cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 26 of 141
CVE-2017-8477P4MEDIUMCVSS 5.0PoCv1511v1607+1 more2017-06-15
CVE-2017-8477 [MEDIUM] CVE-2017-8477: Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an authenticated attacker to run a specially crafted application when the Windows kernel improperly initializes objects in memory, aka "Win32k Information Disclosure Vulne
nvd
CVE-2017-8483P4MEDIUMCVSS 5.0PoCv1511v1607+1 more2017-06-15
CVE-2017-8483 [MEDIUM] CVE-2017-8483: The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serv The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vu
nvd
CVE-2022-30141P3HIGHCVSS 8.1v20h2v21h1+3 more2022-06-15
CVE-2022-30141 [HIGH] CVE-2022-30141: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2016-0079P4MEDIUMCVSS 5.0PoCv1511v16072016-10-14
CVE-2016-0079 [MEDIUM] CWE-200 CVE-2016-0079: The kernel in Microsoft Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a The kernel in Microsoft Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, aka "Windows Kernel Local Elevation of Privilege Vulnerability."
nvd
CVE-2017-0300P4MEDIUMCVSS 5.0PoCv1511v1607+1 more2017-06-15
CVE-2017-0300 [MEDIUM] CVE-2017-0300: The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serv The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vu
nvd
CVE-2017-8490P4MEDIUMCVSS 5.0PoCv1511v1607+1 more2017-06-15
CVE-2017-8490 [MEDIUM] CVE-2017-8490: The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serv The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vu
nvd
CVE-2019-0538P3HIGHCVSS 7.8v1607v1703+18 more2019-01-08
CVE-2019-0538 [HIGH] CVE-2019-0538: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008
nvd
CVE-2019-0889P3HIGHCVSS 7.8v1607v1703+4 more2019-05-16
CVE-2019-0889 [HIGH] CVE-2019-0889: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0890, CVE-2019-0891, CVE-2019-0893, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0899, CVE-2019-0900, CVE
nvd
CVE-2019-0899P3HIGHCVSS 7.8v1607v1703+4 more2019-05-16
CVE-2019-0899 [HIGH] CVE-2019-0899: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0889, CVE-2019-0890, CVE-2019-0891, CVE-2019-0893, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0900, CVE
nvd
CVE-2019-0891P3HIGHCVSS 7.8v1607v1703+4 more2019-05-16
CVE-2019-0891 [HIGH] CVE-2019-0891: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0889, CVE-2019-0890, CVE-2019-0893, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0899, CVE-2019-0900, CVE
nvd
CVE-2020-1408P3HIGHCVSS 8.8v1607v1709+5 more2020-07-14
CVE-2020-1408 [HIGH] CWE-346 CVE-2020-1408: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'.
nvd
CVE-2018-0883P3HIGHCVSS 7.5v1511v1607+1 more2018-03-14
CVE-2018-0883 [HIGH] CVE-2018-0883: Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1 Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016 and Windows Server, version 1709 allows a remote code execution vulnerability due to how file copy destinations are validated, aka "Windows Shell Remote Code Execution Vulnerabil
nvd
CVE-2017-0293P3HIGHCVSS 7.5v1511v1607+1 more2017-08-08
CVE-2017-0293 [HIGH] CWE-119 CVE-2017-0293: Microsoft Windows PDF Library in Windows Server 2008 R2 SP1, Windows 8.1, Windows Server 2012 Gold a Microsoft Windows PDF Library in Windows Server 2008 R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability when it improperly handles objects in memory, aka "Windows PDF Remote Code Execution Vulnerability".
nvd
CVE-2022-37957P3HIGHCVSS 7.8v20h2v21h1+3 more2022-09-13
CVE-2022-37957 [HIGH] CVE-2022-37957: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2020-1585P3HIGHCVSS 8.8v1709v1803+4 more2020-08-17
CVE-2020-1585 [HIGH] CVE-2020-1585: A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handle A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Exploitation of the vuln
nvd
CVE-2022-22025P3HIGHCVSS 7.5v20h2v21h1+3 more2022-07-12
CVE-2022-22025 [HIGH] CVE-2022-22025: Windows Internet Information Services Cachuri Module Denial of Service Vulnerability Windows Internet Information Services Cachuri Module Denial of Service Vulnerability
nvd
CVE-2022-21893P3HIGHCVSS 8.0v20h2v21h1+4 more2022-01-11
CVE-2022-21893 [HIGH] CVE-2022-21893: Remote Desktop Protocol Remote Code Execution Vulnerability Remote Desktop Protocol Remote Code Execution Vulnerability
nvd
CVE-2018-8553P3HIGHCVSS 7.8v1607v32-bit Systems+3 more2018-11-14
CVE-2018-8553 [HIGH] CVE-2018-8553: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 1
nvd
CVE-2019-1280P3HIGHCVSS 7.8v1607v1703+4 more2019-09-11
CVE-2019-1280 [HIGH] CWE-59 CVE-2019-1280: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
nvd
CVE-2017-11769P3HIGHCVSS 7.8v1511v1607+1 more2017-10-13
CVE-2017-11769 [HIGH] CVE-2017-11769: The Microsoft Windows TRIE component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows The Microsoft Windows TRIE component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability in the way it handles loading dll files, aka "TRIE Remote Code Execution Vulnerability".
nvd
Microsoft Windows 10 vulnerabilities | cvebase