cbcvebase.

Microsoft Windows 10 1809 vulnerabilities

2,099 known vulnerabilities affecting microsoft/windows_10_1809.

Total CVEs
2,099
CISA KEV
100
actively exploited
Public exploits
62
Exploited in wild
111
Severity breakdown
CRITICAL63HIGH1493MEDIUM535LOW8

Vulnerabilities

Page 23 of 105
CVE-2024-38045P3HIGHCVSS 8.1fixed in 10.0.17763.62932024-09-10
CVE-2024-38045 [HIGH] CWE-122 CVE-2024-38045: Windows TCP/IP Remote Code Execution Vulnerability Windows TCP/IP Remote Code Execution Vulnerability
nvd
CVE-2024-49124P3HIGHCVSS 8.1fixed in 10.0.17763.66592024-12-12
CVE-2024-49124 [HIGH] CWE-362 CVE-2024-49124: Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability
nvd
CVE-2025-62472P3HIGHCVSS 7.8fixed in 10.0.17763.81462025-12-09
CVE-2025-62472 [HIGH] CWE-416 CVE-2025-62472: Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attac Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-49127P3HIGHCVSS 8.1fixed in 10.0.17763.66592024-12-12
CVE-2024-49127 [HIGH] CWE-416 CVE-2024-49127: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2025-29810P3HIGHCVSS 7.5fixed in 10.0.17763.71362025-04-08
CVE-2025-29810 [HIGH] CWE-284 CVE-2025-29810: Improper access control in Active Directory Domain Services allows an authorized attacker to elevate Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-42900P3HIGHCVSS 8.1fixed in 10.0.17763.90202026-07-14
CVE-2026-42900 [HIGH] CWE-362 CVE-2026-42900: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2026-50348P3HIGHCVSS 8.1fixed in 10.0.17763.90202026-07-14
CVE-2026-50348 [HIGH] CWE-362 CVE-2026-50348: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2026-20922P3HIGHCVSS 7.8fixed in 10.0.17763.82762026-01-13
CVE-2026-20922 [HIGH] CWE-122 CVE-2026-20922: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2026-50452P3HIGHCVSS 8.1fixed in 10.0.17763.90202026-07-14
CVE-2026-50452 [HIGH] CWE-362 CVE-2026-50452: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2026-50683P3HIGHCVSS 8.0fixed in 10.0.17763.90202026-07-14
CVE-2026-50683 [HIGH] CWE-122 CVE-2026-50683: Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privilege Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.
nvd
CVE-2024-26218P3HIGHCVSS 7.8fixed in 10.0.17763.56962024-04-09
CVE-2024-26218 [HIGH] CWE-367 CVE-2024-26218: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2026-20848P3HIGHCVSS 7.5fixed in 10.0.17763.82762026-01-13
CVE-2026-20848 [HIGH] CWE-362 CVE-2026-20848: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-50685P3HIGHCVSS 7.5fixed in 10.0.17763.90202026-07-14
CVE-2026-50685 [HIGH] CWE-415 CVE-2026-50685: Double free in Windows DHCP Server allows an authorized attacker to execute code over a network. Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.
nvd
CVE-2026-58608P3HIGHCVSS 7.5fixed in 10.0.17763.90202026-07-14
CVE-2026-58608 [HIGH] CWE-362 CVE-2026-58608: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.
nvd
CVE-2024-21310P3HIGHCVSS 7.8fixed in 10.0.17763.53292024-01-09
CVE-2024-21310 [HIGH] CWE-197 CVE-2024-21310: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-55681P3HIGHCVSS 7.8fixed in 10.0.17763.79192025-10-14
CVE-2025-55681 [HIGH] CWE-125 CVE-2025-55681: Out-of-bounds read in Windows DWM allows an authorized attacker to elevate privileges locally. Out-of-bounds read in Windows DWM allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-38054P3HIGHCVSS 7.8fixed in 10.0.17763.60542024-07-09
CVE-2024-38054 [HIGH] CWE-122 CVE-2024-38054: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-21369P3HIGHCVSS 8.8fixed in 10.0.17763.54582024-02-13
CVE-2024-21369 [HIGH] CWE-122 CVE-2024-21369: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21350P3HIGHCVSS 8.8fixed in 10.0.17763.54582024-02-13
CVE-2024-21350 [HIGH] CWE-190 CVE-2024-21350: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-43519P3HIGHCVSS 8.8fixed in 10.0.17763.64142024-10-08
CVE-2024-43519 [HIGH] CWE-197 CVE-2024-43519: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
Microsoft Windows 10 1809 vulnerabilities | cvebase