cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 44 of 141
CVE-2016-3333P3HIGHCVSS 7.8v1511v16072016-11-10
CVE-2016-3333 [HIGH] CVE-2016-3333: The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Windows Common Log File System Driver Elevation of
nvd
CVE-2016-3334P3HIGHCVSS 7.8v1511v16072016-11-10
CVE-2016-3334 [HIGH] CVE-2016-3334: The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Windows Common Log File System Driver Elevation of
nvd
CVE-2016-3332P3HIGHCVSS 7.8v1511v16072016-11-10
CVE-2016-3332 [HIGH] CVE-2016-3332: The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Windows Common Log File System Driver Elevation of
nvd
CVE-2016-0026P3HIGHCVSS 7.8v1511v16072016-11-10
CVE-2016-0026 [HIGH] CWE-119 CVE-2016-0026: The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Windows Common Log File System Driver Elev
nvd
CVE-2016-3338P3HIGHCVSS 7.8v1511v16072016-11-10
CVE-2016-3338 [HIGH] CVE-2016-3338: The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Windows Common Log File System Driver Elevation of
nvd
CVE-2016-7184P3HIGHCVSS 7.8v1511v16072016-11-10
CVE-2016-7184 [HIGH] CVE-2016-7184: The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Windows Common Log File System Driver Elevation of
nvd
CVE-2016-3335P3HIGHCVSS 7.8v1511v16072016-11-10
CVE-2016-3335 [HIGH] CVE-2016-3335: The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Windows Common Log File System Driver Elevation of
nvd
CVE-2017-11847P3HIGHCVSS 7.8v1511v1607+1 more2017-11-15
CVE-2017-11847 [HIGH] CVE-2017-11847: Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT1, Windows Se Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to run arbitrary code in kernel mode, install programs, view, change or delete data, and create new accounts with full user r
nvd
CVE-2016-3266P3HIGHCVSS 7.8v1511v16072016-10-14
CVE-2016-3266 [HIGH] CWE-264 CVE-2016-3266: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2
nvd
CVE-2019-0906P3HIGHCVSS 7.8v1607v1703+4 more2019-06-12
CVE-2019-0906 [HIGH] CWE-129 CVE-2019-0906: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vul
nvd
CVE-2016-7247P3HIGHCVSS 7.5v1511v16072016-11-10
CVE-2016-7247 [HIGH] CWE-284 CVE-2016-7247: Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1 Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow physically proximate attackers to bypass the Secure Boot protection mechanism via a crafted boot policy, aka "Secure Boot Component Vulnerability."
nvd
CVE-2020-0951P3MEDIUMCVSS 6.7v1607v1709+5 more2020-09-11
CVE-2020-0951 [MEDIUM] CVE-2020-0951: <p>A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) whi A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could execute PowerShell commands that would be blocked by WDAC. To exploit the vulnerability, an attacker need administrator access on a local machine
nvd
CVE-2022-21994P3HIGHCVSS 7.8v20h2v21h1+3 more2022-02-09
CVE-2022-21994 [HIGH] CVE-2022-21994: Windows DWM Core Library Elevation of Privilege Vulnerability Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2020-16967P3HIGHCVSS 7.8v1607v1709+5 more2020-10-16
CVE-2020-16967 [HIGH] CVE-2020-16967: <p>A remote code execution vulnerability exists when the Windows Camera Codec Pack improperly handle A remote code execution vulnerability exists when the Windows Camera Codec Pack improperly handles objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An a
nvd
CVE-2020-1562P3HIGHCVSS 7.8v1607v1709+5 more2020-08-17
CVE-2020-1562 [HIGH] CVE-2020-1562: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have to open a specially crafted file. The security update addresses the vulnerability by correct
nvd
CVE-2020-0909P3HIGHCVSS 7.5v1607v1709+4 more2020-05-21
CVE-2020-0909 [HIGH] CVE-2020-0909: A denial of service vulnerability exists when Hyper-V on a Windows Server fails to properly handle s A denial of service vulnerability exists when Hyper-V on a Windows Server fails to properly handle specially crafted network packets.To exploit the vulnerability, an attacker would send specially crafted network packets to the Hyper-V Server.The security update addresses the vulnerability by resolving the conditions where Hyper-V would fail to properly handle t
nvd
CVE-2021-1668P3HIGHCVSS 7.8v20h2v1607+4 more2021-01-12
CVE-2021-1668 [HIGH] CVE-2021-1668: Microsoft DTV-DVD Video Decoder Remote Code Execution Vulnerability Microsoft DTV-DVD Video Decoder Remote Code Execution Vulnerability
nvd
CVE-2018-8219P3HIGHCVSS 8.8v1607v1703+6 more2018-06-14
CVE-2018-8219 [HIGH] CVE-2018-8219: An elevation of privilege vulnerability exists when Windows Hyper-V instruction emulation fails to p An elevation of privilege vulnerability exists when Windows Hyper-V instruction emulation fails to properly enforce privilege levels, aka "Hypervisor Code Integrity Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2021-26415P3HIGHCVSS 7.8v20h2v1607+4 more2021-04-13
CVE-2021-26415 [HIGH] CWE-20 CVE-2021-26415: Windows Installer Elevation of Privilege Vulnerability Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2016-3218P3HIGHCVSS 7.8v15112016-06-16
CVE-2016-3218 [HIGH] CWE-264 CVE-2016-3218: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-322
nvd
Microsoft Windows 10 vulnerabilities | cvebase