cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 99 of 141
CVE-2020-1077P3HIGHCVSS 7.8v1607v1709+4 more2020-05-21
CVE-2020-1077 [HIGH] CVE-2020-1077: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects i An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1086, CVE-2020-1090, CVE-2020-1125, CVE-2020-1139, CVE-2020-1149, CVE-2020-1151, CVE-2020-1155, CVE-2020-1156, CVE-2020-1157, CVE-2020-1158, CVE-2020-1164.
nvd
CVE-2020-0896P3HIGHCVSS 7.8v1607v1709+4 more2020-03-12
CVE-2020-0896 [HIGH] CWE-65 CVE-2020-0896: An elevation of privilege vulnerability exists when Windows improperly handles hard links, aka 'Wind An elevation of privilege vulnerability exists when Windows improperly handles hard links, aka 'Windows Hard Link Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0840, CVE-2020-0841, CVE-2020-0849.
nvd
CVE-2020-1353P3HIGHCVSS 7.8v1607v1709+5 more2020-07-14
CVE-2020-1353 [HIGH] CVE-2020-1353: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects i An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1249, CVE-2020-1370, CVE-2020-1399, CVE-2020-1404, CVE-2020-1413, CVE-2020-1414, CVE-2020-1415, CVE-2020-1422.
nvd
CVE-2020-1399P3HIGHCVSS 7.8v1607v1709+5 more2020-07-14
CVE-2020-1399 [HIGH] CVE-2020-1399: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects i An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1249, CVE-2020-1353, CVE-2020-1370, CVE-2020-1404, CVE-2020-1413, CVE-2020-1414, CVE-2020-1415, CVE-2020-1422.
nvd
CVE-2020-1090P3HIGHCVSS 7.8v1607v1709+4 more2020-05-21
CVE-2020-1090 [HIGH] CVE-2020-1090: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects i An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1077, CVE-2020-1086, CVE-2020-1125, CVE-2020-1139, CVE-2020-1149, CVE-2020-1151, CVE-2020-1155, CVE-2020-1156, CVE-2020-1157, CVE-2020-1158, CVE-2020-1164.
nvd
CVE-2020-1086P3HIGHCVSS 7.8v1607v1709+4 more2020-05-21
CVE-2020-1086 [HIGH] CVE-2020-1086: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects i An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1077, CVE-2020-1090, CVE-2020-1125, CVE-2020-1139, CVE-2020-1149, CVE-2020-1151, CVE-2020-1155, CVE-2020-1156, CVE-2020-1157, CVE-2020-1158, CVE-2020-1164.
nvd
CVE-2020-1265P3HIGHCVSS 7.8v1903v19092020-06-09
CVE-2020-1265 [HIGH] CVE-2020-1265: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects i An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1235, CVE-2020-1282, CVE-2020-1304, CVE-2020-1306, CVE-2020-1334.
nvd
CVE-2020-1334P3HIGHCVSS 7.8v1607v1709+5 more2020-06-09
CVE-2020-1334 [HIGH] CVE-2020-1334: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects i An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE-2020-1282, CVE-2020-1304, CVE-2020-1306.
nvd
CVE-2022-29113P3HIGHCVSS 7.8v20h2v21h1+3 more2022-05-10
CVE-2022-29113 [HIGH] CWE-362 CVE-2022-29113: Windows Digital Media Receiver Elevation of Privilege Vulnerability Windows Digital Media Receiver Elevation of Privilege Vulnerability
nvd
CVE-2020-1560P3HIGHCVSS 7.3v1709v1803+4 more2020-08-17
CVE-2020-1560 [HIGH] CVE-2020-1560: A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handle A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Exploitation of the vuln
nvd
CVE-2021-31205P3MEDIUMCVSS 6.5v20h2v20042021-05-11
CVE-2021-31205 [MEDIUM] CVE-2021-31205: Windows SMB Client Security Feature Bypass Vulnerability Windows SMB Client Security Feature Bypass Vulnerability
nvd
CVE-2017-8592P3MEDIUMCVSS 6.5v1511v1607+1 more2017-07-11
CVE-2017-8592 [MEDIUM] CWE-200 CVE-2017-8592: Microsoft browsers on when Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows Microsoft browsers on when Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows RT 8.1, and Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a security feature bypass vulnerability when they improperly handle redirect requests, aka "Microsoft Browser Security Feature Bypass".
nvd
CVE-2018-8394P3MEDIUMCVSS 6.5v1607v1703+12 more2018-08-15
CVE-2018-8394 [MEDIUM] CWE-200 CVE-2018-8394: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Window
nvd
CVE-2018-8398P3MEDIUMCVSS 6.5v1607v1703+2 more2018-08-15
CVE-2018-8398 [MEDIUM] CVE-2018-8398: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Wi
nvd
CVE-2017-8533P3MEDIUMCVSS 6.5v1511v1607+1 more2017-06-15
CVE-2017-8533 [MEDIUM] CVE-2017-8533: Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows improper disclosure of memory contents, aka "Graphics Uniscribe Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0286, CVE-2017-0287, CVE-2017-0
nvd
CVE-2021-38624P3MEDIUMCVSS 6.5v20h2v21h1+3 more2021-09-15
CVE-2021-38624 [MEDIUM] CWE-639 CVE-2021-38624: Windows Key Storage Provider Security Feature Bypass Vulnerability Windows Key Storage Provider Security Feature Bypass Vulnerability
nvd
CVE-2017-8532P3MEDIUMCVSS 6.5v1511v1607+1 more2017-06-15
CVE-2017-8532 [MEDIUM] CVE-2017-8532: Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows improper disclosure of memory contents, aka "Graphics Uniscribe Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0286, CVE-2017-0287, CVE-2017-0
nvd
CVE-2022-21883P3HIGHCVSS 7.5v20h2v21h1+4 more2022-01-11
CVE-2022-21883 [HIGH] CVE-2022-21883: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2017-8531P3MEDIUMCVSS 6.5v1511v1607+1 more2017-06-15
CVE-2017-8531 [MEDIUM] CVE-2017-8531: Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016, Microsoft Office 2007 Service Pack 3, and Microsoft Office 2010 Service Pack 2 allows improper disclosure of memory contents, aka "Graphics Uniscribe Information Disclosure Vulnera
nvd
CVE-2022-21848P3HIGHCVSS 7.5v20h2v21h1+4 more2022-01-11
CVE-2022-21848 [HIGH] CVE-2022-21848: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
Microsoft Windows 10 vulnerabilities | cvebase