cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 13 of 141
CVE-2019-0795P3HIGHCVSS 8.8v1607v1703+3 more2019-04-09
CVE-2019-0795 [HIGH] CVE-2019-0795: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0790, CVE-2019-0791, CVE-2019-0792, CVE-2019-0793.
nvd
CVE-2019-1333P2HIGHCVSS 8.8v1607v1703+4 more2019-10-10
CVE-2019-1333 [HIGH] CVE-2019-1333: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.
nvd
CVE-2022-44666P3HIGHCVSS 7.8v20h2v21h1+4 more2022-12-13
CVE-2022-44666 [HIGH] CVE-2022-44666: Windows Contacts Remote Code Execution Vulnerability Windows Contacts Remote Code Execution Vulnerability
nvd
CVE-2019-0902P3HIGHCVSS 8.8v1607v1703+4 more2019-05-16
CVE-2019-0902 [HIGH] CVE-2019-0902: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0889, CVE-2019-0890, CVE-2019-0891, CVE-2019-0893, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0899, CVE
nvd
CVE-2018-8332P3HIGHCVSS 8.8v1607v1703+12 more2018-09-13
CVE-2018-8332 [HIGH] CVE-2018-8332: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability." This affects Windows 7, Microsoft Office, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, Windows Server 2016, Windows
nvd
CVE-2017-8527P3HIGHCVSS 8.8v1511v1607+1 more2017-06-15
CVE-2017-8527 [HIGH] CWE-119 CVE-2017-8527: Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way it handles objects in memory, aka "Windows Graphics Remote Code Execution Vulnerability".
nvd
CVE-2016-7273P3HIGHCVSS 8.8v1511v16072016-12-20
CVE-2016-7273 [HIGH] CWE-19 CVE-2016-7273: The Graphics component in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows r The Graphics component in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Remote Code Execution Vulnerability."
nvd
CVE-2020-0687P2HIGHCVSS 8.8v1607v1709+4 more2020-04-15
CVE-2020-0687 [HIGH] CVE-2020-0687: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'.
nvd
CVE-2016-0184P3HIGHCVSS 8.8v15112016-05-11
CVE-2016-0184 [HIGH] CVE-2016-0184: Use-after-free vulnerability in GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 S Use-after-free vulnerability in GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted document, aka "Direct3D Use After Free Vulnerability."
nvd
CVE-2017-0062P3MEDIUMCVSS 4.7PoCv1511v16072017-03-17
CVE-2017-0062 [MEDIUM] CVE-2017-0062: The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 S The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI+ Information Disclosure Vulnerabili
nvd
CVE-2022-37954P3HIGHCVSS 7.8v20h2v21h1+2 more2022-09-13
CVE-2022-37954 [HIGH] CVE-2022-37954: DirectX Graphics Kernel Elevation of Privilege Vulnerability DirectX Graphics Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-21752P3HIGHCVSS 7.1PoCv20h2v21h2+3 more2023-01-10
CVE-2023-21752 [HIGH] CWE-284 CVE-2023-21752: Windows Backup Service Elevation of Privilege Vulnerability Windows Backup Service Elevation of Privilege Vulnerability
nvd
CVE-2022-21984P2HIGHCVSS 8.8v20h2v21h1+2 more2022-02-09
CVE-2022-21984 [HIGH] CVE-2022-21984: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2022-34722P2CRITICALCVSS 9.8v20h2v21h1+3 more2022-09-13
CVE-2022-34722 [CRITICAL] CVE-2022-34722: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2019-0722P2HIGHCVSS 8.8v1607v1703+4 more2019-06-12
CVE-2019-0722 [HIGH] CWE-20 CVE-2019-0722: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary
nvd
CVE-2020-0964P2HIGHCVSS 8.8v1607v1709+4 more2020-04-15
CVE-2020-0964 [HIGH] CVE-2020-0964: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2023-21803P2CRITICALCVSS 9.8fixed in 10.0.10240.197472023-02-14
CVE-2023-21803 [CRITICAL] CWE-190 CVE-2023-21803: Windows iSCSI Discovery Service Remote Code Execution Vulnerability Windows iSCSI Discovery Service Remote Code Execution Vulnerability
nvd
CVE-2023-36606P3HIGHCVSS 7.5fixed in 10.0.10240.202322023-10-10
CVE-2023-36606 [HIGH] CWE-400 CVE-2023-36606: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2020-0734P2HIGHCVSS 8.8v1607v1709+4 more2020-02-11
CVE-2020-0734 [HIGH] CVE-2020-0734: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0681.
nvd
CVE-2018-8214P3HIGHCVSS 7.0PoCv1607v1703+2 more2018-06-14
CVE-2018-8214 [HIGH] CVE-2018-8214: An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly mana An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8208.
nvd
Microsoft Windows 10 vulnerabilities | cvebase