cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 37 of 141
CVE-2020-0949P3HIGHCVSS 8.8v1607v1709+4 more2020-04-15
CVE-2020-0949 [HIGH] CVE-2020-0949: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0948, CVE-2020-0950.
nvd
CVE-2020-0950P3HIGHCVSS 8.8v1607v1709+4 more2020-04-15
CVE-2020-0950 [HIGH] CVE-2020-0950: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0948, CVE-2020-0949.
nvd
CVE-2020-1126P3HIGHCVSS 8.8v1607v1709+4 more2020-05-21
CVE-2020-1126 [HIGH] CVE-2020-1126: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1028, CVE-2020-1136, CVE-2020-1150.
nvd
CVE-2020-0708P3HIGHCVSS 7.8v1607v1709+4 more2020-02-11
CVE-2020-0708 [HIGH] CVE-2020-0708: A remote code execution vulnerability exists when the Windows Imaging Library improperly handles mem A remote code execution vulnerability exists when the Windows Imaging Library improperly handles memory.To exploit this vulnerability, an attacker would first have to coerce a victim to open a specially crafted file.The security update addresses the vulnerability by correcting how the Windows Imaging Library handles memory., aka 'Windows Imaging Library Remote
nvd
CVE-2019-1183P3HIGHCVSS 8.8v1607v1703+4 more2019-08-14
CVE-2019-1183 [HIGH] CVE-2019-1183: This information is being revised to indicate that this CVE (CVE-2019-1183) is fully mitigated by th This information is being revised to indicate that this CVE (CVE-2019-1183) is fully mitigated by the security updates for the vulnerability discussed in CVE-2019-1194. No update is required.
nvd
CVE-2018-0746P4MEDIUMCVSS 4.7PoCv1511v1607+2 more2018-01-04
CVE-2018-0746 [MEDIUM] CVE-2018-0746: The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 160 The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way memory addresses are handled, aka "Windows Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0745 and C
nvd
CVE-2022-38051P3HIGHCVSS 7.8v20h2v21h1+3 more2022-10-11
CVE-2022-38051 [HIGH] CVE-2022-38051: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2020-0869P3HIGHCVSS 8.8v1607v1709+4 more2020-03-12
CVE-2020-0869 [HIGH] CVE-2020-0869: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0801, CVE-2020-0807, CVE-2020-0809.
nvd
CVE-2019-0688P3HIGHCVSS 7.5v1607v1703+3 more2019-04-09
CVE-2019-0688 [HIGH] CWE-327 CVE-2019-0688: An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles frag An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles fragmented IP packets, aka 'Windows TCP/IP Information Disclosure Vulnerability'.
nvd
CVE-2022-30140P3HIGHCVSS 7.5v20h2v21h1+3 more2022-06-15
CVE-2022-30140 [HIGH] CVE-2022-30140: Windows iSCSI Discovery Service Remote Code Execution Vulnerability Windows iSCSI Discovery Service Remote Code Execution Vulnerability
nvd
CVE-2022-24474P3HIGHCVSS 7.8v20h2v21h1+4 more2022-04-15
CVE-2022-24474 [HIGH] CVE-2022-24474: Windows Win32k Elevation of Privilege Vulnerability Windows Win32k Elevation of Privilege Vulnerability
nvd
CVE-2019-1246P3HIGHCVSS 7.8v1607v1703+4 more2019-09-11
CVE-2019-1246 [HIGH] CVE-2019-1246: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1240, CVE-2019-1241, CVE-2019-1242, CVE-2019-1243, CVE-2019-1247, CVE-2019-1248, CVE-2019-1249, CVE-2019-1250.
nvd
CVE-2016-3342P3HIGHCVSS 7.8v1511v16072016-11-10
CVE-2016-3342 [HIGH] CVE-2016-3342: The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Windows Common Log File System Driver Elevation of
nvd
CVE-2016-3340P3HIGHCVSS 7.8v1511v16072016-11-10
CVE-2016-3340 [HIGH] CVE-2016-3340: The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Windows Common Log File System Driver Elevation of
nvd
CVE-2016-3343P3HIGHCVSS 7.8v1511v16072016-11-10
CVE-2016-3343 [HIGH] CVE-2016-3343: The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Windows Common Log File System Driver Elevation of
nvd
CVE-2020-1113P3HIGHCVSS 7.5v1607v1709+4 more2020-05-21
CVE-2020-1113 [HIGH] CWE-295 CVE-2020-1113: A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over RPC, aka 'Windows Task Scheduler Security Feature Bypass Vulnerability'.
nvd
CVE-2019-1406P3HIGHCVSS 7.8v1607v1709+3 more2019-11-12
CVE-2019-1406 [HIGH] CVE-2019-1406: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.
nvd
CVE-2016-0128P3MEDIUMCVSS 6.8v15112016-04-12
CVE-2016-0128 [MEDIUM] CWE-254 CVE-2016-0128: The SAM and LSAD protocol implementations in Microsoft Windows Vista SP2, Windows Server 2008 SP2 an The SAM and LSAD protocol implementations in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 do not properly establish an RPC channel, which allows man-in-the-middle attackers to perform protocol-downgrade attacks and impersonate
nvd
CVE-2022-32230P3HIGHCVSS 7.5v20h2v21h1+2 more2022-06-14
CVE-2022-32230 [HIGH] CWE-476 CVE-2022-32230: Microsoft Windows SMBv3 suffers from a null pointer dereference in versions of Windows prior to the Microsoft Windows SMBv3 suffers from a null pointer dereference in versions of Windows prior to the April, 2022 patch set. By sending a malformed FileNormalizedNameInformation SMBv3 request over a named pipe, an attacker can cause a Blue Screen of Death (BSOD) crash of the Windows kernel. For most systems, this attack requires authentication, except in
nvd
CVE-2018-0745P4MEDIUMCVSS 4.7PoCv1703v17092018-01-04
CVE-2018-0745 [MEDIUM] CWE-665 CVE-2018-0745: The Windows kernel in Windows 10 version 1703. Windows 10 version 1709, and Windows Server, version The Windows kernel in Windows 10 version 1703. Windows 10 version 1709, and Windows Server, version 1709 allows an information disclosure vulnerability due to the way objects are handled in memory, aka "Windows Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0746 and CVE-2018-0747.
nvd
Microsoft Windows 10 vulnerabilities | cvebase