Microsoft Windows 10 1809 vulnerabilities
2,099 known vulnerabilities affecting microsoft/windows_10_1809.
Total CVEs
2,099
CISA KEV
100
actively exploited
Public exploits
62
Exploited in wild
111
Severity breakdown
CRITICAL63HIGH1493MEDIUM535LOW8
Vulnerabilities
Page 10 of 105
CVE-2026-54995P2CRITICALCVSS 9.8fixed in 10.0.17763.90202026-07-14
CVE-2026-54995 [CRITICAL] CWE-416 CVE-2026-54995: Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to ex
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-33064P2HIGHCVSS 8.8fixed in 10.0.17763.74342025-06-10
CVE-2025-33064 [HIGH] CWE-122 CVE-2025-33064: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
nvd
CVE-2026-50666P2HIGHCVSS 8.8fixed in 10.0.17763.90202026-07-14
CVE-2026-50666 [HIGH] CWE-416 CVE-2026-50666: Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2023-32015P2CRITICALCVSS 9.8fixed in 10.0.17763.44992023-06-14
CVE-2023-32015 [CRITICAL] CWE-20 CVE-2023-32015: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-28250P2CRITICALCVSS 9.8fixed in 10.0.17763.42522023-04-11
CVE-2023-28250 [CRITICAL] CWE-191 CVE-2023-28250: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-29363P2CRITICALCVSS 9.8fixed in 10.0.17763.44992023-06-14
CVE-2023-29363 [CRITICAL] CWE-122 CVE-2023-29363: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-32014P2CRITICALCVSS 9.8fixed in 10.0.17763.44992023-06-14
CVE-2023-32014 [CRITICAL] CWE-191 CVE-2023-32014: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-35365P2CRITICALCVSS 9.8fixed in 10.0.17763.46452023-07-11
CVE-2023-35365 [CRITICAL] CWE-20 CVE-2023-35365: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2023-35366P2CRITICALCVSS 9.8fixed in 10.0.17763.46452023-07-11
CVE-2023-35366 [CRITICAL] CWE-20 CVE-2023-35366: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2023-35367P2CRITICALCVSS 9.8fixed in 10.0.17763.46452023-07-11
CVE-2023-35367 [CRITICAL] CWE-20 CVE-2023-35367: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2023-36911P2CRITICALCVSS 9.8fixed in 10.0.17763.47372023-08-08
CVE-2023-36911 [CRITICAL] CWE-190 CVE-2023-36911: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2025-26670P2HIGHCVSS 8.1fixed in 10.0.17763.71362025-04-08
CVE-2025-26670 [HIGH] CWE-416 CVE-2025-26670: Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attack
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-25177P2HIGHCVSS 8.8fixed in 10.0.17763.85112026-03-10
CVE-2026-25177 [HIGH] CWE-641 CVE-2026-25177: Improper restriction of names for files and other resources in Active Directory Domain Services allo
Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-54121P2HIGHCVSS 8.8fixed in 10.0.17763.90202026-07-14
CVE-2026-54121 [HIGH] CWE-285 CVE-2026-54121: Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacke
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-48564P2HIGHCVSS 8.8fixed in 10.0.17763.90202026-07-14
CVE-2026-48564 [HIGH] CWE-122 CVE-2026-48564: Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
nvd
CVE-2026-50444P2HIGHCVSS 8.8fixed in 10.0.17763.90202026-07-14
CVE-2026-50444 [HIGH] CWE-306 CVE-2026-50444: Missing authentication for critical function in Windows Server Update Service allows an authorized a
Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-50502P2HIGHCVSS 8.8fixed in 10.0.17763.90202026-07-14
CVE-2026-50502 [HIGH] CWE-1220 CVE-2026-50502: Insufficient granularity of access control in Windows Event Logging Service allows an authorized att
Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.
nvd
CVE-2022-35744P2CRITICALCVSS 9.8fixed in 10.0.17763.32872023-05-31
CVE-2022-35744 [CRITICAL] CVE-2022-35744: Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
nvd
CVE-2023-21803P2CRITICALCVSS 9.8fixed in 10.0.17763.40102023-02-14
CVE-2023-21803 [CRITICAL] CWE-190 CVE-2023-21803: Windows iSCSI Discovery Service Remote Code Execution Vulnerability
Windows iSCSI Discovery Service Remote Code Execution Vulnerability
nvd
CVE-2023-36606P3HIGHCVSS 7.5fixed in 10.0.17763.49742023-10-10
CVE-2023-36606 [HIGH] CWE-400 CVE-2023-36606: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd