cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 138 of 141
CVE-2018-0843P4MEDIUMCVSS 4.7v17092018-02-15
CVE-2018-0843 [MEDIUM] CVE-2018-0843: The Windows kernel in Windows 10 version 1709 and Windows Server, version 1709 allows an information The Windows kernel in Windows 10 version 1709 and Windows Server, version 1709 allows an information disclosure vulnerability due to how objects in memory are handled, aka "Windows Kernel Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0742, CVE-2018-0756, CVE-2018-0809 and CVE-2018-0820.
nvd
CVE-2019-0601P4MEDIUMCVSS 4.7v1607v1703+3 more2019-03-05
CVE-2019-0601 [MEDIUM] CVE-2019-0601: An information disclosure vulnerability exists when the Human Interface Devices (HID) component impr An information disclosure vulnerability exists when the Human Interface Devices (HID) component improperly handles objects in memory, aka 'HID Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0600.
nvd
CVE-2019-1368P4MEDIUMCVSS 4.6v1803v1809+1 more2019-10-10
CVE-2019-1368 [MEDIUM] CVE-2019-1368: A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging f A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging functionality, aka 'Windows Secure Boot Security Feature Bypass Vulnerability'.
nvd
CVE-2022-21900P4MEDIUMCVSS 4.6v20h2v21h1+4 more2022-01-11
CVE-2022-21900 [MEDIUM] CVE-2022-21900: Windows Hyper-V Security Feature Bypass Vulnerability Windows Hyper-V Security Feature Bypass Vulnerability
nvd
CVE-2022-21921P4MEDIUMCVSS 4.4v20h2v21h1+1 more2022-01-11
CVE-2022-21921 [MEDIUM] CVE-2022-21921: Windows Defender Credential Guard Security Feature Bypass Vulnerability Windows Defender Credential Guard Security Feature Bypass Vulnerability
nvd
CVE-2022-29121P4MEDIUMCVSS 6.5v20h2v21h1+4 more2022-05-10
CVE-2022-29121 [MEDIUM] CVE-2022-29121: Windows WLAN AutoConfig Service Denial of Service Vulnerability Windows WLAN AutoConfig Service Denial of Service Vulnerability
nvd
CVE-2016-3354P4LOWCVSS 3.3v1511v16072016-09-14
CVE-2016-3354 [LOW] CWE-254 CVE-2016-3354: The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 S The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "GDI Information Disclosure Vulnerability."
nvd
CVE-2020-0616P4MEDIUMCVSS 5.5v1809v1903+1 more2020-01-14
CVE-2020-0616 [MEDIUM] CWE-59 CVE-2020-0616: A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.
nvd
CVE-2019-0754P4MEDIUMCVSS 5.5v1607v1703+3 more2019-04-09
CVE-2019-0754 [MEDIUM] CVE-2019-0754: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.
nvd
CVE-2018-8612P4MEDIUMCVSS 5.5v1607v1703+16 more2018-12-12
CVE-2018-8612 [MEDIUM] CWE-20 CVE-2018-8612: A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values, aka "Connected User Experiences and Telemetry Service Denial of Service Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers.
nvd
CVE-2019-1391P4MEDIUMCVSS 5.5v1607v1709+3 more2019-11-12
CVE-2019-1391 [MEDIUM] CVE-2019-1391: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2018-12207.
nvd
CVE-2020-17071P4MEDIUMCVSS 5.5v20h2v1607+5 more2020-11-11
CVE-2020-17071 [MEDIUM] CVE-2020-17071: Windows Delivery Optimization Information Disclosure Vulnerability Windows Delivery Optimization Information Disclosure Vulnerability
nvd
CVE-2020-1084P4MEDIUMCVSS 5.5v1607v1709+4 more2020-05-21
CVE-2020-1084 [MEDIUM] CWE-20 CVE-2020-1084: A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values.An attacker who successfully exploited this vulnerability could deny dependent security feature functionality.To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially c
nvd
CVE-2020-1123P4MEDIUMCVSS 5.5v1607v1709+4 more2020-05-21
CVE-2020-1123 [MEDIUM] CVE-2020-1123: A denial of service vulnerability exists when Connected User Experiences and Telemetry Service impro A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-1084.
nvd
CVE-2019-0600P4MEDIUMCVSS 4.7v1607v1703+3 more2019-03-05
CVE-2019-0600 [MEDIUM] CVE-2019-0600: An information disclosure vulnerability exists when the Human Interface Devices (HID) component impr An information disclosure vulnerability exists when the Human Interface Devices (HID) component improperly handles objects in memory, aka 'HID Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0601.
nvd
CVE-2018-8121P4MEDIUMCVSS 4.7v1703v1709+11 more2018-06-14
CVE-2018-8121 [MEDIUM] CWE-665 CVE-2018-8121: An information disclosure vulnerability exists when the Windows kernel improperly initializes object An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID is unique from CVE-2018-8207.
nvd
CVE-2016-3258P4MEDIUMCVSS 4.7v15112016-07-13
CVE-2016-3258 [MEDIUM] CWE-264 CVE-2016-3258: Race condition in the kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8 Race condition in the kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Low Integrity protection mechanism and write to files by leveraging unspecified object-manager features, aka "Windows File System Security Feature Bypass."
nvd
CVE-2021-28316P4MEDIUMCVSS 4.6v20h2v1607+4 more2021-04-13
CVE-2021-28316 [MEDIUM] CVE-2021-28316: Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability
nvd
CVE-2016-3287P4MEDIUMCVSS 4.4v15112016-07-13
CVE-2016-3287 [MEDIUM] CWE-254 CVE-2016-3287: Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Secure Boot protection mechanism by leveraging administrative access to install a crafted policy, aka "Secure Boot Security Feature Bypass."
nvd
CVE-2022-24466P4MEDIUMCVSS 4.1v20h2v21h1+4 more2022-05-10
CVE-2022-24466 [MEDIUM] CVE-2022-24466: Windows Hyper-V Security Feature Bypass Vulnerability Windows Hyper-V Security Feature Bypass Vulnerability
nvd
Microsoft Windows 10 vulnerabilities | cvebase