cbcvebase.

Microsoft Windows 10 1809 vulnerabilities

2,099 known vulnerabilities affecting microsoft/windows_10_1809.

Total CVEs
2,099
CISA KEV
100
actively exploited
Public exploits
62
Exploited in wild
111
Severity breakdown
CRITICAL63HIGH1493MEDIUM535LOW8

Vulnerabilities

Page 22 of 105
CVE-2023-36577P3HIGHCVSS 8.8fixed in 10.0.17763.49742023-10-10
CVE-2023-36577 [HIGH] CWE-122 CVE-2023-36577: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2023-28297P3HIGHCVSS 8.8fixed in 10.0.17763.38872023-04-11
CVE-2023-28297 [HIGH] CWE-416 CVE-2023-28297: Windows Remote Procedure Call Service (RPCSS) Elevation of Privilege Vulnerability Windows Remote Procedure Call Service (RPCSS) Elevation of Privilege Vulnerability
nvd
CVE-2024-21367P3HIGHCVSS 8.8fixed in 10.0.17763.54582024-02-13
CVE-2024-21367 [HIGH] CWE-122 CVE-2024-21367: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21375P3HIGHCVSS 8.8fixed in 10.0.17763.54582024-02-13
CVE-2024-21375 [HIGH] CWE-416 CVE-2024-21375: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21361P3HIGHCVSS 8.8fixed in 10.0.17763.54582024-02-13
CVE-2024-21361 [HIGH] CWE-122 CVE-2024-21361: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21368P3HIGHCVSS 8.8fixed in 10.0.17763.54582024-02-13
CVE-2024-21368 [HIGH] CWE-122 CVE-2024-21368: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21359P3HIGHCVSS 8.8fixed in 10.0.17763.54582024-02-13
CVE-2024-21359 [HIGH] CWE-122 CVE-2024-21359: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21391P3HIGHCVSS 8.8fixed in 10.0.17763.54582024-02-13
CVE-2024-21391 [HIGH] CWE-197 CVE-2024-21391: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21352P3HIGHCVSS 8.8fixed in 10.0.17763.54582024-02-13
CVE-2024-21352 [HIGH] CWE-197 CVE-2024-21352: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2025-59199P3HIGHCVSS 7.8fixed in 10.0.17763.79192025-10-14
CVE-2025-59199 [HIGH] CWE-284 CVE-2025-59199: Improper access control in Software Protection Platform (SPP) allows an authorized attacker to eleva Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20872P3MEDIUMCVSS 6.5fixed in 10.0.17763.82762026-01-13
CVE-2026-20872 [MEDIUM] CWE-73 CVE-2026-20872: External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spo External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2024-43517P3HIGHCVSS 8.8fixed in 10.0.17763.64142024-10-08
CVE-2024-43517 [HIGH] CWE-122 CVE-2024-43517: Microsoft ActiveX Data Objects Remote Code Execution Vulnerability Microsoft ActiveX Data Objects Remote Code Execution Vulnerability
nvd
CVE-2024-38131P3HIGHCVSS 8.8fixed in 10.0.17763.61892024-08-13
CVE-2024-38131 [HIGH] CWE-591 CVE-2024-38131: Clipboard Virtual Channel Extension Remote Code Execution Vulnerability Clipboard Virtual Channel Extension Remote Code Execution Vulnerability
nvd
CVE-2024-38053P3HIGHCVSS 8.8fixed in 10.0.17763.60542024-07-09
CVE-2024-38053 [HIGH] CWE-416 CVE-2024-38053: Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability
nvd
CVE-2024-43518P3HIGHCVSS 8.8fixed in 10.0.17763.64142024-10-08
CVE-2024-43518 [HIGH] CWE-122 CVE-2024-43518: Windows Telephony Server Remote Code Execution Vulnerability Windows Telephony Server Remote Code Execution Vulnerability
nvd
CVE-2025-29964P3HIGHCVSS 8.8fixed in 10.0.17763.73142025-05-13
CVE-2025-29964 [HIGH] CWE-122 CVE-2025-29964: Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a n Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-29963P3HIGHCVSS 8.8fixed in 10.0.17763.73142025-05-13
CVE-2025-29963 [HIGH] CWE-122 CVE-2025-29963: Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a n Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-49170P3HIGHCVSS 7.8fixed in 10.0.17763.90202026-07-14
CVE-2026-49170 [HIGH] CWE-285 CVE-2026-49170: Insufficient granularity of access control in Windows StateRepository API allows an authorized attac Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-38049P3HIGHCVSS 8.1fixed in 10.0.17763.60542024-07-09
CVE-2024-38049 [HIGH] CWE-73 CVE-2024-38049: Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability
nvd
CVE-2026-42989P3HIGHCVSS 7.8fixed in 10.0.17763.88802026-06-09
CVE-2026-42989 [HIGH] CWE-59 CVE-2026-42989: Improper link resolution before file access ('link following') in Winlogon allows an authorized atta Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows 10 1809 vulnerabilities | cvebase