Microsoft Windows 10 Version 1809 vulnerabilities
3,581 known vulnerabilities affecting microsoft/windows_10_version_1809.
Total CVEs
3,581
CISA KEV
117
actively exploited
Public exploits
98
Exploited in wild
156
Severity breakdown
CRITICAL104HIGH2569MEDIUM894LOW14
Vulnerabilities
Page 150 of 180
CVE-2025-21272P4MEDIUMCVSS 6.5≥ 10.0.17763.0, < 10.0.17763.67752025-01-14
CVE-2025-21272 [MEDIUM] CWE-908 CVE-2025-21272: Windows COM Server Information Disclosure Vulnerability
Windows COM Server Information Disclosure Vulnerability
nvd
CVE-2025-21288P4MEDIUMCVSS 6.5≥ 10.0.17763.0, < 10.0.17763.67752025-01-14
CVE-2025-21288 [MEDIUM] CWE-908 CVE-2025-21288: Windows COM Server Information Disclosure Vulnerability
Windows COM Server Information Disclosure Vulnerability
nvd
CVE-2022-21877P4MEDIUMCVSS 5.5≥ 10.0.17763.0, < 10.0.17763.2452≥ 10.0.0, < 10.0.17763.24522022-01-11
CVE-2022-21877 [MEDIUM] CWE-125 CVE-2022-21877: Storage Spaces Controller Information Disclosure Vulnerability
Storage Spaces Controller Information Disclosure Vulnerability
nvd
CVE-2024-21344P4MEDIUMCVSS 5.9≥ 10.0.17763.0, < 10.0.17763.5458≥ 10.0.0, < 10.0.17763.54582024-02-13
CVE-2024-21344 [MEDIUM] CWE-125 CVE-2024-21344: Windows Network Address Translation (NAT) Denial of Service Vulnerability
Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2022-35747P4MEDIUMCVSS 5.9≥ 10.0.17763.0, < 10.0.17763.3287≥ 10.0.0, < 10.0.17763.32872023-05-31
CVE-2022-35747 [MEDIUM] CVE-2022-35747: Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
nvd
CVE-2024-38254P4MEDIUMCVSS 6.2≥ 10.0.17763.0, < 10.0.17763.62932024-09-10
CVE-2024-38254 [MEDIUM] CWE-908 CVE-2024-38254: Windows Authentication Information Disclosure Vulnerability
Windows Authentication Information Disclosure Vulnerability
nvd
CVE-2025-29957P4MEDIUMCVSS 6.2≥ 10.0.17763.0, < 10.0.17763.73142025-05-13
CVE-2025-29957 [MEDIUM] CWE-400 CVE-2025-29957: Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to
Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally.
nvd
CVE-2021-31961P4MEDIUMCVSS 6.1≥ 10.0.0, < 10.0.17763.20612021-07-14
CVE-2021-31961 [MEDIUM] CWE-269 CVE-2021-31961: Windows InstallService Elevation of Privilege Vulnerability
Windows InstallService Elevation of Privilege Vulnerability
nvd
CVE-2019-1143P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2019-08-14
CVE-2019-1143 [MEDIUM] CWE-200 CVE-2019-1143: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open
nvd
CVE-2019-1158P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2019-08-14
CVE-2019-1158 [MEDIUM] CWE-200 CVE-2019-1158: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open
nvd
CVE-2019-1163P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2019-08-14
CVE-2019-1163 [MEDIUM] CWE-354 CVE-2019-1163: A security feature bypass exists when Windows incorrectly validates CAB file signatures. An attacker
A security feature bypass exists when Windows incorrectly validates CAB file signatures. An attacker who successfully exploited this vulnerability could inject code into a CAB file without invalidating the file's signature.
To exploit the vulnerability, an attacker could modify a signed CAB file and inject malicious code. The attacker could then convi
nvd
CVE-2021-31188P4MEDIUMCVSS 5.5≥ 10.0.0, < 10.0.17763.19352021-05-11
CVE-2021-31188 [MEDIUM] CWE-416 CVE-2021-31188: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2020-16889P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16889 [MEDIUM] CVE-2020-16889: <p>An information disclosure vulnerability exists when the Windows KernelStream improperly handles o
An information disclosure vulnerability exists when the Windows KernelStream improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted applic
nvd
CVE-2020-1589P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-09-11
CVE-2020-1589 [MEDIUM] CVE-2020-1589: <p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. T
nvd
CVE-2020-16921P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16921 [MEDIUM] CVE-2020-16921: <p>An information disclosure vulnerability exists in Text Services Framework when it fails to proper
An information disclosure vulnerability exists in Text Services Framework when it fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could potentially read data that was not intended to be disclosed. Note that this vulnerability would not allow an attacker to execute code or to elevate their user rights dir
nvd
CVE-2020-16897P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16897 [MEDIUM] CVE-2020-16897: <p>An information disclosure vulnerability exists when NetBIOS over TCP (NBT) Extensions (NetBT) imp
An information disclosure vulnerability exists when NetBIOS over TCP (NBT) Extensions (NetBT) improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have run a specially crafted application. The vulnerabi
nvd
CVE-2020-16854P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-09-11
CVE-2020-16854 [MEDIUM] CVE-2020-16854: <p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.
nvd
CVE-2020-1548P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-08-17
CVE-2020-1548 [MEDIUM] CVE-2020-1548: An information disclosure vulnerability exists when the Windows WaasMedic Service improperly handles
An information disclosure vulnerability exists when the Windows WaasMedic Service improperly handles memory.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to improperly disclose memory.
The security update addresses the vulnerability by correcting
nvd
CVE-2024-21313P4MEDIUMCVSS 5.3≥ 10.0.17763.0, < 10.0.17763.5329≥ 10.0.0, < 10.0.17763.53292024-01-09
CVE-2024-21313 [MEDIUM] CWE-209 CVE-2024-21313: Windows TCP/IP Information Disclosure Vulnerability
Windows TCP/IP Information Disclosure Vulnerability
nvd
CVE-2025-49722P4MEDIUMCVSS 5.7≥ 10.0.17763.0, < 10.0.17763.75582025-07-08
CVE-2025-49722 [MEDIUM] CWE-400 CVE-2025-49722: Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker
Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over an adjacent network.
nvd