cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 7 of 141
CVE-2020-17136P3HIGHCVSS 7.8PoCv20h2v1803+4 more2020-12-10
CVE-2020-17136 [HIGH] CVE-2020-17136: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2021-24074P2CRITICALCVSS 9.8v20h2v1607+4 more2021-02-25
CVE-2021-24074 [CRITICAL] CVE-2021-24074: Windows TCP/IP Remote Code Execution Vulnerability Windows TCP/IP Remote Code Execution Vulnerability
nvd
CVE-2019-0618P2HIGHCVSS 8.8v1607v1703+3 more2019-03-05
CVE-2019-0618 [HIGH] CVE-2019-0618: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0662.
nvd
CVE-2021-24094P2CRITICALCVSS 9.8v20h2v1607+4 more2021-02-25
CVE-2021-24094 [CRITICAL] CVE-2021-24094: Windows TCP/IP Remote Code Execution Vulnerability Windows TCP/IP Remote Code Execution Vulnerability
nvd
CVE-2019-0571P3HIGHCVSS 7.8PoCv1607v1703+18 more2019-01-08
CVE-2019-0571 [HIGH] CWE-706 CVE-2019-0571: An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly hand An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers. This CVE ID is unique from CVE-2019-0572, CVE-2019-0573, CVE-2019-0574.
nvd
CVE-2020-1300P2HIGHCVSS 8.8v1607v1709+5 more2020-06-09
CVE-2020-1300 [HIGH] CVE-2020-1300: A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files.To exploit the vulnerability, an attacker would have to convince a user to either open a specially crafted cabinet file or spoof a network printer and trick a user into installing a malicious cabinet file disguised as a printer driver.The update addresses
nvd
CVE-2016-3376P3HIGHCVSS 7.8PoCv1511v1607+1 more2016-10-14
CVE-2016-3376 [HIGH] CVE-2016-3376: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." a different vulnerability than CVE-2016-3266
nvd
CVE-2019-0887P2HIGHCVSS 8.0v1607v1703+4 more2019-07-15
CVE-2019-0887 [HIGH] CWE-22 CVE-2019-0887: A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
nvd
CVE-2021-24093P2HIGHCVSS 8.8v20h2v1607+4 more2021-02-25
CVE-2021-24093 [HIGH] CVE-2021-24093: Windows Graphics Component Remote Code Execution Vulnerability Windows Graphics Component Remote Code Execution Vulnerability
nvd
CVE-2019-1170P3HIGHCVSS 8.8PoCv1809v19032019-08-14
CVE-2019-1170 [HIGH] CWE-862 CVE-2019-1170: An elevation of privilege vulnerability exists when reparse points are created by sandboxed processe An elevation of privilege vulnerability exists when reparse points are created by sandboxed processes allowing sandbox escape. An attacker who successfully exploited the vulnerability could use the sandbox escape to elevate privileges on an affected system. To exploit the vulnerability, an attacker would first have to log on to the system, and then run
nvd
CVE-2022-26928P4HIGHCVSS 7.0Exploitedv20h2v21h1+3 more2022-09-13
CVE-2022-26928 [HIGH] CWE-362 CVE-2022-26928: Windows Photo Import API Elevation of Privilege Vulnerability Windows Photo Import API Elevation of Privilege Vulnerability
nvd
CVE-2020-0655P2HIGHCVSS 8.0v1607v1709+4 more2020-02-11
CVE-2020-0655 [HIGH] CVE-2020-0655: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Termin A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
nvd
CVE-2018-0952P3HIGHCVSS 7.8PoCv1607v1703+12 more2018-08-15
CVE-2018-0952 [HIGH] CVE-2018-0952: An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file c An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations, aka "Diagnostic Hub Standard Collector Elevation Of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Microsoft Visual Studio, Windows 10 Servers.
nvd
CVE-2016-3345P2HIGHCVSS 8.8v1511v16072016-09-14
CVE-2016-3345 [HIGH] CWE-284 CVE-2016-3345: The SMBv1 server in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, The SMBv1 server in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Authenticated Remote Code Execution Vulnerability."
nvd
CVE-2019-1182P2CRITICALCVSS 9.8v1607v1703+4 more2019-08-14
CVE-2019-1182 [CRITICAL] CVE-2019-1182: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability cou
nvd
CVE-2019-0697P2CRITICALCVSS 9.8v1803v18092019-04-09
CVE-2019-0697 [CRITICAL] CWE-787 CVE-2019-0697: A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0698, CVE-2019-0726.
nvd
CVE-2016-7212P2HIGHCVSS 7.8v1511v16072016-11-10
CVE-2016-7212 [HIGH] CWE-284 CVE-2016-7212: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow remote attackers to execute arbitrary code via a crafted image file, aka "Windows Remote Code Execution Vulnerability."
nvd
CVE-2018-8420P2HIGHCVSS 8.8v1607v1703+12 more2018-09-13
CVE-2018-8420 [HIGH] CWE-611 CVE-2018-8420: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 S
nvd
CVE-2016-3371P3MEDIUMCVSS 5.5PoCv1511v16072016-09-14
CVE-2016-3371 [MEDIUM] CWE-200 CVE-2016-3371: The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wi The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 does not properly enforce permissions, which allows local users to obtain sensitive information via a crafted application, aka "Windows Kernel Elevation of P
nvd
CVE-2020-1301P2HIGHCVSS 8.8v1607v1709+5 more2020-06-09
CVE-2020-1301 [HIGH] CVE-2020-1301: A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0 A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0 (SMBv1) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'.
nvd
Microsoft Windows 10 vulnerabilities | cvebase