Microsoft Windows 10 Version 1809 vulnerabilities
3,581 known vulnerabilities affecting microsoft/windows_10_version_1809.
Total CVEs
3,581
CISA KEV
117
actively exploited
Public exploits
98
Exploited in wild
156
Severity breakdown
CRITICAL104HIGH2569MEDIUM894LOW14
Vulnerabilities
Page 147 of 180
CVE-2021-27079P4MEDIUMCVSS 5.7≥ 10.0.0, < publication2021-04-13
CVE-2021-27079 [MEDIUM] CVE-2021-27079: Windows Media Photo Codec Information Disclosure Vulnerability
Windows Media Photo Codec Information Disclosure Vulnerability
nvd
CVE-2023-24944P4MEDIUMCVSS 6.5≥ 10.0.17763.0, < 10.0.17763.4377≥ 10.0.0, < 10.0.17763.43772023-05-09
CVE-2023-24944 [MEDIUM] CWE-843 CVE-2023-24944: Windows Bluetooth Driver Information Disclosure Vulnerability
Windows Bluetooth Driver Information Disclosure Vulnerability
nvd
CVE-2019-1187P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2019-08-14
CVE-2019-1187 [MEDIUM] CWE-611 CVE-2019-1187: A denial of service vulnerability exists when the XmlLite runtime (XmlLite.dll) improperly parses XM
A denial of service vulnerability exists when the XmlLite runtime (XmlLite.dll) improperly parses XML input. An attacker who successfully exploited this vulnerability could cause a denial of service against an XML application.
A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to an XML application
nvd
CVE-2021-26866P4MEDIUMCVSS 6.1≥ 10.0.0, < publication2021-03-11
CVE-2021-26866 [MEDIUM] CWE-59 CVE-2021-26866: Windows Update Service Elevation of Privilege Vulnerability
Windows Update Service Elevation of Privilege Vulnerability
nvd
CVE-2022-41086P4MEDIUMCVSS 6.4≥ 10.0.17763.0, < 10.0.17763.3650≥ 10.0.0, < 10.0.17763.36502022-11-09
CVE-2022-41086 [MEDIUM] CWE-362 CVE-2022-41086: Windows Group Policy Elevation of Privilege Vulnerability
Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2022-24503P4MEDIUMCVSS 5.3≥ 10.0.17763.0, < 10.0.17763.2686≥ 10.0.0, < 10.0.17763.26862022-03-09
CVE-2022-24503 [MEDIUM] CVE-2022-24503: Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability
nvd
CVE-2023-21693P4MEDIUMCVSS 5.7≥ 10.0.17763.0, < 10.0.17763.4010≥ 10.0.0, < 10.0.17763.40102023-02-14
CVE-2023-21693 [MEDIUM] CWE-125 CVE-2023-21693: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2024-20692P4MEDIUMCVSS 5.7≥ 10.0.17763.0, < 10.0.17763.5329≥ 10.0.0, < 10.0.17763.53292024-01-09
CVE-2024-20692 [MEDIUM] CWE-326 CVE-2024-20692: Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
nvd
CVE-2019-1227P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2019-08-14
CVE-2019-1227 [MEDIUM] CWE-200 CVE-2019-1227: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted applic
nvd
CVE-2024-43547P4MEDIUMCVSS 5.9≥ 10.0.17763.0, < 10.0.17763.64142024-10-08
CVE-2024-43547 [MEDIUM] CWE-325 CVE-2024-43547: Windows Kerberos Information Disclosure Vulnerability
Windows Kerberos Information Disclosure Vulnerability
nvd
CVE-2019-1171P4MEDIUMCVSS 5.6≥ 10.0.0, < publication2019-08-14
CVE-2019-1171 [MEDIUM] CWE-200 CVE-2019-1171: An information disclosure vulnerability exists in SymCrypt during the OAEP decryption stage. An atta
An information disclosure vulnerability exists in SymCrypt during the OAEP decryption stage. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulne
nvd
CVE-2025-21269P4MEDIUMCVSS 4.3≥ 10.0.17763.0, < 10.0.17763.67752025-01-14
CVE-2025-21269 [MEDIUM] CWE-41 CVE-2025-21269: Windows HTML Platforms Security Feature Bypass Vulnerability
Windows HTML Platforms Security Feature Bypass Vulnerability
nvd
CVE-2021-1645P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2021-01-12
CVE-2021-1645 [MEDIUM] CVE-2021-1645: Windows Docker Information Disclosure Vulnerability
Windows Docker Information Disclosure Vulnerability
nvd
CVE-2021-1638P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2021-01-12
CVE-2021-1638 [MEDIUM] CVE-2021-1638: Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For
Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG.
To address the vulnerability, Microsoft has released a software update that will fail attempts to pair if the remote device exchanges a public key with the same X coordinate
nvd
CVE-2020-1383P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-08-17
CVE-2020-1383 [MEDIUM] CVE-2020-1383: An information disclosure vulnerability exists in RPC if the server has Routing and Remote Access en
An information disclosure vulnerability exists in RPC if the server has Routing and Remote Access enabled. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system
To exploit this vulnerability, an attacker would need to run a specially crafted application against an RPC server which has Routin
nvd
CVE-2025-53136P4MEDIUMCVSS 5.5≥ 10.0.17763.0, < 10.0.17763.76782025-08-12
CVE-2025-53136 [MEDIUM] CWE-200 CVE-2025-53136: Exposure of sensitive information to an unauthorized actor in Windows NT OS Kernel allows an authori
Exposure of sensitive information to an unauthorized actor in Windows NT OS Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2021-1731P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2021-02-25
CVE-2021-1731 [MEDIUM] CWE-522 CVE-2021-1731: PFX Encryption Security Feature Bypass Vulnerability
PFX Encryption Security Feature Bypass Vulnerability
nvd
CVE-2020-16922P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16922 [MEDIUM] CWE-347 CVE-2020-16922: <p>A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker w
A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files.
In an attack scenario, an attacker could bypass security features intended to prevent improperly signed files from being loaded.
The update addr
nvd
CVE-2025-53799P4MEDIUMCVSS 5.5≥ 10.0.17763.0, < 10.0.17763.77922025-09-09
CVE-2025-53799 [MEDIUM] CWE-908 CVE-2025-53799: Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclo
Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.
nvd
CVE-2023-36889P4MEDIUMCVSS 5.5≥ 10.0.17763.0, < 10.0.17763.4737≥ 10.0.0, < 10.0.17763.47372023-08-08
CVE-2023-36889 [MEDIUM] CWE-284 CVE-2023-36889: Windows Group Policy Security Feature Bypass Vulnerability
Windows Group Policy Security Feature Bypass Vulnerability
nvd