cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 56 of 141
CVE-2023-23423P3HIGHCVSS 7.8fixed in 10.0.10240.198052023-03-14
CVE-2023-23423 [HIGH] CVE-2023-23423: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-38039P3HIGHCVSS 7.8v20h2v21h1+2 more2022-10-11
CVE-2022-38039 [HIGH] CVE-2022-38039: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-37990P3HIGHCVSS 7.8v20h2v21h1+3 more2022-10-11
CVE-2022-37990 [HIGH] CVE-2022-37990: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-26810P3HIGHCVSS 7.8v20h2v21h1+4 more2022-04-15
CVE-2022-26810 [HIGH] CVE-2022-26810: Windows File Server Resource Management Service Elevation of Privilege Vulnerability Windows File Server Resource Management Service Elevation of Privilege Vulnerability
nvd
CVE-2022-37995P3HIGHCVSS 7.8v20h2v21h1+3 more2022-10-11
CVE-2022-37995 [HIGH] CVE-2022-37995: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2021-43223P3HIGHCVSS 7.8v20h2v21h1+4 more2021-12-15
CVE-2021-43223 [HIGH] CVE-2021-43223: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
nvd
CVE-2017-0190P4MEDIUMCVSS 4.4v1511v16072017-05-12
CVE-2017-0190 [MEDIUM] CWE-200 CVE-2017-0190: The GDI component in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windo The GDI component in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI Information Disclosure Vulnerability."
nvd
CVE-2020-1234P3HIGHCVSS 7.8v1607v1709+5 more2020-06-09
CVE-2020-1234 [HIGH] CVE-2020-1234: An elevation of privilege vulnerability exists when Windows Error Reporting improperly handles objec An elevation of privilege vulnerability exists when Windows Error Reporting improperly handles objects in memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1309P3HIGHCVSS 7.8v1607v1709+5 more2020-06-09
CVE-2020-1309 [HIGH] CVE-2020-1309: An elevation of privilege vulnerability exists when the Microsoft Store Runtime improperly handles m An elevation of privilege vulnerability exists when the Microsoft Store Runtime improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Microsoft Store Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1222.
nvd
CVE-2020-1492P3HIGHCVSS 7.8v1607v1709+5 more2020-08-17
CVE-2020-1492 [HIGH] CWE-787 CVE-2020-1492: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincin
nvd
CVE-2020-1554P3HIGHCVSS 7.8v1607v1709+5 more2020-08-17
CVE-2020-1554 [HIGH] CWE-787 CVE-2020-1554: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincin
nvd
CVE-2020-1379P3HIGHCVSS 7.8v1607v1709+5 more2020-08-17
CVE-2020-1379 [HIGH] CWE-787 CVE-2020-1379: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincin
nvd
CVE-2021-24090P3HIGHCVSS 7.8v20h2v1909+1 more2021-03-11
CVE-2021-24090 [HIGH] CWE-269 CVE-2021-24090: Windows Error Reporting Elevation of Privilege Vulnerability Windows Error Reporting Elevation of Privilege Vulnerability
nvd
CVE-2020-1241P3HIGHCVSS 7.8v1607v1709+5 more2020-06-09
CVE-2020-1241 [HIGH] CVE-2020-1241: A security feature bypass vulnerability exists when Windows Kernel fails to properly sanitize certai A security feature bypass vulnerability exists when Windows Kernel fails to properly sanitize certain parameters.To exploit the vulnerability, a locally-authenticated attacker could attempt to run a specially crafted application on a targeted system.The update addresses the vulnerability by correcting how Windows Kernel handles parameter sanitization., aka 'Win
nvd
CVE-2020-1292P3HIGHCVSS 7.8v1803v1809+3 more2020-06-09
CVE-2020-1292 [HIGH] CVE-2020-1292: An elevation of privilege vulnerability exists in OpenSSH for Windows when it does not properly rest An elevation of privilege vulnerability exists in OpenSSH for Windows when it does not properly restrict access to configuration settings, aka 'OpenSSH for Windows Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1305P3HIGHCVSS 7.8v1607v1709+5 more2020-06-09
CVE-2020-1305 [HIGH] CVE-2020-1305: An elevation of privilege vulnerability exists when the Windows State Repository Service improperly An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1311P3HIGHCVSS 7.8v1607v1709+5 more2020-06-09
CVE-2020-1311 [HIGH] CVE-2020-1311: An elevation of privilege vulnerability exists when Component Object Model (COM) client uses special An elevation of privilege vulnerability exists when Component Object Model (COM) client uses special case IIDs, aka 'Component Object Model Elevation of Privilege Vulnerability'.
nvd
CVE-2016-0135P3HIGHCVSS 8.4v15112016-04-12
CVE-2016-0135 [HIGH] CWE-119 CVE-2016-0135: The Secondary Logon Service in Microsoft Windows 10 Gold and 1511 allows local users to gain privile The Secondary Logon Service in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Secondary Logon Elevation of Privilege Vulnerability."
nvd
CVE-2021-27070P3HIGHCVSS 7.8v20h2v20042021-03-11
CVE-2021-27070 [HIGH] CWE-732 CVE-2021-27070: Windows 10 Update Assistant Elevation of Privilege Vulnerability Windows 10 Update Assistant Elevation of Privilege Vulnerability
nvd
CVE-2017-0180P3HIGHCVSS 7.6v1511v1607+1 more2017-04-12
CVE-2017-0180 [HIGH] CVE-2017-0180: A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host s A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is unique from CVE-2017-0162, CVE-2017-0163, and CVE-2017-0181.
nvd
Microsoft Windows 10 vulnerabilities | cvebase