cbcvebase.

Microsoft Windows 10 Version 1607 vulnerabilities

3,019 known vulnerabilities affecting microsoft/windows_10_version_1607.

Total CVEs
3,019
CISA KEV
102
actively exploited
Public exploits
82
Exploited in wild
133
Severity breakdown
CRITICAL95HIGH2175MEDIUM737LOW12

Vulnerabilities

Page 43 of 151
CVE-2025-24063P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.80662025-05-13
CVE-2025-24063 [HIGH] CWE-122 CVE-2025-24063: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-60714P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.85942025-11-11
CVE-2025-60714 [HIGH] CWE-122 CVE-2025-60714: Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally. Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally.
nvd
CVE-2023-35632P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.65292023-12-12
CVE-2023-35632 [HIGH] CWE-190 CVE-2023-35632: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd
CVE-2026-35421P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.91402026-05-12
CVE-2026-35421 [HIGH] CWE-122 CVE-2026-35421: Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally. Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally.
nvd
CVE-2023-38142P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.62522023-09-12
CVE-2023-38142 [HIGH] CWE-190 CVE-2023-38142: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-24495P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.50662022-04-15
CVE-2022-24495 [HIGH] CVE-2022-24495: Windows Direct Show Remote Code Execution Vulnerability Windows Direct Show Remote Code Execution Vulnerability
nvd
CVE-2024-30098P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.85192024-07-09
CVE-2024-30098 [HIGH] CWE-327 CVE-2024-30098: Windows Cryptographic Services Security Feature Bypass Vulnerability Windows Cryptographic Services Security Feature Bypass Vulnerability
nvd
CVE-2026-48574P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.92342026-06-09
CVE-2026-48574 [HIGH] CWE-122 CVE-2026-48574: Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
nvd
CVE-2022-30194P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.52912022-08-09
CVE-2022-30194 [HIGH] CWE-94 CVE-2022-30194: Windows WebBrowser Control Remote Code Execution Vulnerability Windows WebBrowser Control Remote Code Execution Vulnerability
nvd
CVE-2026-50313P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50313 [HIGH] CWE-122 CVE-2026-50313: Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50347P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50347 [HIGH] CWE-122 CVE-2026-50347: Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code local Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-45636P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.92342026-06-09
CVE-2026-45636 [HIGH] CWE-20 CVE-2026-45636: Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-49796P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-49796 [HIGH] CWE-122 CVE-2026-49796: Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-62474P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.86882025-12-09
CVE-2025-62474 [HIGH] CWE-284 CVE-2025-62474: Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49797P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-49797 [HIGH] CWE-122 CVE-2026-49797: Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-53789P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.82462025-08-12
CVE-2025-53789 [HIGH] CWE-306 CVE-2025-53789: Missing authentication for critical function in Windows StateRepository API allows an authorized att Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50448P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50448 [HIGH] CWE-122 CVE-2026-50448: Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50461P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50461 [HIGH] CWE-122 CVE-2026-50461: Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50386P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50386 [HIGH] CWE-122 CVE-2026-50386: Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-40399P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.91402026-05-12
CVE-2026-40399 [HIGH] CWE-121 CVE-2026-40399: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd