cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 35 of 141
CVE-2022-24495P3HIGHCVSS 7.5v20h2v21h1+4 more2022-04-15
CVE-2022-24495 [HIGH] CVE-2022-24495: Windows Direct Show Remote Code Execution Vulnerability Windows Direct Show Remote Code Execution Vulnerability
nvd
CVE-2022-30194P3HIGHCVSS 7.5v20h2v21h1+2 more2022-08-09
CVE-2022-30194 [HIGH] CWE-94 CVE-2022-30194: Windows WebBrowser Control Remote Code Execution Vulnerability Windows WebBrowser Control Remote Code Execution Vulnerability
nvd
CVE-2016-3308P3HIGHCVSS 7.8v1511v16072016-08-09
CVE-2016-3308 [HIGH] CWE-264 CVE-2016-3308: The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2
nvd
CVE-2019-0582P3HIGHCVSS 7.8v1607v1703+3 more2019-01-08
CVE-2019-0582 [HIGH] CVE-2019-0582: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008
nvd
CVE-2020-1153P3HIGHCVSS 7.8v1607v1709+4 more2020-05-21
CVE-2020-1153 [HIGH] CVE-2020-1153: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
nvd
CVE-2020-0907P3HIGHCVSS 7.8v1607v1709+4 more2020-04-15
CVE-2020-0907 [HIGH] CVE-2020-0907: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
nvd
CVE-2020-1525P3HIGHCVSS 8.8v1607v1709+5 more2020-08-17
CVE-2020-1525 [HIGH] CWE-787 CVE-2020-1525: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincin
nvd
CVE-2018-8239P3MEDIUMCVSS 5.5v1607v1703+10 more2018-06-14
CVE-2018-8239 [MEDIUM] CWE-200 CVE-2018-8239: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2016-3319P3HIGHCVSS 7.0v1511v16072016-08-09
CVE-2016-3319 [HIGH] CWE-284 CVE-2016-3319: The PDF library in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, The PDF library in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allows remote attackers to execute arbitrary code via a crafted PDF file, aka "Microsoft PDF Remote Code Execution Vulnerability."
nvd
CVE-2019-0879P3HIGHCVSS 7.8v1607v1703+3 more2019-04-09
CVE-2019-0879 [HIGH] CVE-2019-0879: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0846, CVE-2019-0847, CVE-2019-0851, CVE-2019-0877.
nvd
CVE-2018-0959P3HIGHCVSS 7.6v1607v1703+7 more2018-05-09
CVE-2018-0959 [HIGH] CWE-20 CVE-2018-0959: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server
nvd
CVE-2019-1471P3HIGHCVSS 8.2v1803v1809+2 more2019-12-10
CVE-2019-1471 [HIGH] CWE-20 CVE-2019-1471: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'.
nvd
CVE-2022-37974P3MEDIUMCVSS 6.5v20h2v21h1+1 more2022-10-11
CVE-2022-37974 [MEDIUM] CVE-2022-37974: Windows Mixed Reality Developer Tools Information Disclosure Vulnerability Windows Mixed Reality Developer Tools Information Disclosure Vulnerability
nvd
CVE-2019-1484P3HIGHCVSS 7.8v1607v1709+4 more2019-12-10
CVE-2019-1484 [HIGH] CWE-20 CVE-2019-1484: A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate u A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.
nvd
CVE-2020-0738P3HIGHCVSS 8.8v1607v1709+4 more2020-02-11
CVE-2020-0738 [HIGH] CWE-787 CVE-2020-0738: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'.
nvd
CVE-2022-30150P3HIGHCVSS 7.5v20h2v21h1+3 more2022-06-15
CVE-2022-30150 [HIGH] CWE-287 CVE-2022-30150: Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability
nvd
CVE-2020-1239P3HIGHCVSS 8.8v1607v1709+5 more2020-06-09
CVE-2020-1239 [HIGH] CVE-2020-1239: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1238.
nvd
CVE-2020-0807P3HIGHCVSS 8.8v1803v1809+2 more2020-03-12
CVE-2020-0807 [HIGH] CVE-2020-0807: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0801, CVE-2020-0809, CVE-2020-0869.
nvd
CVE-2020-0809P3HIGHCVSS 8.8v1607v1709+4 more2020-03-12
CVE-2020-0809 [HIGH] CVE-2020-0809: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0801, CVE-2020-0807, CVE-2020-0869.
nvd
CVE-2022-41109P3HIGHCVSS 7.8v20h2v21h1+4 more2022-11-09
CVE-2022-41109 [HIGH] CVE-2022-41109: Windows Win32k Elevation of Privilege Vulnerability Windows Win32k Elevation of Privilege Vulnerability
nvd
Microsoft Windows 10 vulnerabilities | cvebase