cbcvebase.

Microsoft Windows 10 1507 vulnerabilities

1,047 known vulnerabilities affecting microsoft/windows_10_1507.

Total CVEs
1,047
CISA KEV
74
actively exploited
Public exploits
44
Exploited in wild
83
Severity breakdown
CRITICAL32HIGH730MEDIUM280LOW5

Vulnerabilities

Page 45 of 53
CVE-2025-47980P4MEDIUMCVSS 6.2fixed in 10.0.10240.210732025-07-08
CVE-2025-47980 [MEDIUM] CWE-200 CVE-2025-47980: Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an un Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker to disclose information locally.
nvd
CVE-2023-24900P4MEDIUMCVSS 5.9fixed in 10.0.10240.199262023-05-09
CVE-2023-24900 [MEDIUM] CWE-125 CVE-2023-24900: Windows NTLM Security Support Provider Information Disclosure Vulnerability Windows NTLM Security Support Provider Information Disclosure Vulnerability
nvd
CVE-2025-32722P4MEDIUMCVSS 5.5fixed in 10.0.10240.210342025-06-10
CVE-2025-32722 [MEDIUM] CWE-284 CVE-2025-32722: Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose inf Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2025-55338P4MEDIUMCVSS 4.6fixed in 10.0.10240.211612025-10-14
CVE-2025-55338 [MEDIUM] CWE-1310 CVE-2025-55338: Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a s Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-54101P4MEDIUMCVSS 4.8fixed in 10.0.10240.211282025-09-09
CVE-2025-54101 [MEDIUM] CWE-416 CVE-2025-54101: Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network. Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network.
nvd
CVE-2025-47160P4MEDIUMCVSS 5.4fixed in 10.0.10240.210342025-06-10
CVE-2025-47160 [MEDIUM] CWE-693 CVE-2025-47160: Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security f Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2025-55325P4MEDIUMCVSS 5.5fixed in 10.0.10240.211612025-10-14
CVE-2025-55325 [MEDIUM] CWE-126 CVE-2025-55325: Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose in Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-55229P4MEDIUMCVSS 5.3fixed in 10.0.10240.210142025-08-21
CVE-2025-55229 [MEDIUM] CWE-347 CVE-2025-55229: Improper verification of cryptographic signature in Windows Certificates allows an unauthorized atta Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2023-20569P4MEDIUMCVSS 4.7fixed in 10.0.10240.201072023-08-08
CVE-2023-20569 [MEDIUM] CWE-203 CVE-2023-20569: A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the retur A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
nvd
CVE-2025-21202P4MEDIUMCVSS 6.1fixed in 10.0.10240.208902025-01-14
CVE-2025-21202 [MEDIUM] CWE-284 CVE-2025-21202: Windows Recovery Environment Agent Elevation of Privilege Vulnerability Windows Recovery Environment Agent Elevation of Privilege Vulnerability
nvd
CVE-2025-29974P4MEDIUMCVSS 5.7fixed in 10.0.10240.210142025-05-13
CVE-2025-29974 [MEDIUM] CWE-125 CVE-2025-29974: Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an adjacent network.
nvd
CVE-2023-35336P4MEDIUMCVSS 5.4fixed in 10.0.10240.200482023-07-11
CVE-2023-35336 [MEDIUM] CWE-20 CVE-2023-35336: Windows MSHTML Platform Security Feature Bypass Vulnerability Windows MSHTML Platform Security Feature Bypass Vulnerability
nvd
CVE-2025-59211P4MEDIUMCVSS 5.5fixed in 10.0.10240.211612025-10-14
CVE-2025-59211 [MEDIUM] CWE-200 CVE-2025-59211: Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
nvd
CVE-2025-62209P4MEDIUMCVSS 5.5fixed in 10.0.10240.211612025-11-11
CVE-2025-62209 [MEDIUM] CWE-532 CVE-2025-62209: Insertion of sensitive information into log file in Windows License Manager allows an authorized att Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
nvd
CVE-2025-62208P4MEDIUMCVSS 5.5fixed in 10.0.10240.211612025-11-11
CVE-2025-62208 [MEDIUM] CWE-532 CVE-2025-62208: Insertion of sensitive information into log file in Windows License Manager allows an authorized att Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
nvd
CVE-2023-28226P4MEDIUMCVSS 5.3fixed in 10.0.10240.198692023-04-11
CVE-2023-28226 [MEDIUM] CWE-347 CVE-2023-28226: Windows Enroll Engine Security Feature Bypass Vulnerability Windows Enroll Engine Security Feature Bypass Vulnerability
nvd
CVE-2023-35377P4MEDIUMCVSS 6.5fixed in 10.0.10240.201072023-08-08
CVE-2023-35377 [MEDIUM] CWE-20 CVE-2023-35377: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2023-35376P4MEDIUMCVSS 6.5fixed in 10.0.10240.201072023-08-08
CVE-2023-35376 [MEDIUM] CWE-20 CVE-2023-35376: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2023-28266P4MEDIUMCVSS 5.5fixed in 10.0.10240.198692023-04-11
CVE-2023-28266 [MEDIUM] CWE-126 CVE-2023-28266: Windows Common Log File System Driver Information Disclosure Vulnerability Windows Common Log File System Driver Information Disclosure Vulnerability
nvd
CVE-2025-21226P4MEDIUMCVSS 6.6fixed in 10.0.10240.208902025-01-14
CVE-2025-21226 [MEDIUM] CWE-125 CVE-2025-21226: Windows Digital Media Elevation of Privilege Vulnerability Windows Digital Media Elevation of Privilege Vulnerability
nvd
Microsoft Windows 10 1507 vulnerabilities | cvebase