Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27
Vulnerabilities
Page 116 of 141
CVE-2020-16914P4MEDIUMCVSS 5.5v1607v1709+5 more2020-10-16
CVE-2020-16914 [MEDIUM] CVE-2020-16914: <p>An information disclosure vulnerability exists in the way that the Windows Graphics Device Interf
An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface Plus (GDI+) handles objects in memory, allowing an attacker to retrieve information from a targeted system. By itself, the information disclosure does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses i
nvd
CVE-2019-1374P4MEDIUMCVSS 5.5v1607v1709+3 more2019-11-12
CVE-2019-1374 [MEDIUM] CWE-200 CVE-2019-1374: An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles obje
An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka 'Windows Error Reporting Information Disclosure Vulnerability'.
nvd
CVE-2020-0937P4MEDIUMCVSS 5.5v1607v1709+4 more2020-04-15
CVE-2020-0937 [MEDIUM] CVE-2020-0937: An information disclosure vulnerability exists when Media Foundation improperly handles objects in m
An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0939, CVE-2020-0945, CVE-2020-0946, CVE-2020-0947.
nvd
CVE-2020-0947P4MEDIUMCVSS 5.5v1903v19092020-04-15
CVE-2020-0947 [MEDIUM] CVE-2020-0947: An information disclosure vulnerability exists when Media Foundation improperly handles objects in m
An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0937, CVE-2020-0939, CVE-2020-0945, CVE-2020-0946.
nvd
CVE-2020-0945P4MEDIUMCVSS 5.5v1607v1709+4 more2020-04-15
CVE-2020-0945 [MEDIUM] CVE-2020-0945: An information disclosure vulnerability exists when Media Foundation improperly handles objects in m
An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0937, CVE-2020-0939, CVE-2020-0946, CVE-2020-0947.
nvd
CVE-2020-0946P4MEDIUMCVSS 5.5v1607v1709+4 more2020-04-15
CVE-2020-0946 [MEDIUM] CVE-2020-0946: An information disclosure vulnerability exists when Media Foundation improperly handles objects in m
An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0937, CVE-2020-0939, CVE-2020-0945, CVE-2020-0947.
nvd
CVE-2020-0607P4MEDIUMCVSS 5.5v1607v1709+4 more2020-01-14
CVE-2020-0607 [MEDIUM] CVE-2020-0607: An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle
An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Information Disclosure Vulnerability'.
nvd
CVE-2017-0042P4LOWCVSS 3.1v1511v16072017-03-17
CVE-2017-0042 [LOW] CWE-200 CVE-2017-0042: Windows Media Player in Microsoft Windows 8.1; Windows Server 2012 R2; Windows RT 8.1; Windows 7 SP1
Windows Media Player in Microsoft Windows 8.1; Windows Server 2012 R2; Windows RT 8.1; Windows 7 SP1; Windows 2008 SP2 and R2 SP1, Windows Server 2016; Windows Vista SP2; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "Windows Media Player Information Disclosure Vulnerability."
nvd
CVE-2020-0746P4MEDIUMCVSS 5.5v1803v1809+2 more2020-02-11
CVE-2020-0746 [MEDIUM] CVE-2020-0746: An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle
An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Information Disclosure Vulnerability'.
nvd
CVE-2017-0057P4MEDIUMCVSS 4.3v1511v16072017-03-17
CVE-2017-0057 [MEDIUM] CWE-200 CVE-2017-0057: DNS client in Microsoft Windows 8.1; Windows Server 2012 R2, Windows RT 8.1; Windows 10 Gold, 1511,
DNS client in Microsoft Windows 8.1; Windows Server 2012 R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 fails to properly process DNS queries, which allows remote attackers to obtain sensitive information via (1) convincing a workstation user to visit an untrusted webpage or (2) tricking a server into sending a DNS query t
nvd
CVE-2019-1096P4MEDIUMCVSS 5.5v1607v1703+4 more2019-07-15
CVE-2019-1096 [MEDIUM] CWE-200 CVE-2019-1096: An information disclosure vulnerability exists when the win32k component improperly provides kernel
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.
nvd
CVE-2023-36909P4MEDIUMCVSS 6.5fixed in 10.0.10240.201072023-08-08
CVE-2023-36909 [MEDIUM] CWE-191 CVE-2023-36909: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2020-1071P4MEDIUMCVSS 6.8v1607v1709+4 more2020-05-21
CVE-2020-1071 [MEDIUM] CWE-755 CVE-2020-1071: An elevation of privilege vulnerability exists when Windows improperly handles errors tied to Remote
An elevation of privilege vulnerability exists when Windows improperly handles errors tied to Remote Access Common Dialog, aka 'Windows Remote Access Common Dialog Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1333P4MEDIUMCVSS 6.7v1607v1709+5 more2020-07-14
CVE-2020-1333 [MEDIUM] CVE-2020-1333: An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improper
An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improperly handle reparse points, aka 'Group Policy Services Policy Processing Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1258P4MEDIUMCVSS 6.7v1709v1803+4 more2020-06-09
CVE-2020-1258 [MEDIUM] CVE-2020-1258: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, ak
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1310P4MEDIUMCVSS 6.7v1607v1709+4 more2020-06-09
CVE-2020-1310 [MEDIUM] CVE-2020-1310: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1251, CVE-2020-1253.
nvd
CVE-2020-1253P4MEDIUMCVSS 6.7v1607v1709+5 more2020-06-09
CVE-2020-1253 [MEDIUM] CVE-2020-1253: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1251, CVE-2020-1310.
nvd
CVE-2021-43224P4MEDIUMCVSS 5.5v20h2v21h1+4 more2021-12-15
CVE-2021-43224 [MEDIUM] CVE-2021-43224: Windows Common Log File System Driver Information Disclosure Vulnerability
Windows Common Log File System Driver Information Disclosure Vulnerability
nvd
CVE-2020-1251P4MEDIUMCVSS 6.7v1607v1709+5 more2020-06-09
CVE-2020-1251 [MEDIUM] CVE-2020-1251: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1253, CVE-2020-1310.
nvd
CVE-2020-0728P4MEDIUMCVSS 5.5v1607v1709+4 more2020-02-11
CVE-2020-0728 [MEDIUM] CVE-2020-0728: An information vulnerability exists when Windows Modules Installer Service improperly discloses file
An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules Installer Service Information Disclosure Vulnerability'.
nvd