM] CWE-125 CVE-2020-1232: An information disclosure vulnerability exists when Media Foundation improperly handles objects in m
An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosure Vulnerability'.
nvd
CVE-2020-0952P4MEDIUMCVSS 6.5v1607v1709+4 more2020-04-15
CVE-2020-0952 [MEDIUM] CVE-2020-0952: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
nvd
CVE-2017-0280P4MEDIUMCVSS 5.9v1511v1607+1 more2017-05-12
CVE-2017-0280 [MEDIUM] CVE-2017-0280: The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends speci
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0269 and CVE-2017-0273.
nvd
CVE-2020-0963P4MEDIUMCVSS 6.5v1607v1709+4 more2020-05-21
CVE-2020-0963 [MEDIUM] CVE-2020-0963: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1141, CVE-2020-1145, CVE-2020-1179.
nvd
CVE-2020-1348P4MEDIUMCVSS 6.5v1607v1709+5 more2020-06-09
CVE-2020-1348 [MEDIUM] CVE-2020-1348: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
nvd
CVE-2020-1468P4MEDIUMCVSS 6.5v1607v1709+5 more2020-07-14
CVE-2020-1468 [MEDIUM] CVE-2020-1468: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
nvd
CVE-2019-1411P4MEDIUMCVSS 6.5v1607v1709+3 more2019-11-12
CVE-2019-1411 [MEDIUM] CWE-125 CVE-2019-1411: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1432.
nvd
CVE-2020-0837P4MEDIUMCVSS 5.3v1607v1809+3 more2020-09-11
CVE-2020-0837 [MEDIUM] CVE-2020-0837: <p>An elevation of privilege vulnerability exists when Active Directory Federation Services (ADFS) i
An elevation of privilege vulnerability exists when Active Directory Federation Services (ADFS) improperly handles multi-factor authentication requests. An attacker who successfully exploited this vulnerability could bypass some, but not all, of the authentication factors.
To exploit this vulnerability, an attacker could send a specially crafted authenticatio
nvd
CVE-2018-8444P4MEDIUMCVSS 5.9v32-bit Systemsvx64-based Systems2018-09-13
CVE-2018-8444 [MEDIUM] CWE-200 CVE-2018-8444: An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 2.
An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka "Windows SMB Information Disclosure Vulnerability." This affects Windows Server 2012, Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012 R2.
nvd
CVE-2016-3272P4LOWCVSS 2.8v15112016-07-13
CVE-2016-3272 [LOW] CWE-200 CVE-2016-3272: The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandles page-fault system calls, which allows local users to obtain sensitive information from an arbitrary process via a crafted application, aka "Windows Kernel Information Disclosure Vulnerability."
nvd
CVE-2019-0717P4MEDIUMCVSS 5.8v1809v19032019-08-14
CVE-2019-0717 [MEDIUM] CWE-20 CVE-2019-0717: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash.
To exploit the vulnerability, an attacker who already has a privileged account
nvd
CVE-2019-0718P4MEDIUMCVSS 5.8v1607v1703+4 more2019-08-14
CVE-2019-0718 [MEDIUM] CWE-20 CVE-2019-0718: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash.
To exploit the vulnerability, an attacker who already has a privileged account
nvd
CVE-2019-0723P4MEDIUMCVSS 5.8v1607v1703+4 more2019-08-14
CVE-2019-0723 [MEDIUM] CWE-20 CVE-2019-0723: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash.
To exploit the vulnerability, an attacker who already has a privileged account
nvd