cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 45 of 141
CVE-2020-1425P3HIGHCVSS 7.8v1709v1803+4 more2020-07-27
CVE-2020-1425 [HIGH] CVE-2020-1425: A remoted code execution vulnerability exists in the way that Microsoft Windows Codecs Library handl A remoted code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1457.
nvd
CVE-2022-38016P3HIGHCVSS 8.8v20h2v21h1+3 more2022-10-11
CVE-2022-38016 [HIGH] CVE-2022-38016: Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
nvd
CVE-2021-26868P3HIGHCVSS 7.8v20h2v1607+4 more2021-03-11
CVE-2021-26868 [HIGH] CWE-119 CVE-2021-26868: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2022-21878P3HIGHCVSS 7.8v20h2v21h1+4 more2022-01-11
CVE-2022-21878 [HIGH] CVE-2022-21878: Windows Geolocation Service Remote Code Execution Vulnerability Windows Geolocation Service Remote Code Execution Vulnerability
nvd
CVE-2016-3310P3HIGHCVSS 7.8v1511v16072016-08-09
CVE-2016-3310 [HIGH] CVE-2016-3310: The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3308
nvd
CVE-2020-0908P3HIGHCVSS 7.5v1607v1709+5 more2020-09-11
CVE-2020-0908 [HIGH] CVE-2020-0908: <p>A remote code execution vulnerability exists when the Windows Text Service Module improperly hand A remote code execution vulnerability exists when the Windows Text Service Module improperly handles memory. An attacker who successfully exploited the vulnerability could gain execution on a victim system. An attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft Edge (Chromium-based), and then convince
nvd
CVE-2022-21992P3HIGHCVSS 7.8v20h2v21h1+4 more2022-02-09
CVE-2022-21992 [HIGH] CVE-2022-21992: Windows Mobile Device Management Remote Code Execution Vulnerability Windows Mobile Device Management Remote Code Execution Vulnerability
nvd
CVE-2016-0174P3HIGHCVSS 7.8v15112016-05-11
CVE-2016-0174 [HIGH] CVE-2016-0174: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0171, CVE-2
nvd
CVE-2021-1726P3HIGHCVSS 8.0v20h2v1607+4 more2021-02-25
CVE-2021-1726 [HIGH] CVE-2021-1726: Microsoft SharePoint Server Spoofing Vulnerability Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2022-29115P3HIGHCVSS 7.8v20h2v21h1+4 more2022-05-10
CVE-2022-29115 [HIGH] CVE-2022-29115: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2021-27089P3HIGHCVSS 7.8v20h2v1607+4 more2021-04-13
CVE-2021-27089 [HIGH] CVE-2021-27089: Microsoft Internet Messaging API Remote Code Execution Vulnerability Microsoft Internet Messaging API Remote Code Execution Vulnerability
nvd
CVE-2018-8335P3HIGHCVSS 7.5v1607v1703+12 more2018-09-13
CVE-2018-8335 [HIGH] CVE-2018-8335: A denial of service vulnerability exists in the Microsoft Server Block Message (SMB) when an attacke A denial of service vulnerability exists in the Microsoft Server Block Message (SMB) when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
nvd
CVE-2022-21913P3HIGHCVSS 7.5v20h2v21h1+4 more2022-01-11
CVE-2022-21913 [HIGH] CVE-2022-21913: Local Security Authority (Domain Policy) Remote Protocol Security Feature Bypass Local Security Authority (Domain Policy) Remote Protocol Security Feature Bypass
nvd
CVE-2022-22027P3HIGHCVSS 7.8v20h2v21h1+3 more2022-07-12
CVE-2022-22027 [HIGH] CVE-2022-22027: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2016-0196P3HIGHCVSS 7.8v15112016-05-11
CVE-2016-0196 [HIGH] CVE-2016-0196: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0171, CVE-2
nvd
CVE-2022-22024P3HIGHCVSS 7.8v20h2v21h1+3 more2022-07-12
CVE-2022-22024 [HIGH] CVE-2022-22024: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2022-30164P3HIGHCVSS 7.8v20h2v21h1+3 more2022-06-15
CVE-2022-30164 [HIGH] CVE-2022-30164: Kerberos AppContainer Security Feature Bypass Vulnerability Kerberos AppContainer Security Feature Bypass Vulnerability
nvd
CVE-2020-0790P3HIGHCVSS 7.8v1607v1709+5 more2020-09-11
CVE-2020-0790 [HIGH] CVE-2020-0790: <p>A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity. This vulnerability by itself does not allow arbitrary code execution; however, it could allow arbitrary code to be run if th
nvd
CVE-2018-8218P3HIGHCVSS 7.7v1709vVersion 1709 for x64-based Systems2018-06-14
CVE-2018-8218 [HIGH] CWE-20 CVE-2018-8218: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service Vulnerability." This affects Windows 10, Windows 10 Servers.
nvd
CVE-2020-1080P3HIGHCVSS 7.8v1803v1809+3 more2020-10-16
CVE-2020-1080 [HIGH] CVE-2020-1080: <p>An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to pro An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory. An attacker who successfully exploited these vulnerabilities could gain elevated privileges on a target operating system. This vulnerability by itself does not allow arbitrary code to be run. However, this vulnerability could be used
nvd
Microsoft Windows 10 vulnerabilities | cvebase