cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 41 of 141
CVE-2020-1407P3HIGHCVSS 7.8v1607v1709+5 more2020-07-14
CVE-2020-1407 [HIGH] CVE-2020-1407: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1400, CVE-2020-1401.
nvd
CVE-2016-3374P3MEDIUMCVSS 6.5v1511v16072016-09-14
CVE-2016-3374 [MEDIUM] CVE-2016-3374: The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "PDF Library Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3370.
nvd
CVE-2022-22000P3HIGHCVSS 7.8v20h2v21h1+4 more2022-02-09
CVE-2022-22000 [HIGH] CVE-2022-22000: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-35761P3HIGHCVSS 7.8v20h2v21h1+3 more2022-08-09
CVE-2022-35761 [HIGH] CWE-269 CVE-2022-35761: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2017-8591P3HIGHCVSS 7.8v1511v1607+1 more2017-08-08
CVE-2017-8591 [HIGH] CVE-2017-8591: Windows Input Method Editor (IME) in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, W Windows Input Method Editor (IME) in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an remote code execution vulnerability when it fails to properly handle objects in memory, aka "Windows IME Remote Code Execution Vulnerability".
nvd
CVE-2017-8495P3HIGHCVSS 7.5v1511v1607+1 more2017-07-11
CVE-2017-8495 [HIGH] CWE-287 CVE-2017-8495: Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to bypass Extended Protection for Authentication when Kerberos fails to prevent tampering with the SNAME field during ticket exchange, aka "Kerberos SNA
nvd
CVE-2023-21812P3HIGHCVSS 7.8fixed in 10.0.10240.197472023-02-14
CVE-2023-21812 [HIGH] CWE-122 CVE-2023-21812: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2019-0637P3HIGHCVSS 7.5v1709v1803+1 more2019-03-05
CVE-2019-0637 [HIGH] CVE-2019-0637: A security feature bypass vulnerability exists when Windows Defender Firewall incorrectly applies fi A security feature bypass vulnerability exists when Windows Defender Firewall incorrectly applies firewall profiles to cellular network connections, aka 'Windows Defender Firewall Security Feature Bypass Vulnerability'.
nvd
CVE-2022-22026P3HIGHCVSS 8.8v20h2v21h1+3 more2022-07-12
CVE-2022-22026 [HIGH] CWE-787 CVE-2022-22026: Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
nvd
CVE-2017-8584P3HIGHCVSS 7.5v16072017-07-11
CVE-2017-8584 [HIGH] CVE-2017-8584: Windows 10 1607 and Windows Server 2016 allow an attacker to execute code remotely via a specially c Windows 10 1607 and Windows Server 2016 allow an attacker to execute code remotely via a specially crafted WiFi packet aka "HoloLens Remote Code Execution Vulnerability."
nvd
CVE-2017-8588P3HIGHCVSS 7.0v1511v1607+1 more2017-07-11
CVE-2017-8588 [HIGH] CVE-2017-8588: Microsoft WordPad in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server Microsoft WordPad in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way it parses specially crafted files, aka "WordPad Remote Code Execution Vulnerability".
nvd
CVE-2017-8633P3HIGHCVSS 7.5v1511v1607+1 more2017-08-08
CVE-2017-8633 [HIGH] CWE-863 CVE-2017-8633: Windows Error Reporting (WER) in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Win Windows Error Reporting (WER) in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability, aka "Windows Error Reporting Elevation of Privilege Vulnerability".
nvd
CVE-2022-21843P3HIGHCVSS 7.5v20h2v21h1+4 more2022-01-11
CVE-2022-21843 [HIGH] CVE-2022-21843: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2016-3201P3MEDIUMCVSS 6.5v15112016-06-16
CVE-2016-3201 [MEDIUM] CWE-200 CVE-2016-3201: Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted PDF document, aka "Windows PDF Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3215.
nvd
CVE-2022-22037P3HIGHCVSS 7.5v20h2v21h1+3 more2022-07-12
CVE-2022-22037 [HIGH] CVE-2022-22037: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
nvd
CVE-2021-43233P3HIGHCVSS 7.5v20h2v21h1+5 more2021-12-15
CVE-2021-43233 [HIGH] CVE-2021-43233: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2022-30142P3HIGHCVSS 7.5v20h2v21h1+3 more2022-06-15
CVE-2022-30142 [HIGH] CVE-2022-30142: Windows File History Remote Code Execution Vulnerability Windows File History Remote Code Execution Vulnerability
nvd
CVE-2022-21983P3HIGHCVSS 7.5v20h2v21h1+4 more2022-04-15
CVE-2022-21983 [HIGH] CVE-2022-21983: Win32 Stream Enumeration Remote Code Execution Vulnerability Win32 Stream Enumeration Remote Code Execution Vulnerability
nvd
CVE-2017-11788P3HIGHCVSS 7.5v1511v1607+2 more2017-11-15
CVE-2017-11788 [HIGH] CVE-2017-11788: Windows Search in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Windows Search in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows server, version 1709 allows an unauthenticated attacker to remotely send specially crafted messages that could cause a denial of service against the system due to i
nvd
CVE-2021-34534P3HIGHCVSS 7.5v20h2v21h1+4 more2021-08-12
CVE-2021-34534 [HIGH] CVE-2021-34534: Windows MSHTML Platform Remote Code Execution Vulnerability Windows MSHTML Platform Remote Code Execution Vulnerability
nvd
Microsoft Windows 10 vulnerabilities | cvebase