cbcvebase.

Microsoft Windows 10 Version 1507 vulnerabilities

2,277 known vulnerabilities affecting microsoft/windows_10_version_1507.

Total CVEs
2,277
CISA KEV
89
actively exploited
Public exploits
75
Exploited in wild
118
Severity breakdown
CRITICAL69HIGH1630MEDIUM570LOW8

Vulnerabilities

Page 70 of 114
CVE-2023-36394P3HIGHCVSS 7.0≥ 10.0.10240.0, < 10.0.10240.203082023-11-14
CVE-2023-36394 [HIGH] CWE-59 CVE-2023-36394: Windows Search Service Elevation of Privilege Vulnerability Windows Search Service Elevation of Privilege Vulnerability
nvd
CVE-2025-53140P3HIGHCVSS 7.0≥ 10.0.10240.0, < 10.0.10240.211002025-08-12
CVE-2025-53140 [HIGH] CWE-416 CVE-2025-53140: Use after free in Kernel Transaction Manager allows an authorized attacker to elevate privileges loc Use after free in Kernel Transaction Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55678P3HIGHCVSS 7.0≥ 10.0.10240.0, < 10.0.10240.211612025-10-14
CVE-2025-55678 [HIGH] CWE-416 CVE-2025-55678: Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59259P3MEDIUMCVSS 6.5≥ 10.0.10240.0, < 10.0.10240.211612025-10-14
CVE-2025-59259 [MEDIUM] CWE-1287 CVE-2025-59259: Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an auth Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
nvd
CVE-2020-1577P3MEDIUMCVSS 6.5≥ 10.0.0, < publication2020-08-17
CVE-2020-1577 [MEDIUM] CVE-2020-1577: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted
nvd
CVE-2025-59185P3MEDIUMCVSS 6.5≥ 10.0.10240.0, < 10.0.10240.211612025-10-14
CVE-2025-59185 [MEDIUM] CWE-73 CVE-2025-59185: External control of file name or path in Windows Core Shell allows an unauthorized attacker to perfo External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2025-59244P3MEDIUMCVSS 6.5≥ 10.0.10240.0, < 10.0.10240.211612025-10-14
CVE-2025-59244 [MEDIUM] CWE-73 CVE-2025-59244: External control of file name or path in Windows Core Shell allows an unauthorized attacker to perfo External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2024-21433P3HIGHCVSS 7.0≥ 10.0.10240.0, < 10.0.10240.205262024-03-12
CVE-2024-21433 [HIGH] CWE-367 CVE-2024-21433: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2025-21181P3HIGHCVSS 7.5≥ 10.0.10240.0, < 10.0.10240.209152025-02-11
CVE-2025-21181 [HIGH] CWE-400 CVE-2025-21181: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2020-1552P3HIGHCVSS 7.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1552 [HIGH] CVE-2020-1552: An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handl An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulner
nvd
CVE-2024-38126P3HIGHCVSS 7.5≥ 10.0.10240.0, < 10.0.10240.207512024-08-13
CVE-2024-38126 [HIGH] CWE-476 CVE-2024-38126: Windows Network Address Translation (NAT) Denial of Service Vulnerability Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2025-21300P3HIGHCVSS 7.5≥ 10.0.10240.0, < 10.0.10240.208902025-01-14
CVE-2025-21300 [HIGH] CWE-400 CVE-2025-21300: Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability
nvd
CVE-2024-38145P3HIGHCVSS 7.5≥ 10.0.10240.0, < 10.0.10240.207512024-08-13
CVE-2024-38145 [HIGH] CWE-476 CVE-2024-38145: Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
nvd
CVE-2024-38146P3HIGHCVSS 7.5≥ 10.0.10240.0, < 10.0.10240.207512024-08-13
CVE-2024-38146 [HIGH] CWE-476 CVE-2024-38146: Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
nvd
CVE-2024-21348P3HIGHCVSS 7.5≥ 10.0.10240.0, < 10.0.10240.204692024-02-13
CVE-2024-21348 [HIGH] CWE-122 CVE-2024-21348: Internet Connection Sharing (ICS) Denial of Service Vulnerability Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd
CVE-2020-17097P3HIGHCVSS 7.8≥ 10.0.10240.0, < publication2020-12-10
CVE-2020-17097 [HIGH] CVE-2020-17097: Windows Digital Media Receiver Elevation of Privilege Vulnerability Windows Digital Media Receiver Elevation of Privilege Vulnerability
nvd
CVE-2019-1045P3HIGHCVSS 7.8≥ 10.0.10240.0, < publication2019-06-12
CVE-2019-1045 [HIGH] CVE-2019-1045: An elevation of privilege vulnerability exists in the way that the Windows Network File System (NFS) An elevation of privilege vulnerability exists in the way that the Windows Network File System (NFS) handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addres
nvd
CVE-2020-1491P3HIGHCVSS 7.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1491 [HIGH] CVE-2020-1491: <p>An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Ser An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Service handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addre
nvd
CVE-2023-21701P3HIGHCVSS 7.5≥ 10.0.10240.0, < 10.0.10240.197472023-02-14
CVE-2023-21701 [HIGH] CWE-126 CVE-2023-21701: Microsoft Protected Extensible Authentication Protocol (PEAP) Denial of Service Vulnerability Microsoft Protected Extensible Authentication Protocol (PEAP) Denial of Service Vulnerability
nvd
CVE-2023-24901P3HIGHCVSS 7.5≥ 10.0.10240.0, < 10.0.10240.199262023-05-09
CVE-2023-24901 [HIGH] CWE-126 CVE-2023-24901: Windows NFS Portmapper Information Disclosure Vulnerability Windows NFS Portmapper Information Disclosure Vulnerability
nvd
Microsoft Windows 10 Version 1507 vulnerabilities | cvebase