cbcvebase.

Microsoft Windows 10 Version 1809 vulnerabilities

3,581 known vulnerabilities affecting microsoft/windows_10_version_1809.

Total CVEs
3,581
CISA KEV
117
actively exploited
Public exploits
98
Exploited in wild
156
Severity breakdown
CRITICAL104HIGH2569MEDIUM894LOW14

Vulnerabilities

Page 133 of 180
CVE-2023-24870P4MEDIUMCVSS 6.5≥ 10.0.17763.0, < 10.0.17763.4131≥ 10.0.0, < 10.0.17763.41312023-03-14
CVE-2023-24870 [MEDIUM] CWE-126 CVE-2023-24870: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2024-43525P4MEDIUMCVSS 6.8≥ 10.0.17763.0, < 10.0.17763.64142024-10-08
CVE-2024-43525 [MEDIUM] CWE-20 CVE-2024-43525: Windows Mobile Broadband Driver Remote Code Execution Vulnerability Windows Mobile Broadband Driver Remote Code Execution Vulnerability
nvd
CVE-2024-43526P4MEDIUMCVSS 6.8≥ 10.0.17763.0, < 10.0.17763.64142024-10-08
CVE-2024-43526 [MEDIUM] CWE-20 CVE-2024-43526: Windows Mobile Broadband Driver Remote Code Execution Vulnerability Windows Mobile Broadband Driver Remote Code Execution Vulnerability
nvd
CVE-2024-43523P4MEDIUMCVSS 6.8≥ 10.0.17763.0, < 10.0.17763.64142024-10-08
CVE-2024-43523 [MEDIUM] CWE-20 CVE-2024-43523: Windows Mobile Broadband Driver Remote Code Execution Vulnerability Windows Mobile Broadband Driver Remote Code Execution Vulnerability
nvd
CVE-2024-43524P4MEDIUMCVSS 6.8≥ 10.0.17763.0, < 10.0.17763.64142024-10-08
CVE-2024-43524 [MEDIUM] CWE-118 CVE-2024-43524: Windows Mobile Broadband Driver Remote Code Execution Vulnerability Windows Mobile Broadband Driver Remote Code Execution Vulnerability
nvd
CVE-2024-43543P4MEDIUMCVSS 6.8≥ 10.0.17763.0, < 10.0.17763.64142024-10-08
CVE-2024-43543 [MEDIUM] CWE-601 CVE-2024-43543: Windows Mobile Broadband Driver Remote Code Execution Vulnerability Windows Mobile Broadband Driver Remote Code Execution Vulnerability
nvd
CVE-2024-43536P4MEDIUMCVSS 6.8≥ 10.0.17763.0, < 10.0.17763.64142024-10-08
CVE-2024-43536 [MEDIUM] CWE-601 CVE-2024-43536: Windows Mobile Broadband Driver Remote Code Execution Vulnerability Windows Mobile Broadband Driver Remote Code Execution Vulnerability
nvd
CVE-2026-45658P4MEDIUMCVSS 6.8≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-45658 [MEDIUM] CWE-284 CVE-2026-45658: Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feat Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-50298P4MEDIUMCVSS 6.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50298 [MEDIUM] CWE-190 CVE-2026-50298: Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate p Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2026-50299P4MEDIUMCVSS 6.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50299 [MEDIUM] CWE-122 CVE-2026-50299: Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to e Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.
nvd
CVE-2026-57097P4MEDIUMCVSS 6.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-57097 [MEDIUM] CWE-426 CVE-2026-57097: Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48807P4MEDIUMCVSS 6.7≥ 10.0.17763.0, < 10.0.17763.77922025-08-12
CVE-2025-48807 [MEDIUM] CWE-923 CVE-2025-48807: Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an aut Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally.
nvd
CVE-2026-32170P4MEDIUMCVSS 6.7≥ 10.0.17763.0, < 10.0.17763.87552026-05-12
CVE-2026-32170 [MEDIUM] CWE-415 CVE-2026-32170: Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21530P4MEDIUMCVSS 6.7≥ 10.0.17763.0, < 10.0.17763.87552026-05-12
CVE-2026-21530 [MEDIUM] CWE-415 CVE-2026-21530: Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-48811P4MEDIUMCVSS 6.7≥ 10.0.17763.0, < 10.0.17763.75582025-07-08
CVE-2025-48811 [MEDIUM] CWE-353 CVE-2025-48811: Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-48803P4MEDIUMCVSS 6.7≥ 10.0.17763.0, < 10.0.17763.75582025-07-08
CVE-2025-48803 [MEDIUM] CWE-353 CVE-2025-48803: Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-26209P4MEDIUMCVSS 5.5≥ 10.0.17763.0, < 10.0.17763.5696≥ 10.0.0, < 10.0.17763.56962024-04-09
CVE-2024-26209 [MEDIUM] CWE-908 CVE-2024-26209: Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
nvd
CVE-2025-29954P4MEDIUMCVSS 5.9≥ 10.0.17763.0, < 10.0.17763.73142025-05-13
CVE-2025-29954 [MEDIUM] CWE-400 CVE-2025-29954: Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-40380P4MEDIUMCVSS 6.2≥ 10.0.17763.0, < 10.0.17763.87552026-05-12
CVE-2026-40380 [MEDIUM] CWE-122 CVE-2026-40380: Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execu Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack.
nvd
CVE-2026-32072P4MEDIUMCVSS 6.2≥ 10.0.17763.0, < 10.0.17763.86442026-04-14
CVE-2026-32072 [MEDIUM] CWE-287 CVE-2026-32072: Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoof Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.
nvd
Microsoft Windows 10 Version 1809 vulnerabilities | cvebase