cbcvebase.

Microsoft Windows 10 Version 1809 vulnerabilities

3,581 known vulnerabilities affecting microsoft/windows_10_version_1809.

Total CVEs
3,581
CISA KEV
117
actively exploited
Public exploits
98
Exploited in wild
155
Severity breakdown
CRITICAL104HIGH2569MEDIUM894LOW14

Vulnerabilities

Page 14 of 180
CVE-2025-33064P2HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.74342025-06-10
CVE-2025-33064 [HIGH] CWE-122 CVE-2025-33064: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
nvd
CVE-2021-36947P2HIGHCVSS 8.8≥ 10.0.0, < 10.0.17763.21142021-08-12
CVE-2021-36947 [HIGH] CVE-2021-36947: Windows Print Spooler Remote Code Execution Vulnerability Windows Print Spooler Remote Code Execution Vulnerability
nvd
CVE-2026-50666P2HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50666 [HIGH] CWE-416 CVE-2026-50666: Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2019-0722P2HIGHCVSS 8.8≥ 10.0.17763.0, < publication≥ 10.0.0, < publication2019-06-12
CVE-2019-0722 [HIGH] CWE-20 CVE-2019-0722: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary
nvd
CVE-2023-32015P2CRITICALCVSS 9.8≥ 10.0.17763.0, < 10.0.17763.4499≥ 10.0.0, < 10.0.17763.44992023-06-14
CVE-2023-32015 [CRITICAL] CWE-20 CVE-2023-32015: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-28250P2CRITICALCVSS 9.8≥ 10.0.17763.0, < 10.0.17763.4252≥ 10.0.0, < 10.0.17763.42522023-04-11
CVE-2023-28250 [CRITICAL] CWE-191 CVE-2023-28250: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-29363P2CRITICALCVSS 9.8≥ 10.0.17763.0, < 10.0.17763.4499≥ 10.0.0, < 10.0.17763.44992023-06-14
CVE-2023-29363 [CRITICAL] CWE-122 CVE-2023-29363: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-32014P2CRITICALCVSS 9.8≥ 10.0.17763.0, < 10.0.17763.4499≥ 10.0.0, < 10.0.17763.44992023-06-14
CVE-2023-32014 [CRITICAL] CWE-191 CVE-2023-32014: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-35365P2CRITICALCVSS 9.8≥ 10.0.17763.0, < 10.0.17763.4645≥ 10.0.0, < 10.0.17763.46452023-07-11
CVE-2023-35365 [CRITICAL] CWE-20 CVE-2023-35365: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2023-35366P2CRITICALCVSS 9.8≥ 10.0.17763.0, < 10.0.17763.4645≥ 10.0.0, < 10.0.17763.46452023-07-11
CVE-2023-35366 [CRITICAL] CWE-20 CVE-2023-35366: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2023-35367P2CRITICALCVSS 9.8≥ 10.0.17763.0, < 10.0.17763.4645≥ 10.0.0, < 10.0.17763.46452023-07-11
CVE-2023-35367 [CRITICAL] CWE-20 CVE-2023-35367: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2023-36911P2CRITICALCVSS 9.8≥ 10.0.17763.0, < 10.0.17763.4737≥ 10.0.0, < 10.0.17763.47372023-08-08
CVE-2023-36911 [CRITICAL] CWE-190 CVE-2023-36911: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2022-21894MEDIUMCVSS 4.4ExploitedPoC≥ 10.0.17763.0, < 10.0.17763.2452≥ 10.0.0, < 10.0.17763.24522022-01-11
CVE-2022-21894 [MEDIUM] Secure Boot Security Feature Bypass Vulnerability Secure Boot Security Feature Bypass Vulnerability Secure Boot Security Feature Bypass Vulnerability
cvelistv5
CVE-2025-26670P2HIGHCVSS 8.1≥ 10.0.17763.0, < 10.0.17763.71362025-04-08
CVE-2025-26670 [HIGH] CWE-416 CVE-2025-26670: Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attack Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
nvd
CVE-2022-44666P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.3770≥ 10.0.0, < 10.0.17763.37702022-12-13
CVE-2022-44666 [HIGH] CVE-2022-44666: Windows Contacts Remote Code Execution Vulnerability Windows Contacts Remote Code Execution Vulnerability
nvd
CVE-2026-25177P2HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.85112026-03-10
CVE-2026-25177 [HIGH] CWE-641 CVE-2026-25177: Improper restriction of names for files and other resources in Active Directory Domain Services allo Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-54121P2HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-54121 [HIGH] CWE-285 CVE-2026-54121: Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacke Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-48564P2HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-48564 [HIGH] CWE-122 CVE-2026-48564: Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
nvd
CVE-2026-50444P2HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50444 [HIGH] CWE-306 CVE-2026-50444: Missing authentication for critical function in Windows Server Update Service allows an authorized a Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-50502P2HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50502 [HIGH] CWE-1220 CVE-2026-50502: Insufficient granularity of access control in Windows Event Logging Service allows an authorized att Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.
nvd