cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 110 of 141
CVE-2019-1186P4HIGHCVSS 7.0v1607v1703+4 more2019-08-14
CVE-2019-1186 [HIGH] CVE-2019-1186: An elevation of privilege vulnerability exists in the way that the wcmsvc.dll handles objects in mem An elevation of privilege vulnerability exists in the way that the wcmsvc.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addresses the vulnerability b
nvd
CVE-2019-1173P4HIGHCVSS 7.0v1803v1809+1 more2019-08-14
CVE-2019-1173 [HIGH] CVE-2019-1173: An elevation of privilege vulnerability exists in the way that the PsmServiceExtHost.dll handles obj An elevation of privilege vulnerability exists in the way that the PsmServiceExtHost.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addresses the vuln
nvd
CVE-2019-1175P4HIGHCVSS 7.0v1709v1803+2 more2019-08-14
CVE-2019-1175 [HIGH] CWE-269 CVE-2019-1175: An elevation of privilege vulnerability exists in the way that the psmsrv.dll handles objects in mem An elevation of privilege vulnerability exists in the way that the psmsrv.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addresses the vulnera
nvd
CVE-2019-1174P4HIGHCVSS 7.0v1809v19032019-08-14
CVE-2019-1174 [HIGH] CWE-1257 CVE-2019-1174: An elevation of privilege vulnerability exists in the way that the PsmServiceExtHost.dll handles obj An elevation of privilege vulnerability exists in the way that the PsmServiceExtHost.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addresses
nvd
CVE-2019-1177P4HIGHCVSS 7.0v1607v1703+4 more2019-08-14
CVE-2019-1177 [HIGH] CWE-269 CVE-2019-1177: An elevation of privilege vulnerability exists in the way that the rpcss.dll handles objects in memo An elevation of privilege vulnerability exists in the way that the rpcss.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addresses the vulnerab
nvd
CVE-2022-29125P4HIGHCVSS 7.0v20h2v21h1+4 more2022-05-10
CVE-2022-29125 [HIGH] CVE-2022-29125: Windows Push Notifications Apps Elevation of Privilege Vulnerability Windows Push Notifications Apps Elevation of Privilege Vulnerability
nvd
CVE-2022-21867P4HIGHCVSS 7.0v20h2v21h1+4 more2022-01-11
CVE-2022-21867 [HIGH] CVE-2022-21867: Windows Push Notifications Apps Elevation of Privilege Vulnerability Windows Push Notifications Apps Elevation of Privilege Vulnerability
nvd
CVE-2016-3302P4MEDIUMCVSS 6.3v1511v16072016-09-14
CVE-2016-3302 [MEDIUM] CWE-264 CVE-2016-3302: Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607, Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607, when the lock screen is enabled, do not properly restrict the loading of web content, which allows physically proximate attackers to execute arbitrary code via a (1) crafted Wi-Fi access point or (2) crafted mobile-broadband device, aka "Windows Lock Scr
nvd
CVE-2022-21896P4HIGHCVSS 7.0v20h2v21h1+3 more2022-01-11
CVE-2022-21896 [HIGH] CWE-362 CVE-2022-21896: Windows DWM Core Library Elevation of Privilege Vulnerability Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2022-23288P4HIGHCVSS 7.0v20h2v21h1+3 more2022-03-09
CVE-2022-23288 [HIGH] CVE-2022-23288: Windows DWM Core Library Elevation of Privilege Vulnerability Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2022-29106P4HIGHCVSS 7.0v20h22022-05-10
CVE-2022-29106 [HIGH] CVE-2022-29106: Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability
nvd
CVE-2019-1318P4MEDIUMCVSS 5.9v1607v1703+4 more2019-10-10
CVE-2019-1318 [MEDIUM] CWE-290 CVE-2019-1318: A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Se A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions, aka 'Microsoft Windows Transport Layer Security Spoofing Vulnerability'.
nvd
CVE-2022-24525P4HIGHCVSS 7.0v20h2v21h1+2 more2022-03-09
CVE-2022-24525 [HIGH] CWE-362 CVE-2022-24525: Windows Update Stack Elevation of Privilege Vulnerability Windows Update Stack Elevation of Privilege Vulnerability
nvd
CVE-2022-38027P4HIGHCVSS 7.0v20h2v21h1+3 more2022-10-11
CVE-2022-38027 [HIGH] CWE-362 CVE-2022-38027: Windows Storage Elevation of Privilege Vulnerability Windows Storage Elevation of Privilege Vulnerability
nvd
CVE-2022-26828P4HIGHCVSS 7.0v20h2v21h1+3 more2022-04-15
CVE-2022-26828 [HIGH] CWE-362 CVE-2022-26828: Windows Bluetooth Driver Elevation of Privilege Vulnerability Windows Bluetooth Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-6769P4MEDIUMCVSS 6.7v10.0.02024-09-26
CVE-2024-6769 [MEDIUM] CWE-426 CVE-2024-6769: A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Micro A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated attacker to elevate from a medium integrity process to a high integrity process without the intervention of a UAC prompt.
nvd
CVE-2022-26807P4HIGHCVSS 7.0v20h2v21h1+4 more2022-04-15
CVE-2022-26807 [HIGH] CWE-362 CVE-2022-26807: Windows Work Folder Service Elevation of Privilege Vulnerability Windows Work Folder Service Elevation of Privilege Vulnerability
nvd
CVE-2022-44669P4HIGHCVSS 7.0v20h2v21h1+3 more2022-12-13
CVE-2022-44669 [HIGH] CWE-362 CVE-2022-44669: Windows Error Reporting Elevation of Privilege Vulnerability Windows Error Reporting Elevation of Privilege Vulnerability
nvd
CVE-2018-0890P4MEDIUMCVSS 5.3v1607v1703+7 more2018-04-12
CVE-2018-0890 [MEDIUM] CVE-2018-0890: A security feature bypass vulnerability exists when Active Directory incorrectly applies Network Iso A security feature bypass vulnerability exists when Active Directory incorrectly applies Network Isolation settings, aka "Active Directory Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2022-30205P4MEDIUMCVSS 6.6v20h2v21h1+3 more2022-07-12
CVE-2022-30205 [MEDIUM] CWE-362 CVE-2022-30205: Windows Group Policy Elevation of Privilege Vulnerability Windows Group Policy Elevation of Privilege Vulnerability
nvd
Microsoft Windows 10 vulnerabilities | cvebase