cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 39 of 141
CVE-2020-1118P3HIGHCVSS 7.5v1709v1803+3 more2020-05-21
CVE-2020-1118 [HIGH] CVE-2020-1118: A denial of service vulnerability exists in the Windows implementation of Transport Layer Security ( A denial of service vulnerability exists in the Windows implementation of Transport Layer Security (TLS) when it improperly handles certain key exchanges, aka 'Microsoft Windows Transport Layer Security Denial of Service Vulnerability'.
nvd
CVE-2019-1188P3HIGHCVSS 7.5v1709v1803+2 more2019-08-14
CVE-2019-1188 [HIGH] CWE-59 CVE-2019-1188: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who
nvd
CVE-2020-1208P3HIGHCVSS 7.8v1607v1709+5 more2020-06-09
CVE-2020-1208 [HIGH] CVE-2020-1208: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1236.
nvd
CVE-2019-1057P3HIGHCVSS 7.5v1607v1703+4 more2019-08-14
CVE-2019-1057 [HIGH] CWE-611 CVE-2019-1057: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exploited the vulnerability could run malicious code remotely to take control of the user’s system. To exploit the vulnerability, an attacker could host a specially crafted website designed to invoke MSXML thr
nvd
CVE-2021-26882P3HIGHCVSS 7.8v20h2v1607+4 more2021-03-11
CVE-2021-26882 [HIGH] CVE-2021-26882: Remote Access API Elevation of Privilege Vulnerability Remote Access API Elevation of Privilege Vulnerability
nvd
CVE-2017-11781P3HIGHCVSS 7.5v1511v1607+1 more2017-10-13
CVE-2017-11781 [HIGH] CWE-20 CVE-2017-11781: The Microsoft Server Block Message (SMB) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 The Microsoft Server Block Message (SMB) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows a denial of service vulnerability when an attacker sends specially crafted requests to the server, aka "Windows SMB D
nvd
CVE-2018-0956P3HIGHCVSS 7.5v1511v1607+12 more2018-04-12
CVE-2018-0956 [HIGH] CVE-2018-0956: A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys imp A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys improperly parses specially crafted HTTP 2.0 requests, aka "HTTP.sys Denial of Service Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2022-24545P3HIGHCVSS 7.5v20h2v21h1+4 more2022-04-15
CVE-2022-24545 [HIGH] CVE-2022-24545: Windows Kerberos Remote Code Execution Vulnerability Windows Kerberos Remote Code Execution Vulnerability
nvd
CVE-2016-3348P3HIGHCVSS 7.8v1511v16072016-09-14
CVE-2016-3348 [HIGH] CWE-264 CVE-2016-3348: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
nvd
CVE-2020-1401P3HIGHCVSS 7.8v1607v1709+5 more2020-07-14
CVE-2020-1401 [HIGH] CVE-2020-1401: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1400, CVE-2020-1407.
nvd
CVE-2022-30149P3HIGHCVSS 7.5v20h2v21h1+3 more2022-06-15
CVE-2022-30149 [HIGH] CVE-2022-30149: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-30143P3HIGHCVSS 7.5v20h2v21h1+3 more2022-06-15
CVE-2022-30143 [HIGH] CVE-2022-30143: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-30146P3HIGHCVSS 7.5v20h2v21h1+3 more2022-06-15
CVE-2022-30146 [HIGH] CVE-2022-30146: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2017-0016P3MEDIUMCVSS 5.9v1511v16072017-03-17
CVE-2017-0016 [MEDIUM] CWE-476 CVE-2017-0016: Microsoft Windows 10 Gold, 1511, and 1607; Windows 8.1; Windows RT 8.1; Windows Server 2012 R2, and Microsoft Windows 10 Gold, 1511, and 1607; Windows 8.1; Windows RT 8.1; Windows Server 2012 R2, and Windows Server 2016 do not properly handle certain requests in SMBv2 and SMBv3 packets, which allows remote attackers to execute arbitrary code via a crafted SMBv2 or SMBv3 packet to the Server service, aka "SMBv2/SMBv3 Null Dereference Denial of Service
nvd
CVE-2018-8251P3HIGHCVSS 7.5v1607v1703+11 more2018-06-14
CVE-2018-8251 [HIGH] CWE-787 CVE-2018-8251: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka "Media Foundation Memory Corruption Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2018-0965P3HIGHCVSS 8.4v1607v1703+6 more2018-09-13
CVE-2018-0965 [HIGH] CWE-20 CVE-2018-0965: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8439.
nvd
CVE-2020-1457P3HIGHCVSS 7.8v1709v1803+4 more2020-07-27
CVE-2020-1457 [HIGH] CVE-2020-1457: A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handle A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1425.
nvd
CVE-2022-30160P3HIGHCVSS 7.8v20h2v21h1+3 more2022-06-15
CVE-2022-30160 [HIGH] CVE-2022-30160: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
nvd
CVE-2022-22034P3HIGHCVSS 7.8v20h2v21h1+3 more2022-07-12
CVE-2022-22034 [HIGH] CWE-416 CVE-2022-22034: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2018-17612P3HIGHCVSS 7.5v1607v1703+3 more2018-11-09
CVE-2018-17612 [HIGH] CWE-295 CVE-2018-17612: Sennheiser HeadSetup 7.3.4903 places Certification Authority (CA) certificates into the Trusted Root Sennheiser HeadSetup 7.3.4903 places Certification Authority (CA) certificates into the Trusted Root CA store of the local system, and publishes the private key in the SennComCCKey.pem file within the public software distribution, which allows remote attackers to spoof arbitrary web sites or software publishers for several years, even if the HeadSetup
nvd
Microsoft Windows 10 vulnerabilities | cvebase