cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 14 of 141
CVE-2020-16898P2HIGHCVSS 8.8v1709v1803+4 more2020-10-16
CVE-2020-16898 [HIGH] CVE-2020-16898: <p>A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICM A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could gain the ability to execute code on the target server or client. To exploit this vulnerability, an attacker would have to send specially crafted ICMPv6 Router Adverti
nvd
CVE-2018-8208P3HIGHCVSS 7.0PoCv1607v1703+10 more2018-06-14
CVE-2018-8208 [HIGH] CVE-2018-8208: An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly mana An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8214.
nvd
CVE-2018-0826P3HIGHCVSS 7.0PoCv1511v1607+2 more2018-02-15
CVE-2018-0826 [HIGH] CVE-2018-0826: Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and W Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Storage Services Elevation of Privilege Vulnerability".
nvd
CVE-2018-8134P3HIGHCVSS 7.0PoCv1607v1703+12 more2018-05-09
CVE-2018-8134 [HIGH] CVE-2018-8134: An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permi An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
nvd
CVE-2019-0959P3HIGHCVSS 7.0PoCv1803v1809+1 more2019-06-12
CVE-2019-0959 [HIGH] CVE-2019-0959: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted appli
nvd
CVE-2018-0751P3HIGHCVSS 7.1PoCv1511v1607+2 more2018-01-04
CVE-2018-0751 [HIGH] CWE-269 CVE-2018-0751: The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way the Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability". This CVE ID is unique from CV
nvd
CVE-2018-0982P3HIGHCVSS 7.0PoCv1607v1703+10 more2018-06-14
CVE-2018-0982 [HIGH] CWE-732 CVE-2018-0982: An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permi An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8225P3HIGHCVSS 8.1v1607v1703+12 more2018-06-14
CVE-2018-8225 [HIGH] CVE-2018-8225: A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, aka "Windows DNSAPI Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Wi
nvd
CVE-2018-1004P3HIGHCVSS 8.8v1511v1607+12 more2018-04-12
CVE-2018-1004 [HIGH] CWE-787 CVE-2018-1004: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Internet Explorer 9, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10.
nvd
CVE-2021-38666P2HIGHCVSS 8.8v20h2v21h1+4 more2021-11-10
CVE-2021-38666 [HIGH] CVE-2021-38666: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2018-8350P3HIGHCVSS 8.8v1703v1709+7 more2018-08-15
CVE-2018-8350 [HIGH] CVE-2018-8350: A remote code execution vulnerability exists when Microsoft Windows PDF Library improperly handles o A remote code execution vulnerability exists when Microsoft Windows PDF Library improperly handles objects in memory, aka "Windows PDF Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.
nvd
CVE-2021-33757P2CRITICALCVSS 9.8v20h2v21h1+4 more2021-07-14
CVE-2021-33757 [CRITICAL] CVE-2021-33757: Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnerability Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnerability
nvd
CVE-2019-0793P3HIGHCVSS 8.8v1607v1703+3 more2019-04-09
CVE-2019-0793 [HIGH] CVE-2019-0793: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0790, CVE-2019-0791, CVE-2019-0792, CVE-2019-0795.
nvd
CVE-2019-0792P3HIGHCVSS 8.8v1607v1703+3 more2019-04-09
CVE-2019-0792 [HIGH] CVE-2019-0792: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0790, CVE-2019-0791, CVE-2019-0793, CVE-2019-0795.
nvd
CVE-2019-0791P3HIGHCVSS 8.8v1607v1703+3 more2019-04-09
CVE-2019-0791 [HIGH] CVE-2019-0791: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0790, CVE-2019-0792, CVE-2019-0793, CVE-2019-0795.
nvd
CVE-2021-24077P2CRITICALCVSS 9.8v20h2v1607+4 more2021-02-25
CVE-2021-24077 [CRITICAL] CVE-2021-24077: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2017-11763P3HIGHCVSS 8.8v1511v1607+1 more2017-10-13
CVE-2017-11763 [HIGH] CWE-20 CVE-2017-11763: The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability in the way it handles specially crafted embedded fonts, aka "Microsoft Graphics Remote
nvd
CVE-2017-11762P3HIGHCVSS 8.8v1511v1607+1 more2017-10-13
CVE-2017-11762 [HIGH] CWE-20 CVE-2017-11762: The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability in the way it handles specially crafted embedded fonts, aka "Microsoft Graphics Remote
nvd
CVE-2022-30133P2CRITICALCVSS 9.8v20h2v21h1+2 more2022-08-09
CVE-2022-30133 [CRITICAL] CVE-2022-30133: Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
nvd
CVE-2021-1722P2CRITICALCVSS 9.8v20h2v1607+4 more2021-02-25
CVE-2021-1722 [CRITICAL] CVE-2021-1722: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
Microsoft Windows 10 vulnerabilities | cvebase