cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 18 of 141
CVE-2018-8231P3HIGHCVSS 8.1v1607v1703+12 more2018-06-14
CVE-2018-8231 [HIGH] CVE-2018-8231: A remote code execution vulnerability exists when HTTP Protocol Stack (Http.sys) improperly handles A remote code execution vulnerability exists when HTTP Protocol Stack (Http.sys) improperly handles objects in memory, aka "HTTP Protocol Stack Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2021-31962P3CRITICALCVSS 9.8v20h2v21h1+4 more2021-06-08
CVE-2021-31962 [CRITICAL] CVE-2021-31962: Kerberos AppContainer Security Feature Bypass Vulnerability Kerberos AppContainer Security Feature Bypass Vulnerability
nvd
CVE-2020-1286P3HIGHCVSS 8.8v1803v1809+3 more2020-06-09
CVE-2020-1286 [HIGH] CWE-20 CVE-2020-1286: A remote code execution vulnerability exists when the Windows Shell does not properly validate file A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the current user, aka 'Windows Shell Remote Code Execution Vulnerability'.
nvd
CVE-2019-0719P3CRITICALCVSS 9.1v1607v1709+3 more2019-11-12
CVE-2019-0719 [CRITICAL] CWE-20 CVE-2019-0719: A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fa A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0721.
nvd
CVE-2019-1102P3HIGHCVSS 8.8v1607v1703+4 more2019-07-15
CVE-2019-1102 [HIGH] CVE-2019-1102: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2019-0721P3CRITICALCVSS 9.1v1709v1803+2 more2019-11-12
CVE-2019-0721 [CRITICAL] CVE-2019-0721: A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fa A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0719.
nvd
CVE-2021-28445P3HIGHCVSS 8.8v20h2v1607+4 more2021-04-13
CVE-2021-28445 [HIGH] CVE-2021-28445: Windows Network File System Remote Code Execution Vulnerability Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2021-24088P3HIGHCVSS 8.8v20h2v1607+4 more2021-02-25
CVE-2021-24088 [HIGH] CVE-2021-24088: Windows Local Spooler Remote Code Execution Vulnerability Windows Local Spooler Remote Code Execution Vulnerability
nvd
CVE-2022-23294P3HIGHCVSS 8.8v20h2v21h1+4 more2022-03-09
CVE-2022-23294 [HIGH] CVE-2022-23294: Windows Event Tracing Remote Code Execution Vulnerability Windows Event Tracing Remote Code Execution Vulnerability
nvd
CVE-2021-28455P3HIGHCVSS 8.8v20h2v1607+4 more2021-05-11
CVE-2021-28455 [HIGH] CVE-2021-28455: Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability
nvd
CVE-2022-24487P3HIGHCVSS 8.8v20h2v21h1+4 more2022-04-15
CVE-2022-24487 [HIGH] CVE-2022-24487: Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
nvd
CVE-2021-34508P3HIGHCVSS 8.8v20h2v21h1+3 more2021-07-14
CVE-2021-34508 [HIGH] CVE-2021-34508: Windows Kernel Remote Code Execution Vulnerability Windows Kernel Remote Code Execution Vulnerability
nvd
CVE-2020-1412P3HIGHCVSS 8.8v1607v1709+5 more2020-07-14
CVE-2020-1412 [HIGH] CWE-269 CVE-2020-1412: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
nvd
CVE-2016-0118P3HIGHCVSS 7.8v15112016-03-09
CVE-2016-0118 [HIGH] CWE-20 CVE-2016-0118: The PDF library in Microsoft Windows 10 Gold and 1511 allows remote attackers to execute arbitrary c The PDF library in Microsoft Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted PDF document, aka "Windows Remote Code Execution Vulnerability."
nvd
CVE-2019-0772P3HIGHCVSS 8.8v1607v1703+3 more2019-04-09
CVE-2019-0772 [HIGH] CVE-2019-0772: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0665, CVE-2019-0666, CVE-2019-0667.
nvd
CVE-2023-21695P3HIGHCVSS 8.8fixed in 10.0.10240.197472023-02-14
CVE-2023-21695 [HIGH] CWE-122 CVE-2023-21695: Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
nvd
CVE-2019-1166P3MEDIUMCVSS 5.9v1607v1703+4 more2019-10-10
CVE-2019-1166 [MEDIUM] CWE-354 CVE-2019-1166: A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to s A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection, aka 'Windows NTLM Tampering Vulnerability'.
nvd
CVE-2021-43215P3CRITICALCVSS 9.8v20h2v21h1+4 more2021-12-15
CVE-2021-43215 [CRITICAL] CWE-787 CVE-2021-43215: iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution
nvd
CVE-2016-0019P3HIGHCVSS 8.1v15112016-01-13
CVE-2016-0019 [HIGH] CWE-254 CVE-2016-0019: The Remote Desktop Protocol (RDP) service implementation in Microsoft Windows 10 Gold and 1511 allow The Remote Desktop Protocol (RDP) service implementation in Microsoft Windows 10 Gold and 1511 allows remote attackers to bypass intended access restrictions and establish sessions for blank-password accounts via a modified RDP client, aka "Windows Remote Desktop Protocol Security Bypass Vulnerability."
nvd
CVE-2022-21881P3HIGHCVSS 7.8v20h2v21h1+4 more2022-01-11
CVE-2022-21881 [HIGH] CWE-362 CVE-2022-21881: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
Microsoft Windows 10 vulnerabilities | cvebase