Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27
Vulnerabilities
Page 107 of 141
CVE-2018-8175P4MEDIUMCVSS 6.5v1709v1803+4 more2018-06-14
CVE-2018-8175 [MEDIUM] CVE-2018-8175: An denial of service vulnerability exists when Windows NT WEBDAV Minirdr attempts to query a WEBDAV
An denial of service vulnerability exists when Windows NT WEBDAV Minirdr attempts to query a WEBDAV directory, aka "WEBDAV Denial of Service Vulnerability." This affects Windows 10 Servers, Windows 10.
nvd
CVE-2019-0614P4MEDIUMCVSS 6.5v1607v1703+3 more2019-04-08
CVE-2019-0614 [MEDIUM] CVE-2019-0614: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0774.
nvd
CVE-2020-0774P4MEDIUMCVSS 6.5v1607v1709+4 more2020-03-12
CVE-2020-0774 [MEDIUM] CVE-2020-0774: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0874, CVE-2020-0879, CVE-2020-0880, CVE-2020-0882.
nvd
CVE-2019-1286P4MEDIUMCVSS 6.5v1607v1703+4 more2019-09-11
CVE-2019-1286 [MEDIUM] CVE-2019-1286: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1252.
nvd
CVE-2019-1466P4MEDIUMCVSS 6.5v1607v1709+4 more2019-12-10
CVE-2019-1466 [MEDIUM] CVE-2019-1466: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1465, CVE-2019-1467.
nvd
CVE-2019-1465P4MEDIUMCVSS 6.5v1607v1709+4 more2019-12-10
CVE-2019-1465 [MEDIUM] CWE-125 CVE-2019-1465: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1466, CVE-2019-1467.
nvd
CVE-2019-1467P4MEDIUMCVSS 6.5v1607v1709+4 more2019-12-10
CVE-2019-1467 [MEDIUM] CVE-2019-1467: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1465, CVE-2019-1466.
nvd
CVE-2020-0993P4MEDIUMCVSS 6.5v1607v1709+4 more2020-04-15
CVE-2020-0993 [MEDIUM] CVE-2020-0993: A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries, ak
A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries, aka 'Windows DNS Denial of Service Vulnerability'.
nvd
CVE-2017-0269P4MEDIUMCVSS 5.9v1511v1607+1 more2017-05-12
CVE-2017-0269 [MEDIUM] CWE-20 CVE-2017-0269: The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends speci
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0273 and CVE-2017-0280.
nvd
CVE-2017-0273P4MEDIUMCVSS 5.9v1511v1607+1 more2017-05-12
CVE-2017-0273 [MEDIUM] CVE-2017-0273: The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends speci
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0269 and CVE-2017-0280.
nvd
CVE-2015-2478P4HIGHCVSS 7.2v15112015-11-11
CVE-2015-2478 [HIGH] CWE-264 CVE-2015-2478: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application that triggers a Winsock call referencing an invalid address, aka "Winsock Elevation of Privilege Vuln
nvd
CVE-2015-6126P4HIGHCVSS 7.2v15112015-12-09
CVE-2015-6126 [HIGH] CWE-362 CVE-2015-6126: Race condition in the Pragmatic General Multicast (PGM) protocol implementation in Microsoft Windows
Race condition in the Pragmatic General Multicast (PGM) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges or cause a denial of service (use-after-fre
nvd
CVE-2022-22041P4MEDIUMCVSS 6.8v20h2v21h1+3 more2022-07-12
CVE-2022-22041 [MEDIUM] CVE-2022-22041: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2018-0817P4HIGHCVSS 7.0v1511v1607+2 more2018-03-14
CVE-2018-0817 [HIGH] CVE-2018-0817: The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows
The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows
nvd
CVE-2022-22042P4MEDIUMCVSS 6.5v20h2v21h1+3 more2022-07-12
CVE-2022-22042 [MEDIUM] CVE-2022-22042: Windows Hyper-V Information Disclosure Vulnerability
Windows Hyper-V Information Disclosure Vulnerability
nvd
CVE-2018-0816P4HIGHCVSS 7.0v1511v1607+2 more2018-03-14
CVE-2018-0816 [HIGH] CVE-2018-0816: The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows
The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows
nvd
CVE-2017-11853P4MEDIUMCVSS 5.5v1511v1607+2 more2017-11-15
CVE-2017-11853 [MEDIUM] CVE-2017-11853: Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Server
Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log in and run a specially crafted application due to the Windows kernel improperly initializing a memory address, aka "Window
nvd
CVE-2018-0868P4HIGHCVSS 7.0v1511v1607+2 more2018-03-14
CVE-2018-0868 [HIGH] CWE-20 CVE-2018-0868: Windows Installer in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT
Windows Installer in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how input is sanitized, aka "Windows Installer Elevation of Privilege
nvd
CVE-2018-0809P4HIGHCVSS 7.0v1703v17092018-02-15
CVE-2018-0809 [HIGH] CVE-2018-0809: The Windows kernel in Windows 10, versions 1703 and 1709, and Windows Server, version 1709 allows an
The Windows kernel in Windows 10, versions 1703 and 1709, and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0742, CVE-2018-0756, CVE-2018-0820 and CVE-2018-0843.
nvd
CVE-2018-0983P4HIGHCVSS 7.0v1511v1607+2 more2018-03-14
CVE-2018-0983 [HIGH] CVE-2018-0983: Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and W
Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Storage Services Elevation of Privilege Vulnerability".
nvd