cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 9 of 141
CVE-2016-0117P3HIGHCVSS 7.8v15112016-03-09
CVE-2016-0117 [HIGH] CWE-20 CVE-2016-0117: The PDF library in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windo The PDF library in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted PDF document, aka "Windows Remote Code Execution Vulnerability."
nvd
CVE-2019-1222P2CRITICALCVSS 9.8v1803v1809+1 more2019-08-14
CVE-2019-1222 [CRITICAL] CVE-2019-1222: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability cou
nvd
CVE-2019-1226P2CRITICALCVSS 9.8v1803v1809+1 more2019-08-14
CVE-2019-1226 [CRITICAL] CVE-2019-1226: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability cou
nvd
CVE-2018-0744P3HIGHCVSS 7.0PoCv1511v1607+2 more2018-01-04
CVE-2018-0744 [HIGH] CVE-2018-0744: The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 160 The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Elevation of Privilege Vulnerability".
nvd
CVE-2016-0007P3HIGHCVSS 7.8PoCv15112016-01-13
CVE-2016-0007 [HIGH] CVE-2016-0007: The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windo The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles reparse points, which allows local users to gain privileges via a crafted application, aka "Windows Mount Point Elevation of Privil
nvd
CVE-2016-0092P3HIGHCVSS 7.8v15112016-03-09
CVE-2016-0092 [HIGH] CVE-2016-0092: OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted file, aka "Windows OLE Memory Remote Code Execution Vulnerability," a different vulnerability than CVE-2016-0091.
nvd
CVE-2019-0731P3HIGHCVSS 7.8PoCv1607v1703+3 more2019-04-09
CVE-2019-0731 [HIGH] CVE-2019-0731: An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV dr An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836, CVE-2019-0841.
nvd
CVE-2019-0730P3HIGHCVSS 7.8PoCv1607v1703+3 more2019-04-09
CVE-2019-0730 [HIGH] CWE-264 CVE-2019-0730: An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV dr An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836, CVE-2019-0841.
nvd
CVE-2019-0735P3HIGHCVSS 7.8PoCv1607v1703+3 more2019-04-09
CVE-2019-0735 [HIGH] CWE-269 CVE-2019-0735: An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CS An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory, aka 'Windows CSRSS Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1245P3MEDIUMCVSS 6.5PoCv1607v1703+4 more2019-09-11
CVE-2019-1245 [MEDIUM] CVE-2019-1245: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1244, CVE-2019-1251.
nvd
CVE-2018-0877P3HIGHCVSS 7.8PoCv1607v1703+1 more2018-03-14
CVE-2018-0877 [HIGH] CVE-2018-0877: The Desktop Bridge Virtual File System (VFS) in Windows 10 1607, 1703, and 1709, Windows Server 2016 The Desktop Bridge Virtual File System (VFS) in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how file paths are managed, aka "Windows Desktop Bridge VFS Elevation of Privilege Vulnerability".
nvd
CVE-2016-0049P3MEDIUMCVSS 6.2PoCv15112016-02-10
CVE-2016-0049 [MEDIUM] CWE-255 CVE-2016-0049: Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 does not properly validate password changes, which allows remote attackers to bypass authentication by deploying a crafted Key Distribution Center (KDC) and then performing a sign-in acti
nvd
CVE-2018-8550P3HIGHCVSS 7.8PoCv1607v1703+3 more2018-11-14
CVE-2018-8550 [HIGH] CVE-2018-8550: An elevation of privilege exists in Windows COM Aggregate Marshaler, aka "Windows COM Elevation of P An elevation of privilege exists in Windows COM Aggregate Marshaler, aka "Windows COM Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2019-1244P3MEDIUMCVSS 6.5PoCv1607v1703+4 more2019-09-11
CVE-2019-1244 [MEDIUM] CWE-200 CVE-2019-1244: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1245, CVE-2019-1251.
nvd
CVE-2018-0748P3HIGHCVSS 7.8PoCv1511v1607+2 more2018-01-04
CVE-2018-0748 [HIGH] CWE-269 CVE-2018-0748: The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Win The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way memory addresses are handled, aka "Windows Elevation of Privilege Vulne
nvd
CVE-2018-0752P3HIGHCVSS 7.8PoCv1511v1607+2 more2018-01-04
CVE-2018-0752 [HIGH] CVE-2018-0752: The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way the Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2018-0
nvd
CVE-2018-8584P3HIGHCVSS 7.8PoCv1607v1703+18 more2018-11-14
CVE-2018-8584 [HIGH] CWE-367 CVE-2018-8584: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Loc An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers.
nvd
CVE-2023-21758P3HIGHCVSS 7.5v20h2v21h2+3 more2023-01-10
CVE-2023-21758 [HIGH] CWE-476 CVE-2023-21758: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2016-3220P3HIGHCVSS 7.8PoCv15112016-06-16
CVE-2016-3220 [HIGH] CWE-264 CVE-2016-3220: atmfd.dll in the Adobe Type Manager Font Driver in Microsoft Windows Vista SP2, Windows Server 2008 atmfd.dll in the Adobe Type Manager Font Driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "ATMFD.dll Elevation of Privilege Vulnerability."
nvd
CVE-2022-23285P2HIGHCVSS 8.8v20h2v21h1+4 more2022-03-09
CVE-2022-23285 [HIGH] CVE-2022-23285: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
Microsoft Windows 10 vulnerabilities | cvebase