Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27
Vulnerabilities
Page 12 of 141
CVE-2016-0195P2HIGHCVSS 8.8v15112016-05-11
CVE-2016-0195 [HIGH] CWE-119 CVE-2016-0195: The Imaging Component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7
The Imaging Component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted document, aka "Windows Imaging Component Memory Corruption Vulnerability."
nvd
CVE-2018-1016P2HIGHCVSS 8.8v1511v1607+2 more2018-04-12
CVE-2018-1016 [HIGH] CVE-2018-1016: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 1
nvd
CVE-2018-1012P2HIGHCVSS 8.8v1511v1607+2 more2018-04-12
CVE-2018-1012 [HIGH] CVE-2018-1012: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 1
nvd
CVE-2018-1013P2HIGHCVSS 8.8v1511v1607+2 more2018-04-12
CVE-2018-1013 [HIGH] CVE-2018-1013: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 1
nvd
CVE-2018-1015P2HIGHCVSS 8.8v1511v1607+2 more2018-04-12
CVE-2018-1015 [HIGH] CVE-2018-1015: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 1
nvd
CVE-2023-36910P2CRITICALCVSS 9.8fixed in 10.0.10240.201072023-08-08
CVE-2023-36910 [CRITICAL] CWE-190 CVE-2023-36910: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2016-0178P2HIGHCVSS 8.8v15112016-05-11
CVE-2016-0178 [HIGH] CWE-264 CVE-2016-0178: The RPC NDR Engine in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1
The RPC NDR Engine in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandles free operations, which allows remote attackers to execute arbitrary code via malformed RPC requests, aka "RPC Network Data Representation Engine Elevat
nvd
CVE-2018-8256P3HIGHCVSS 8.8v1607v1703+18 more2018-11-14
CVE-2018-8256 [HIGH] CVE-2018-8256: A remote code execution vulnerability exists when PowerShell improperly handles specially crafted fi
A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka "Microsoft PowerShell Remote Code Execution Vulnerability." This affects Windows RT 8.1, PowerShell Core 6.0, Microsoft.PowerShell.Archive 1.2.2.0, Windows Server 2016, Windows Server 2012, Windows Server 2008 R2, Windows Server 2019, Windows 7, Windows
nvd
CVE-2018-8450P2HIGHCVSS 8.8v1607v1703+10 more2018-11-14
CVE-2018-8450 [HIGH] CWE-404 CVE-2018-8450: A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Win
A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8344P3HIGHCVSS 8.8v1607v1703+12 more2018-08-15
CVE-2018-8344 [HIGH] CWE-94 CVE-2018-8344: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Wi
nvd
CVE-2016-7205P3HIGHCVSS 8.8v1511v16072016-11-10
CVE-2016-7205 [HIGH] CWE-119 CVE-2016-7205: Animation Manager in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serve
Animation Manager in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Animation Manager Memory Corruption Vulnerability."
nvd
CVE-2020-1074P3HIGHCVSS 7.8v1607v1709+5 more2020-09-11
CVE-2020-1074 [HIGH] CVE-2020-1074: <p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly hand
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd
CVE-2016-0101P2HIGHCVSS 8.8v15112016-03-09
CVE-2016-0101 [HIGH] CWE-20 CVE-2016-0101: Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, W
Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow remote attackers to execute arbitrary code via crafted media content, aka "Windows Media Parsing Remote Code Execution Vulnerability."
nvd
CVE-2021-36947P2HIGHCVSS 8.8v20h2v21h1+4 more2021-08-12
CVE-2021-36947 [HIGH] CVE-2021-36947: Windows Print Spooler Remote Code Execution Vulnerability
Windows Print Spooler Remote Code Execution Vulnerability
nvd
CVE-2018-8349P3HIGHCVSS 8.8v1607v1703+12 more2018-08-15
CVE-2018-8349 [HIGH] CWE-502 CVE-2018-8349: A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properl
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 20
nvd
CVE-2019-1468P3HIGHCVSS 8.8v1607v1709+4 more2019-12-10
CVE-2019-1468 [HIGH] CWE-787 CVE-2019-1468: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code Execution Vulnerability'.
nvd
CVE-2018-8494P3HIGHCVSS 8.8v1607v1703+15 more2018-10-10
CVE-2018-8494 [HIGH] CWE-611 CVE-2018-8494: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Win
nvd
CVE-2023-36911P2CRITICALCVSS 9.8fixed in 10.0.10240.201072023-08-08
CVE-2023-36911 [CRITICAL] CWE-190 CVE-2023-36911: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2020-0883P2HIGHCVSS 8.8v1607v1709+4 more2020-03-12
CVE-2020-0883 [HIGH] CVE-2020-0883: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0881.
nvd
CVE-2017-0214P3HIGHCVSS 7.0PoCv1511v1607+1 more2017-05-12
CVE-2017-0214 [HIGH] CVE-2017-0214: Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when Windows fails to properly validate input before loading type libraries, aka "Windows COM Elevation of Privilege V
nvd