Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27
Vulnerabilities
Page 20 of 141
CVE-2021-27092P3CRITICALCVSS 9.8v20h2v1803+3 more2021-04-13
CVE-2021-27092 [CRITICAL] CVE-2021-27092: Azure AD Web Sign-in Security Feature Bypass Vulnerability
Azure AD Web Sign-in Security Feature Bypass Vulnerability
nvd
CVE-2019-0888P3HIGHCVSS 8.8v1607v1703+4 more2019-06-12
CVE-2019-0888 [HIGH] CVE-2019-0888: A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objec
A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with the victim user’s privileges.
An attacker could craft a website that exploits the vulnerability and then convince a victim user to visit the website.
The secu
nvd
CVE-2020-17042P3HIGHCVSS 8.8v20h2v1607+5 more2020-11-11
CVE-2020-17042 [HIGH] CVE-2020-17042: Windows Print Spooler Remote Code Execution Vulnerability
Windows Print Spooler Remote Code Execution Vulnerability
nvd
CVE-2020-1061P3HIGHCVSS 8.8v1607v1709+4 more2020-05-21
CVE-2020-1061 [HIGH] CWE-787 CVE-2020-1061: A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles ob
A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles objects in memory, aka 'Microsoft Script Runtime Remote Code Execution Vulnerability'.
nvd
CVE-2020-16911P3HIGHCVSS 8.8v1607v1709+5 more2020-10-16
CVE-2020-16911 [HIGH] CVE-2020-16911: <p>A remote code execution vulnerability exists in the way that the Windows Graphics Device Interfac
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users w
nvd
CVE-2016-0038P3HIGHCVSS 7.8v15112016-02-10
CVE-2016-0038 [HIGH] CWE-119 CVE-2016-0038: Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, W
Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journal Memory Corruption Vulnerability."
nvd
CVE-2017-0161P3HIGHCVSS 8.1v1511v1607+1 more2017-09-13
CVE-2017-0161 [HIGH] CWE-362 CVE-2017-0161: The Windows NetBT Session Services component on Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1,
The Windows NetBT Session Services component on Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to maintain certain sequencing requirements, aka "NetBIOS Remote Code
nvd
CVE-2015-6100P3MEDIUMCVSS 6.9PoCv15112015-11-11
CVE-2015-6100 [MEDIUM] CWE-264 CVE-2015-6100: The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability," a different vulne
nvd
CVE-2017-0250P3HIGHCVSS 7.8v1511v1607+1 more2017-08-08
CVE-2017-0250 [HIGH] CWE-119 CVE-2017-0250: Microsoft JET Database Engine in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Win
Microsoft JET Database Engine in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to buffer overflow, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability".
nvd
CVE-2021-1674P3HIGHCVSS 8.8v20h2v1607+4 more2021-01-12
CVE-2021-1674 [HIGH] CVE-2021-1674: Windows Remote Desktop Protocol Core Security Feature Bypass Vulnerability
Windows Remote Desktop Protocol Core Security Feature Bypass Vulnerability
nvd
CVE-2021-1669P3HIGHCVSS 8.8v20h2v1607+4 more2021-01-12
CVE-2021-1669 [HIGH] CVE-2021-1669: Windows Remote Desktop Security Feature Bypass Vulnerability
Windows Remote Desktop Security Feature Bypass Vulnerability
nvd
CVE-2022-21922P3HIGHCVSS 8.8v20h2v21h1+4 more2022-01-11
CVE-2022-21922 [HIGH] CVE-2022-21922: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2020-0684P3HIGHCVSS 8.8v1607v1709+4 more2020-03-12
CVE-2020-0684 [HIGH] CVE-2020-0684: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
nvd
CVE-2021-28327P3HIGHCVSS 8.8v20h2v1607+4 more2021-04-13
CVE-2021-28327 [HIGH] CVE-2021-28327: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28340P3HIGHCVSS 8.8v20h2v1607+4 more2021-04-13
CVE-2021-28340 [HIGH] CVE-2021-28340: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28356P3HIGHCVSS 8.8v20h2v1607+4 more2021-04-13
CVE-2021-28356 [HIGH] CVE-2021-28356: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28344P3HIGHCVSS 8.8v20h2v1607+4 more2021-04-13
CVE-2021-28344 [HIGH] CVE-2021-28344: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28333P3HIGHCVSS 8.8v20h2v1607+4 more2021-04-13
CVE-2021-28333 [HIGH] CVE-2021-28333: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28355P3HIGHCVSS 8.8v20h2v1607+4 more2021-04-13
CVE-2021-28355 [HIGH] CVE-2021-28355: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28434P3HIGHCVSS 8.8v20h2v1607+4 more2021-04-13
CVE-2021-28434 [HIGH] CVE-2021-28434: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd