cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 127 of 141
CVE-2020-0675P4MEDIUMCVSS 5.5v1607v1709+4 more2020-02-11
CVE-2020-0675 [MEDIUM] CVE-2020-0675: An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service whe An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to properly handle objects in memory.To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.The security update addresses the vulnerability by correcting how the service handles o
nvd
CVE-2020-0676P4MEDIUMCVSS 5.5v1607v1709+4 more2020-02-11
CVE-2020-0676 [MEDIUM] CVE-2020-0676: An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service whe An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to properly handle objects in memory.To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.The security update addresses the vulnerability by correcting how the service handles o
nvd
CVE-2020-0756P4MEDIUMCVSS 5.5v1607v1709+4 more2020-02-11
CVE-2020-0756 [MEDIUM] CVE-2020-0756: An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service whe An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to properly handle objects in memory.To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.The security update addresses the vulnerability by correcting how the service handles o
nvd
CVE-2020-1160P4MEDIUMCVSS 5.5v1607v1709+5 more2020-06-09
CVE-2020-1160 [MEDIUM] CVE-2020-1160: An information disclosure vulnerability exists when the Microsoft Windows Graphics Component imprope An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'.
nvd
CVE-2020-16940P4MEDIUMCVSS 5.5v1607v1709+5 more2020-10-16
CVE-2020-16940 [MEDIUM] CWE-269 CVE-2020-16940: <p>An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) im An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then
nvd
CVE-2019-1472P4MEDIUMCVSS 5.5v1607v1709+4 more2019-12-10
CVE-2019-1472 [MEDIUM] CWE-200 CVE-2019-1472: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1474.
nvd
CVE-2019-1474P4MEDIUMCVSS 5.5v1607v1709+4 more2019-12-10
CVE-2019-1474 [MEDIUM] CVE-2019-1474: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1472.
nvd
CVE-2017-8719P4MEDIUMCVSS 4.7v1511v1607+1 more2017-09-13
CVE-2017-8719 [MEDIUM] CVE-2017-8719: The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnera
nvd
CVE-2017-8709P4MEDIUMCVSS 4.7v1511v1607+1 more2017-09-13
CVE-2017-8709 [MEDIUM] CVE-2017-8709: The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnera
nvd
CVE-2016-7218P4MEDIUMCVSS 4.7v1511v16072016-11-10
CVE-2016-7218 [MEDIUM] CWE-200 CVE-2016-7218: Bowser.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 Bowser.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to obtain sensitive information via a crafted application, aka "Windows Bowser.sys Information
nvd
CVE-2020-0658P4MEDIUMCVSS 5.5v1607v1709+4 more2020-02-11
CVE-2020-0658 [MEDIUM] CVE-2020-0658: An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver w An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'.
nvd
CVE-2019-1381P4MEDIUMCVSS 5.5v1607v1709+3 more2019-11-12
CVE-2019-1381 [MEDIUM] CWE-200 CVE-2019-1381: An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unp An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unprivileged file locations, aka 'Microsoft Windows Information Disclosure Vulnerability'.
nvd
CVE-2020-0871P4MEDIUMCVSS 5.5v1607v1709+4 more2020-03-12
CVE-2020-0871 [MEDIUM] CVE-2020-0871: An information disclosure vulnerability exists when Windows Network Connections Service fails to pro An information disclosure vulnerability exists when Windows Network Connections Service fails to properly handle objects in memory, aka 'Windows Network Connections Service Information Disclosure Vulnerability'.
nvd
CVE-2020-1075P4MEDIUMCVSS 5.5v1803v1809+2 more2020-05-21
CVE-2020-1075 [MEDIUM] CVE-2020-1075: An information disclosure vulnerability exists when Windows Subsystem for Linux improperly handles o An information disclosure vulnerability exists when Windows Subsystem for Linux improperly handles objects in memory, aka 'Windows Subsystem for Linux Information Disclosure Vulnerability'.
nvd
CVE-2019-1274P4MEDIUMCVSS 5.5v1607v1703+4 more2019-09-11
CVE-2019-1274 [MEDIUM] CWE-665 CVE-2019-1274: An information disclosure vulnerability exists when the Windows kernel fails to properly initialize An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'.
nvd
CVE-2019-1282P4MEDIUMCVSS 5.5v1607v1703+4 more2019-09-11
CVE-2019-1282 [MEDIUM] CVE-2019-1282: An information disclosure exists in the Windows Common Log File System (CLFS) driver when it fails t An information disclosure exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle sandbox checks, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'.
nvd
CVE-2019-1254P4MEDIUMCVSS 5.5v1607v1703+4 more2019-09-11
CVE-2019-1254 [MEDIUM] CWE-908 CVE-2019-1254: An information disclosure vulnerability exists when Windows Hyper-V writes uninitialized memory to d An information disclosure vulnerability exists when Windows Hyper-V writes uninitialized memory to disk, aka 'Windows Hyper-V Information Disclosure Vulnerability'.
nvd
CVE-2020-0775P4MEDIUMCVSS 5.5v1607v1709+4 more2020-03-12
CVE-2020-0775 [MEDIUM] CVE-2020-0775: An information disclosure vulnerability exists when Windows Error Reporting improperly handles file An information disclosure vulnerability exists when Windows Error Reporting improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Error Reporting Information Disclosure Vulnerability'.
nvd
CVE-2020-0859P4MEDIUMCVSS 5.5v1607v1709+4 more2020-03-12
CVE-2020-0859 [MEDIUM] CVE-2020-0859: An information vulnerability exists when Windows Modules Installer Service improperly discloses file An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules Installer Service Information Disclosure Vulnerability'.
nvd
CVE-2020-0643P4MEDIUMCVSS 5.5v1607v1709+4 more2020-01-14
CVE-2020-0643 [MEDIUM] CVE-2020-0643: An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface Plus (GDI+) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI+ Information Disclosure Vulnerability'.
nvd
Microsoft Windows 10 vulnerabilities | cvebase