cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 118 of 141
CVE-2018-8222P4MEDIUMCVSS 5.3v1607v1703+12 more2018-07-11
CVE-2018-8222 [MEDIUM] CVE-2018-8222: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to injec A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8217P4MEDIUMCVSS 5.3v1607v17032018-06-14
CVE-2018-8217 [MEDIUM] CVE-2018-8217: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to injec A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10. This CVE ID is unique from CVE-2018-8201, CVE-2018-8211, CVE-2018-8212, CVE-2018-82
nvd
CVE-2018-8221P4MEDIUMCVSS 5.3v1607v1703+2 more2018-06-14
CVE-2018-8221 [MEDIUM] CVE-2018-8221: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to injec A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8201, CVE-2018-8211, CVE-20
nvd
CVE-2018-8215P4MEDIUMCVSS 5.3v1607v1703+2 more2018-06-14
CVE-2018-8215 [MEDIUM] CVE-2018-8215: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to injec A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8201, CVE-2018-8211, CVE-20
nvd
CVE-2018-8211P4MEDIUMCVSS 5.3v1607v1703+2 more2018-06-14
CVE-2018-8211 [MEDIUM] CVE-2018-8211: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to injec A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID is unique from CVE-2018-8201, CVE-2018-8212, CVE-2018-8215, CVE-2018-821
nvd
CVE-2018-8216P4MEDIUMCVSS 5.3v1607v17032018-06-14
CVE-2018-8216 [MEDIUM] CVE-2018-8216: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to injec A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10. This CVE ID is unique from CVE-2018-8201, CVE-2018-8211, CVE-2018-8212, CVE-2018-82
nvd
CVE-2021-1645P4MEDIUMCVSS 5.5v20h2v1607+3 more2021-01-12
CVE-2021-1645 [MEDIUM] CVE-2021-1645: Windows Docker Information Disclosure Vulnerability Windows Docker Information Disclosure Vulnerability
nvd
CVE-2021-1638P4MEDIUMCVSS 5.5v20h2v1803+3 more2021-01-12
CVE-2021-1638 [MEDIUM] CVE-2021-1638: Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software update that will fail attempts to pair if the remote device exchanges a public key with the same X coordinate
nvd
CVE-2017-0218P4MEDIUMCVSS 5.3v1511v16072017-06-15
CVE-2017-0218 [MEDIUM] CVE-2017-0218: Microsoft Windows 10 Gold, Windows 10 1511, Windows 10 1607, and Windows Server 2016 allow an attack Microsoft Windows 10 Gold, Windows 10 1511, Windows 10 1607, and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerability in Device Guard that could allow the attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This CVE ID is unique
nvd
CVE-2019-1382P4MEDIUMCVSS 5.5v1607v1709+3 more2019-11-12
CVE-2019-1382 [MEDIUM] CVE-2019-1382: An elevation of privilege vulnerability exists when ActiveX Installer service may allow access to fi An elevation of privilege vulnerability exists when ActiveX Installer service may allow access to files without proper authentication, aka 'Microsoft ActiveX Installer Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1383P4MEDIUMCVSS 5.5v1607v1709+5 more2020-08-17
CVE-2020-1383 [MEDIUM] CVE-2020-1383: An information disclosure vulnerability exists in RPC if the server has Routing and Remote Access en An information disclosure vulnerability exists in RPC if the server has Routing and Remote Access enabled. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system To exploit this vulnerability, an attacker would need to run a specially crafted application against an RPC server which has Routin
nvd
CVE-2021-1731P4MEDIUMCVSS 5.5v20h2v1803+3 more2021-02-25
CVE-2021-1731 [MEDIUM] CWE-522 CVE-2021-1731: PFX Encryption Security Feature Bypass Vulnerability PFX Encryption Security Feature Bypass Vulnerability
nvd
CVE-2020-16922P4MEDIUMCVSS 5.5v1607v1709+5 more2020-10-16
CVE-2020-16922 [MEDIUM] CWE-347 CVE-2020-16922: <p>A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker w A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass security features intended to prevent improperly signed files from being loaded. The update addr
nvd
CVE-2021-24075P4MEDIUMCVSS 6.8v20h2v20042021-02-25
CVE-2021-24075 [MEDIUM] CVE-2021-24075: Microsoft Windows VMSwitch Denial of Service Vulnerability Microsoft Windows VMSwitch Denial of Service Vulnerability
nvd
CVE-2021-24080P4MEDIUMCVSS 6.5v20h2v1607+4 more2021-02-25
CVE-2021-24080 [MEDIUM] CVE-2021-24080: Windows Trust Verification API Denial of Service Vulnerability Windows Trust Verification API Denial of Service Vulnerability
nvd
CVE-2019-0690P4MEDIUMCVSS 6.8v1607v1703+3 more2019-04-09
CVE-2019-0690 [MEDIUM] CWE-20 CVE-2019-0690: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0695, CVE-2019-0701.
nvd
CVE-2019-0695P4MEDIUMCVSS 6.8v1607v1703+3 more2019-04-09
CVE-2019-0695 [MEDIUM] CVE-2019-0695: A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly v A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0690, CVE-2019-0701.
nvd
CVE-2019-0701P4MEDIUMCVSS 6.8v1803v18092019-04-09
CVE-2019-0701 [MEDIUM] CVE-2019-0701: A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly v A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0690, CVE-2019-0695.
nvd
CVE-2017-0174P4MEDIUMCVSS 6.5v1511v1607+1 more2017-08-08
CVE-2017-0174 [MEDIUM] CVE-2017-0174: Windows NetBIOS in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 20 Windows NetBIOS in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a denial of service vulnerability when it improperly handles NetBIOS packets, aka "Windows NetBIOS Denial of Service Vulnerability".
nvd
CVE-2019-0635P4MEDIUMCVSS 6.2v1607v1703+3 more2019-03-05
CVE-2019-0635 [MEDIUM] CWE-20 CVE-2019-0635: An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.
nvd
Microsoft Windows 10 vulnerabilities | cvebase