cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 33 of 141
CVE-2017-0288P4MEDIUMCVSS 5.0PoCv1511v1607+1 more2017-06-15
CVE-2017-0288 [MEDIUM] CVE-2017-0288: Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows improper disclosure of memory contents, aka "Windows Graphics Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0286, CVE-2017-0287, CVE-2017-028
nvd
CVE-2017-0284P4MEDIUMCVSS 5.0PoCv1511v16072017-06-15
CVE-2017-0284 [MEDIUM] CVE-2017-0284: Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gol Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016, Microsoft Office 2007 SP3, and Microsoft Office 2010 SP2 allows improper disclosure of memory contents, aka "Windows Uniscribe Information Disclosure Vulnerability". This CVE ID i
nvd
CVE-2017-0282P4MEDIUMCVSS 5.0PoCv1511v1607+1 more2017-06-15
CVE-2017-0282 [MEDIUM] CWE-200 CVE-2017-0282: Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gol Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016, Microsoft Office 2007 SP3, and Microsoft Office 2010 SP2 allows improper disclosure of memory contents, aka "Windows Uniscribe Information Disclosure Vulnerability". This
nvd
CVE-2017-8708P4MEDIUMCVSS 4.7PoCv1511v1607+1 more2017-09-13
CVE-2017-8708 [MEDIUM] CVE-2017-8708: The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnera
nvd
CVE-2020-17047P3HIGHCVSS 7.5v20h2v1607+6 more2020-11-11
CVE-2020-17047 [HIGH] CVE-2020-17047: Windows Network File System Denial of Service Vulnerability Windows Network File System Denial of Service Vulnerability
nvd
CVE-2017-0158P3HIGHCVSS 7.5v1511v1607+1 more2017-04-12
CVE-2017-0158 [HIGH] CVE-2017-0158: An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1 Windows RT 8.1, and Windows Server 2012 R2 fails to properly sanitize handles in memory, aka "Scripting Engine Memory Corruption Vulnerability."
nvd
CVE-2020-1409P3HIGHCVSS 7.8v1607v1709+5 more2020-07-14
CVE-2020-1409 [HIGH] CVE-2020-1409: A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'.
nvd
CVE-2020-0665P3HIGHCVSS 8.1v1607v1709+4 more2020-02-11
CVE-2020-0665 [HIGH] CVE-2020-0665: An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default se An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privilege Vulnerability'.
nvd
CVE-2019-0734P3HIGHCVSS 8.1v1607v1703+4 more2019-05-16
CVE-2019-0734 [HIGH] CVE-2019-0734: An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacke An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully decode and replace authentication request using Kerberos, allowing an attacker to be validated as an Administrator.The update addresses this vulnerability by changing how these requests are validated., aka 'Windows Elevation of Privilege
nvd
CVE-2021-31971P3HIGHCVSS 8.8v20h2v21h1+4 more2021-06-08
CVE-2021-31971 [HIGH] CVE-2021-31971: Windows HTML Platforms Security Feature Bypass Vulnerability Windows HTML Platforms Security Feature Bypass Vulnerability
nvd
CVE-2020-1031P3HIGHCVSS 7.5v1607v1709+5 more2020-09-11
CVE-2020-1031 [HIGH] CVE-2020-1031: <p>An information disclosure vulnerability exists in the way that the Windows Server DHCP service im An information disclosure vulnerability exists in the way that the Windows Server DHCP service improperly discloses the contents of its memory. To exploit the vulnerability, an unauthenticated attacker could send a specially crafted packet to an affected DHCP server. An attacker who successfully exploited this vulnerability could obtain information to further c
nvd
CVE-2021-34446P3HIGHCVSS 8.8v20h2v21h1+4 more2021-07-16
CVE-2021-34446 [HIGH] CVE-2021-34446: Windows HTML Platforms Security Feature Bypass Vulnerability Windows HTML Platforms Security Feature Bypass Vulnerability
nvd
CVE-2019-0851P3HIGHCVSS 7.8v1607v1703+3 more2019-04-09
CVE-2019-0851 [HIGH] CVE-2019-0851: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0846, CVE-2019-0847, CVE-2019-0877, CVE-2019-0879.
nvd
CVE-2019-0846P3HIGHCVSS 7.8v1607v1703+3 more2019-04-09
CVE-2019-0846 [HIGH] CVE-2019-0846: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0847, CVE-2019-0851, CVE-2019-0877, CVE-2019-0879.
nvd
CVE-2019-0847P3HIGHCVSS 7.8v1607v1703+3 more2019-04-09
CVE-2019-0847 [HIGH] CVE-2019-0847: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0846, CVE-2019-0851, CVE-2019-0877, CVE-2019-0879.
nvd
CVE-2022-37975P3HIGHCVSS 8.8v20h2v21h1+3 more2022-10-11
CVE-2022-37975 [HIGH] CVE-2022-37975: Windows Group Policy Elevation of Privilege Vulnerability Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2022-37970P3HIGHCVSS 7.8v20h2v21h1+2 more2022-10-11
CVE-2022-37970 [HIGH] CVE-2022-37970: Windows DWM Core Library Elevation of Privilege Vulnerability Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2022-24542P3HIGHCVSS 7.8v20h2v21h1+4 more2022-04-15
CVE-2022-24542 [HIGH] CVE-2022-24542: Windows Win32k Elevation of Privilege Vulnerability Windows Win32k Elevation of Privilege Vulnerability
nvd
CVE-2017-0277P3HIGHCVSS 7.0v1511v1607+1 more2017-05-12
CVE-2017-0277 [HIGH] CVE-2017-0277: The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution
nvd
CVE-2017-0278P3HIGHCVSS 7.0v1511v1607+1 more2017-05-12
CVE-2017-0278 [HIGH] CVE-2017-0278: The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution
nvd
Microsoft Windows 10 vulnerabilities | cvebase