cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 17 of 141
CVE-2020-1248P3HIGHCVSS 8.8v1903v1909+1 more2020-06-09
CVE-2020-1248 [HIGH] CVE-2020-1248: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2019-1060P3HIGHCVSS 8.8v1607v1703+4 more2019-10-10
CVE-2019-1060 [HIGH] CWE-611 CVE-2019-1060: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.
nvd
CVE-2019-0787P3HIGHCVSS 8.8v1607v1703+4 more2019-09-11
CVE-2019-0787 [HIGH] CVE-2019-0787: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0788, CVE-2019-1290, CVE-2019-1291.
nvd
CVE-2019-0756P3HIGHCVSS 8.8v1607v1703+3 more2019-04-09
CVE-2019-0756 [HIGH] CWE-611 CVE-2019-0756: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.
nvd
CVE-2019-1291P3HIGHCVSS 8.8v1607v1703+4 more2019-09-11
CVE-2019-1291 [HIGH] CVE-2019-1291: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0787, CVE-2019-0788, CVE-2019-1290.
nvd
CVE-2019-1290P3HIGHCVSS 8.8v1607v1703+4 more2019-09-11
CVE-2019-1290 [HIGH] CVE-2019-1290: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0787, CVE-2019-0788, CVE-2019-1291.
nvd
CVE-2019-0788P3HIGHCVSS 8.8v1607v1703+4 more2019-09-11
CVE-2019-0788 [HIGH] CVE-2019-0788: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0787, CVE-2019-1290, CVE-2019-1291.
nvd
CVE-2019-0736P3CRITICALCVSS 9.8v1607v1703+2 more2019-08-14
CVE-2019-0736 [CRITICAL] CWE-787 CVE-2019-0736: A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client. An attacker who successfully exploited the vulnerability could run arbitrary code on the client machine. To exploit the vulnerability, an attacker could send specially crafted DHCP responses to a client. The securi
nvd
CVE-2019-1439P3MEDIUMCVSS 6.5v1607v1709+3 more2019-11-12
CVE-2019-1439 [MEDIUM] CWE-200 CVE-2019-1439: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
nvd
CVE-2016-0075P3MEDIUMCVSS 5.5PoCv1511v16072016-10-14
CVE-2016-0075 [MEDIUM] CVE-2016-0075: The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, aka "Windows Kernel Local Elevation of Privilege Vulnerability," a different vulnerability than CVE-201
nvd
CVE-2019-0786P3CRITICALCVSS 9.8v1709v1803+1 more2019-04-09
CVE-2019-0786 [CRITICAL] CWE-20 CVE-2019-0786: An elevation of privilege vulnerability exists in the Microsoft Server Message Block (SMB) Server wh An elevation of privilege vulnerability exists in the Microsoft Server Message Block (SMB) Server when an attacker with valid credentials attempts to open a specially crafted file over the SMB protocol on the same machine, aka 'SMB Server Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1067P3HIGHCVSS 8.8v1607v1709+4 more2020-05-21
CVE-2020-1067 [HIGH] CVE-2020-1067: A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.
nvd
CVE-2019-0662P3HIGHCVSS 8.8v1607v1703+3 more2019-03-05
CVE-2019-0662 [HIGH] CVE-2019-0662: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0618.
nvd
CVE-2016-0091P3HIGHCVSS 7.8v15112016-03-09
CVE-2016-0091 [HIGH] CWE-20 CVE-2016-0091: OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted file, aka "Windows OLE Memory Remote Code Execution Vulnerability," a different vulnerability than CVE-2016-0092.
nvd
CVE-2017-11783P3HIGHCVSS 7.0PoCv1511v1607+1 more2017-10-13
CVE-2017-11783 [HIGH] CVE-2017-11783: Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703 Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability in the way it handles calls to Advanced Local Procedure Call (ALPC), aka "Windows Elevation of Privilege Vulnerability".
nvd
CVE-2022-35841P3HIGHCVSS 8.8v20h2v21h1+3 more2022-09-13
CVE-2022-35841 [HIGH] CVE-2022-35841: Windows Enterprise App Management Service Remote Code Execution Vulnerability Windows Enterprise App Management Service Remote Code Execution Vulnerability
nvd
CVE-2017-0014P3HIGHCVSS 7.5v1511v16072017-03-17
CVE-2017-0014 [HIGH] CVE-2017-0014: The Windows Graphics Component in Microsoft Office 2010 SP2; Windows Server 2008 R2 SP1; Windows 7 S The Windows Graphics Component in Microsoft Office 2010 SP2; Windows Server 2008 R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Component Remote Code Execution Vulnerabilit
nvd
CVE-2022-29137P3HIGHCVSS 8.8v20h2v21h1+4 more2022-05-10
CVE-2022-29137 [HIGH] CVE-2022-29137: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-22014P3HIGHCVSS 8.8v20h2v21h1+4 more2022-05-10
CVE-2022-22014 [HIGH] CVE-2022-22014: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-22013P3HIGHCVSS 8.8v20h2v21h1+4 more2022-05-10
CVE-2022-22013 [HIGH] CVE-2022-22013: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
Microsoft Windows 10 vulnerabilities | cvebase