Microsoft Windows 10 Version 1809 vulnerabilities
3,581 known vulnerabilities affecting microsoft/windows_10_version_1809.
Total CVEs
3,581
CISA KEV
117
actively exploited
Public exploits
98
Exploited in wild
156
Severity breakdown
CRITICAL104HIGH2569MEDIUM894LOW14
Vulnerabilities
Page 167 of 180
CVE-2024-21304P4MEDIUMCVSS 4.1≥ 10.0.17763.0, < 10.0.17763.5458≥ 10.0.0, < 10.0.17763.54582024-02-13
CVE-2024-21304 [MEDIUM] CWE-20 CVE-2024-21304: Trusted Compute Base Elevation of Privilege Vulnerability
Trusted Compute Base Elevation of Privilege Vulnerability
nvd
CVE-2025-21298CRITICALCVSS 9.8≥ 10.0.17763.0, < 10.0.17763.67752025-01-14
CVE-2025-21298 [CRITICAL] CWE-416 Windows OLE Remote Code Execution Vulnerability
Windows OLE Remote Code Execution Vulnerability
Windows OLE Remote Code Execution Vulnerability
cvelistv5
CVE-2020-17046P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-11-11
CVE-2020-17046 [MEDIUM] CVE-2020-17046: Windows Error Reporting Denial of Service Vulnerability
Windows Error Reporting Denial of Service Vulnerability
nvd
CVE-2023-29325HIGHCVSS 8.1≥ 10.0.17763.0, < 10.0.17763.4377≥ 10.0.0, < 10.0.17763.43772023-05-09
CVE-2023-29325 [HIGH] CWE-416 Windows OLE Remote Code Execution Vulnerability
Windows OLE Remote Code Execution Vulnerability
Windows OLE Remote Code Execution Vulnerability
cvelistv5
CVE-2024-21340P4MEDIUMCVSS 4.6≥ 10.0.17763.0, < 10.0.17763.5458≥ 10.0.0, < 10.0.17763.54582024-02-13
CVE-2024-21340 [MEDIUM] CWE-126 CVE-2024-21340: Windows Kernel Information Disclosure Vulnerability
Windows Kernel Information Disclosure Vulnerability
nvd
CVE-2022-38030P4MEDIUMCVSS 4.3≥ 10.0.17763.0, < 10.0.17763.3532≥ 10.0.0, < 10.0.17763.35322022-10-11
CVE-2022-38030 [MEDIUM] CVE-2022-38030: Windows USB Serial Driver Information Disclosure Vulnerability
Windows USB Serial Driver Information Disclosure Vulnerability
nvd
CVE-2025-29839P4MEDIUMCVSS 4.0≥ 10.0.17763.0, < 10.0.17763.73142025-05-13
CVE-2025-29839 [MEDIUM] CWE-125 CVE-2025-29839: Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information lo
Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-45642P4LOWCVSS 3.9≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-45642 [LOW] CWE-20 CVE-2026-45642: Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Servi
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.
nvd
CVE-2025-59280P4LOWCVSS 3.1≥ 10.0.17763.0, < 10.0.17763.79192025-10-14
CVE-2025-59280 [LOW] CWE-287 CVE-2025-59280: Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering o
Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.
nvd
CVE-2025-21210P4MEDIUMCVSS 4.2≥ 10.0.17763.0, < 10.0.17763.67752025-01-14
CVE-2025-21210 [MEDIUM] CWE-636 CVE-2025-21210: Windows BitLocker Information Disclosure Vulnerability
Windows BitLocker Information Disclosure Vulnerability
nvd
CVE-2025-21214P4MEDIUMCVSS 4.2≥ 10.0.17763.0, < 10.0.17763.67752025-01-14
CVE-2025-21214 [MEDIUM] CWE-200 CVE-2025-21214: Windows BitLocker Information Disclosure Vulnerability
Windows BitLocker Information Disclosure Vulnerability
nvd
CVE-2022-38022P4LOWCVSS 3.3≥ 10.0.17763.0, < 10.0.17763.3532≥ 10.0.0, < 10.0.17763.35322022-10-11
CVE-2022-38022 [LOW] CVE-2022-38022: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-41076HIGHCVSS 8.5≥ 10.0.17763.0, < 10.0.17763.3770≥ 10.0.0, < 10.0.17763.37702022-12-13
CVE-2022-41076 [HIGH] PowerShell Remote Code Execution Vulnerability
PowerShell Remote Code Execution Vulnerability
PowerShell Remote Code Execution Vulnerability
cvelistv5
CVE-2025-55695P4LOWCVSS 3.3≥ 10.0.17763.0, < 10.0.17763.79192025-10-14
CVE-2025-55695 [LOW] CWE-125 CVE-2025-55695: Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose inf
Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50419P4LOWCVSS 3.3≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50419 [LOW] CWE-200 CVE-2026-50419: Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized at
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2026-57085P4LOWCVSS 3.3≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-57085 [LOW] CWE-125 CVE-2026-57085: Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose inf
Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
nvd
CVE-2021-28325MEDIUMCVSS 6.5≥ 10.0.0, < publication2021-04-13
CVE-2021-28325 [MEDIUM] Windows SMB Information Disclosure Vulnerability
Windows SMB Information Disclosure Vulnerability
Windows SMB Information Disclosure Vulnerability
cvelistv5
CVE-2021-24086HIGHCVSS 7.5≥ 10.0.0, < publication2021-02-25
CVE-2021-24086 [HIGH] Windows TCP/IP Denial of Service Vulnerability
Windows TCP/IP Denial of Service Vulnerability
Windows TCP/IP Denial of Service Vulnerability
cvelistv5
CVE-2022-21977P4LOWCVSS 3.3≥ 10.0.17763.0, < 10.0.17763.2686≥ 10.0.0, < 10.0.17763.26862022-03-09
CVE-2022-21977 [LOW] CVE-2022-21977: Media Foundation Information Disclosure Vulnerability
Media Foundation Information Disclosure Vulnerability
nvd
CVE-2020-1592P4LOWCVSS 3.3≥ 10.0.0, < publication2020-09-11
CVE-2020-1592 [LOW] CWE-665 CVE-2020-1592: <p>An information disclosure vulnerability exists when the Windows kernel improperly initializes obj
An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.
To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
The update addresse
nvd