Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27
Vulnerabilities
Page 32 of 141
CVE-2019-0597P3HIGHCVSS 7.8v1607v1703+3 more2019-03-05
CVE-2019-0597 [HIGH] CVE-2019-0597: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0595, CVE-2019-0596, CVE-2019-0598, CVE-2019-0599, CVE-2019-0625.
nvd
CVE-2019-0625P3HIGHCVSS 7.8v1607v1703+3 more2019-03-05
CVE-2019-0625 [HIGH] CVE-2019-0625: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0595, CVE-2019-0596, CVE-2019-0597, CVE-2019-0598, CVE-2019-0599.
nvd
CVE-2019-0596P3HIGHCVSS 7.8v1607v1703+3 more2019-03-05
CVE-2019-0596 [HIGH] CVE-2019-0596: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0595, CVE-2019-0597, CVE-2019-0598, CVE-2019-0599, CVE-2019-0625.
nvd
CVE-2019-0583P3HIGHCVSS 7.8v1607v1703+3 more2019-01-08
CVE-2019-0583 [HIGH] CVE-2019-0583: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008
nvd
CVE-2022-37987P3HIGHCVSS 7.8v20h2v21h1+3 more2022-10-11
CVE-2022-37987 [HIGH] CVE-2022-37987: Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
nvd
CVE-2020-1238P3HIGHCVSS 8.8v1709v1803+4 more2020-06-09
CVE-2020-1238 [HIGH] CWE-787 CVE-2020-1238: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1239.
nvd
CVE-2022-37989P3HIGHCVSS 7.8v20h2v21h1+3 more2022-10-11
CVE-2022-37989 [HIGH] CVE-2022-37989: Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
nvd
CVE-2022-23257P3HIGHCVSS 8.8v20h2v21h1+1 more2022-04-15
CVE-2022-23257 [HIGH] CVE-2022-23257: Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2022-41113P3HIGHCVSS 7.8v20h2v21h1+3 more2022-11-09
CVE-2022-41113 [HIGH] CVE-2022-41113: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2023-36697P3HIGHCVSS 8.0fixed in 10.0.10240.202322023-10-10
CVE-2023-36697 [HIGH] CWE-20 CVE-2023-36697: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2022-34714P3HIGHCVSS 8.1v20h2v21h1+3 more2022-08-09
CVE-2022-34714 [HIGH] CWE-94 CVE-2022-34714: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2022-35794P3HIGHCVSS 8.1v20h2v21h1+2 more2022-08-09
CVE-2022-35794 [HIGH] CVE-2022-35794: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2022-44683P3HIGHCVSS 7.8v20h2v21h1+4 more2022-12-13
CVE-2022-44683 [HIGH] CWE-416 CVE-2022-44683: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2017-8727P3HIGHCVSS 7.5v1511v1607+1 more2017-10-13
CVE-2017-8727 [HIGH] CWE-119 CVE-2017-8727: Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server
Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user, due to how Microsoft Windows Text Services Framework handles objects in memory, aka "Windows Shell Memor
nvd
CVE-2017-8476P4MEDIUMCVSS 5.0PoCv1511v1607+1 more2017-06-15
CVE-2017-8476 [MEDIUM] CVE-2017-8476: The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serv
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vu
nvd
CVE-2017-8480P4MEDIUMCVSS 5.0PoCv1511v1607+1 more2017-06-15
CVE-2017-8480 [MEDIUM] CVE-2017-8480: The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serv
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vu
nvd
CVE-2022-30211P3HIGHCVSS 7.5v20h2v21h1+3 more2022-07-12
CVE-2022-30211 [HIGH] CVE-2022-30211: Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
nvd
CVE-2017-0289P4MEDIUMCVSS 5.0PoCv1511v1607+1 more2017-06-15
CVE-2017-0289 [MEDIUM] CVE-2017-0289: Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold
Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows improper disclosure of memory contents, aka "Windows Graphics Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0286, CVE-2017-0287, CVE-2017-028
nvd
CVE-2017-0287P4MEDIUMCVSS 5.0PoCv1511v1607+1 more2017-06-15
CVE-2017-0287 [MEDIUM] CVE-2017-0287: Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold
Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows improper disclosure of memory contents, aka "Graphics Uniscribe Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0286, CVE-2017-0288, CVE-2017-0
nvd
CVE-2017-0285P4MEDIUMCVSS 5.0PoCv1511v1607+1 more2017-06-15
CVE-2017-0285 [MEDIUM] CVE-2017-0285: Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gol
Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016, Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, and Microsoft Office Word Viewer allows improper disclosure of memory contents, aka "Windows Uniscribe Information Disclosure
nvd