cbcvebase.

Microsoft Windows 10 Version 1607 vulnerabilities

3,019 known vulnerabilities affecting microsoft/windows_10_version_1607.

Total CVEs
3,019
CISA KEV
102
actively exploited
Public exploits
82
Exploited in wild
134
Severity breakdown
CRITICAL95HIGH2175MEDIUM737LOW12

Vulnerabilities

Page 108 of 151
CVE-2025-29832P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.80662025-05-13
CVE-2025-29832 [MEDIUM] CWE-125 CVE-2025-29832: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-29835P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.80662025-05-13
CVE-2025-29835 [MEDIUM] CWE-125 CVE-2025-29835: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-55226P3MEDIUMCVSS 6.7≥ 10.0.14393.0, < 10.0.14393.84222025-09-09
CVE-2025-55226 [MEDIUM] CWE-362 CVE-2025-55226: Concurrent execution using shared resource with improper synchronization ('race condition') in Graph Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to execute code locally.
nvd
CVE-2026-27925P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.90602026-04-14
CVE-2026-27925 [MEDIUM] CWE-416 CVE-2026-27925: Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network.
nvd
CVE-2021-38665P4MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.14393.47702021-11-10
CVE-2021-38665 [MEDIUM] CVE-2021-38665: Remote Desktop Protocol Client Information Disclosure Vulnerability Remote Desktop Protocol Client Information Disclosure Vulnerability
nvd
CVE-2019-1025P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < publication2019-06-12
CVE-2019-1025 [MEDIUM] CVE-2019-1025: A denial of service vulnerability exists when Windows improperly handles objects in memory. An attac A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application or to convince a user to open a specif
nvd
CVE-2023-21677P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.56482023-01-10
CVE-2023-21677 [HIGH] CWE-822 CVE-2023-21677: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2023-21683P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.56482023-01-10
CVE-2023-21683 [HIGH] CWE-476 CVE-2023-21683: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2023-21527P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.56482023-01-10
CVE-2023-21527 [HIGH] CWE-191 CVE-2023-21527: Windows iSCSI Service Denial of Service Vulnerability Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2023-35330P4HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-35330 [HIGH] CWE-126 CVE-2023-35330: Windows Extended Negotiation Denial of Service Vulnerability Windows Extended Negotiation Denial of Service Vulnerability
nvd
CVE-2023-21811P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.57172023-02-14
CVE-2023-21811 [HIGH] CWE-126 CVE-2023-21811: Windows iSCSI Service Denial of Service Vulnerability Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2023-21700P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.57172023-02-14
CVE-2023-21700 [HIGH] CWE-476 CVE-2023-21700: Windows iSCSI Discovery Service Denial of Service Vulnerability Windows iSCSI Discovery Service Denial of Service Vulnerability
nvd
CVE-2023-21702P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.57172023-02-14
CVE-2023-21702 [HIGH] CWE-125 CVE-2023-21702: Windows iSCSI Service Denial of Service Vulnerability Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2022-38042P3HIGHCVSS 7.1≥ 10.0.14393.0, < 10.0.14393.54272022-10-11
CVE-2022-38042 [HIGH] CVE-2022-38042: Active Directory Domain Services Elevation of Privilege Vulnerability Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2022-26936P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-26936 [MEDIUM] CVE-2022-26936: Windows Server Service Information Disclosure Vulnerability Windows Server Service Information Disclosure Vulnerability
nvd
CVE-2019-1043P4MEDIUMCVSS 6.4≥ 10.0.14393.0, < publication2019-06-12
CVE-2019-1043 [MEDIUM] CVE-2019-1043: A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current
nvd
CVE-2022-22015P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-22015 [MEDIUM] CVE-2022-22015: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
nvd
CVE-2024-49082P4MEDIUMCVSS 6.8≥ 10.0.14393.0, < 10.0.14393.76062024-12-12
CVE-2024-49082 [MEDIUM] CWE-22 CVE-2024-49082: Windows File Explorer Information Disclosure Vulnerability Windows File Explorer Information Disclosure Vulnerability
nvd
CVE-2019-1014P4HIGHCVSS 7.0≥ 10.0.14393.0, < publication2019-06-12
CVE-2019-1014 [HIGH] CVE-2019-1014: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vul
nvd
CVE-2019-1017P4HIGHCVSS 7.0≥ 10.0.14393.0, < publication2019-06-12
CVE-2019-1017 [HIGH] CVE-2019-1017: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vul
nvd
Microsoft Windows 10 Version 1607 vulnerabilities | cvebase