Microsoft Windows 10 1809 vulnerabilities
2,099 known vulnerabilities affecting microsoft/windows_10_1809.
Total CVEs
2,099
CISA KEV
100
actively exploited
Public exploits
62
Exploited in wild
111
Severity breakdown
CRITICAL63HIGH1493MEDIUM535LOW8
Vulnerabilities
Page 45 of 105
CVE-2026-20930P3HIGHCVSS 7.8fixed in 10.0.17763.86442026-04-14
CVE-2026-20930 [HIGH] CWE-362 CVE-2026-20930: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42979P3HIGHCVSS 7.8fixed in 10.0.17763.88802026-06-09
CVE-2026-42979 [HIGH] CWE-362 CVE-2026-42979: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42977P3HIGHCVSS 7.8fixed in 10.0.17763.88802026-06-09
CVE-2026-42977 [HIGH] CWE-362 CVE-2026-42977: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50457P3HIGHCVSS 7.8fixed in 10.0.17763.90202026-07-14
CVE-2026-50457 [HIGH] CWE-362 CVE-2026-50457: Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54125P3HIGHCVSS 7.8fixed in 10.0.17763.90202026-07-14
CVE-2026-54125 [HIGH] CWE-362 CVE-2026-54125: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50427P3HIGHCVSS 7.8fixed in 10.0.17763.90202026-07-14
CVE-2026-50427 [HIGH] CWE-362 CVE-2026-50427: Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges local
Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58628P3HIGHCVSS 7.8fixed in 10.0.17763.90202026-07-14
CVE-2026-58628 [HIGH] CWE-362 CVE-2026-58628: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26168P3HIGHCVSS 7.8fixed in 10.0.17763.86442026-04-14
CVE-2026-26168 [HIGH] CWE-362 CVE-2026-26168: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26167P3HIGHCVSS 7.8fixed in 10.0.17763.86442026-04-14
CVE-2026-26167 [HIGH] CWE-362 CVE-2026-26167: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42991P3HIGHCVSS 7.8fixed in 10.0.17763.88802026-06-09
CVE-2026-42991 [HIGH] CWE-362 CVE-2026-42991: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58526P3HIGHCVSS 7.8fixed in 10.0.17763.90202026-07-14
CVE-2026-58526 [HIGH] CWE-362 CVE-2026-58526: Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.
Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-28238P3HIGHCVSS 7.5fixed in 10.0.17763.42522023-04-11
CVE-2023-28238 [HIGH] CWE-591 CVE-2023-28238: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2026-58627P3HIGHCVSS 7.5fixed in 10.0.17763.90202026-07-14
CVE-2026-58627 [HIGH] CWE-400 CVE-2026-58627: Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny ser
Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-45639P3HIGHCVSS 7.5fixed in 10.0.17763.88802026-06-09
CVE-2026-45639 [HIGH] CWE-125 CVE-2026-45639: Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a net
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-42908P3HIGHCVSS 7.5fixed in 10.0.17763.88802026-06-09
CVE-2026-42908 [HIGH] CWE-125 CVE-2026-42908: Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a net
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-58539P3HIGHCVSS 7.5fixed in 10.0.17763.90202026-07-14
CVE-2026-58539 [HIGH] CWE-125 CVE-2026-58539: Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a net
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-50463P3HIGHCVSS 7.5fixed in 10.0.17763.90202026-07-14
CVE-2026-50463 [HIGH] CWE-125 CVE-2026-50463: Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a
Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-57979P3HIGHCVSS 7.5fixed in 10.0.17763.90202026-07-14
CVE-2026-57979 [HIGH] CWE-125 CVE-2026-57979: Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a net
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2022-35751P3HIGHCVSS 7.8fixed in 10.0.17763.32872023-05-31
CVE-2022-35751 [HIGH] CVE-2022-35751: Windows Hyper-V Elevation of Privilege Vulnerability
Windows Hyper-V Elevation of Privilege Vulnerability
nvd
CVE-2026-20844P3HIGHCVSS 7.4fixed in 10.0.17763.82762026-01-13
CVE-2026-20844 [HIGH] CWE-362 CVE-2026-20844: Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges loc
Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.
nvd