Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27
Vulnerabilities
Page 93 of 141
CVE-2021-34459P3HIGHCVSS 7.8v20h2v21h1+4 more2021-07-16
CVE-2021-34459 [HIGH] CWE-269 CVE-2021-34459: Windows AppContainer Elevation Of Privilege Vulnerability
Windows AppContainer Elevation Of Privilege Vulnerability
nvd
CVE-2021-36973P3HIGHCVSS 7.8v20h2v21h1+4 more2021-09-15
CVE-2021-36973 [HIGH] CWE-269 CVE-2021-36973: Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability
Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability
nvd
CVE-2021-38630P3HIGHCVSS 7.8v20h2v21h1+4 more2021-09-15
CVE-2021-38630 [HIGH] CWE-269 CVE-2021-38630: Windows Event Tracing Elevation of Privilege Vulnerability
Windows Event Tracing Elevation of Privilege Vulnerability
nvd
CVE-2021-36966P3HIGHCVSS 7.8v20h2v21h1+3 more2021-09-15
CVE-2021-36966 [HIGH] CWE-269 CVE-2021-36966: Windows Subsystem for Linux Elevation of Privilege Vulnerability
Windows Subsystem for Linux Elevation of Privilege Vulnerability
nvd
CVE-2021-36964P3HIGHCVSS 7.8v20h2v21h1+4 more2021-09-15
CVE-2021-36964 [HIGH] CWE-269 CVE-2021-36964: Windows Event Tracing Elevation of Privilege Vulnerability
Windows Event Tracing Elevation of Privilege Vulnerability
nvd
CVE-2021-41339P3HIGHCVSS 7.8v20h2v21h1+2 more2021-10-13
CVE-2021-41339 [HIGH] CWE-269 CVE-2021-41339: Microsoft DWM Core Library Elevation of Privilege Vulnerability
Microsoft DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2021-36957P3HIGHCVSS 7.8v20h2v21h1+3 more2021-11-10
CVE-2021-36957 [HIGH] CWE-269 CVE-2021-36957: Windows Desktop Bridge Elevation of Privilege Vulnerability
Windows Desktop Bridge Elevation of Privilege Vulnerability
nvd
CVE-2021-42286P3HIGHCVSS 7.8v20h2v21h1+1 more2021-11-10
CVE-2021-42286 [HIGH] CWE-269 CVE-2021-42286: Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerabi
Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability
nvd
CVE-2021-41334P3HIGHCVSS 7.8v20h2v21h1+1 more2021-10-13
CVE-2021-41334 [HIGH] CWE-269 CVE-2021-41334: Windows Desktop Bridge Elevation of Privilege Vulnerability
Windows Desktop Bridge Elevation of Privilege Vulnerability
nvd
CVE-2017-0055P3MEDIUMCVSS 6.1v1511v16072017-03-17
CVE-2017-0055 [MEDIUM] CWE-79 CVE-2017-0055: Microsoft Internet Information Server (IIS) in Windows Vista SP2; Windows Server 2008 SP2 and R2; Wi
Microsoft Internet Information Server (IIS) in Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to perform cross-site scripting and run script with local user privileges via a crafted request, a
nvd
CVE-2023-21820P3HIGHCVSS 7.4fixed in 10.0.10240.197472023-02-14
CVE-2023-21820 [HIGH] CWE-126 CVE-2023-21820: Windows Distributed File System (DFS) Remote Code Execution Vulnerability
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
nvd
CVE-2021-24082P3MEDIUMCVSS 6.5v20h2v1607+4 more2021-02-25
CVE-2021-24082 [MEDIUM] CVE-2021-24082: Microsoft.PowerShell.Utility Module WDAC Security Feature Bypass Vulnerability
Microsoft.PowerShell.Utility Module WDAC Security Feature Bypass Vulnerability
nvd
CVE-2021-28444P3MEDIUMCVSS 6.5v20h2v1607+4 more2021-04-13
CVE-2021-28444 [MEDIUM] CVE-2021-28444: Windows Hyper-V Security Feature Bypass Vulnerability
Windows Hyper-V Security Feature Bypass Vulnerability
nvd
CVE-2021-40460P3MEDIUMCVSS 6.5v20h2v21h1+4 more2021-10-13
CVE-2021-40460 [MEDIUM] CVE-2021-40460: Windows Remote Procedure Call Runtime Security Feature Bypass Vulnerability
Windows Remote Procedure Call Runtime Security Feature Bypass Vulnerability
nvd
CVE-2022-44673P3HIGHCVSS 7.0v20h2v21h1+4 more2022-12-13
CVE-2022-44673 [HIGH] CVE-2022-44673: Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
nvd
CVE-2019-0758P3MEDIUMCVSS 6.5v1607v1703+4 more2019-05-16
CVE-2019-0758 [MEDIUM] CVE-2019-0758: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0882, CVE-2019-0961.
nvd
CVE-2022-30196P3HIGHCVSS 8.2v20h2v21h1+1 more2022-09-13
CVE-2022-30196 [HIGH] CVE-2022-30196: Windows Secure Channel Denial of Service Vulnerability
Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2022-23286P3HIGHCVSS 7.0v20h2v21h1+3 more2022-03-09
CVE-2022-23286 [HIGH] CVE-2022-23286: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-26831P3HIGHCVSS 7.5v20h2v21h1+4 more2022-04-15
CVE-2022-26831 [HIGH] CVE-2022-26831: Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
nvd
CVE-2016-7271P3HIGHCVSS 7.8v1511v16072016-12-20
CVE-2016-7271 [HIGH] CWE-264 CVE-2016-7271: The Secure Kernel Mode implementation in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Serve
The Secure Kernel Mode implementation in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows local users to bypass the virtual trust level (VTL) protection mechanism via a crafted application, aka "Secure Kernel Mode Elevation of Privilege Vulnerability."
nvd