cbcvebase.

Microsoft Windows 10 Version 1809 vulnerabilities

3,581 known vulnerabilities affecting microsoft/windows_10_version_1809.

Total CVEs
3,581
CISA KEV
117
actively exploited
Public exploits
98
Exploited in wild
156
Severity breakdown
CRITICAL104HIGH2569MEDIUM894LOW14

Vulnerabilities

Page 32 of 180
CVE-2026-20922P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.82762026-01-13
CVE-2026-20922 [HIGH] CWE-122 CVE-2026-20922: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2020-0922P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-09-11
CVE-2020-0922 [HIGH] CVE-2020-0922: <p>A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles ob A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have to open a specially crafted file or lure the target to a website hosting malicious JavaScript.
nvd
CVE-2026-50452P3HIGHCVSS 8.1≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50452 [HIGH] CWE-362 CVE-2026-50452: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2026-50683P3HIGHCVSS 8.0≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50683 [HIGH] CWE-122 CVE-2026-50683: Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privilege Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.
nvd
CVE-2024-26218P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.5696≥ 10.0.0, < 10.0.17763.56962024-04-09
CVE-2024-26218 [HIGH] CWE-367 CVE-2024-26218: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2020-1561P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1561 [HIGH] CVE-2020-1561: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have to open a specially crafted file. The security update addresses the vulnerability by correct
nvd
CVE-2026-20848P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.82762026-01-13
CVE-2026-20848 [HIGH] CWE-362 CVE-2026-20848: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2020-1339P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1339 [HIGH] CVE-2020-1339: A remote code execution vulnerability exists when Windows Media Audio Codec improperly handles objec A remote code execution vulnerability exists when Windows Media Audio Codec improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user
nvd
CVE-2026-50685P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50685 [HIGH] CWE-415 CVE-2026-50685: Double free in Windows DHCP Server allows an authorized attacker to execute code over a network. Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.
nvd
CVE-2026-58531P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-58531 [HIGH] CWE-362 CVE-2026-58531: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2020-1508P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1508 [HIGH] CVE-2020-1508: <p>A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user
nvd
CVE-2026-58608P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-58608 [HIGH] CWE-362 CVE-2026-58608: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.
nvd
CVE-2024-21310P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.5329≥ 10.0.0, < 10.0.17763.53292024-01-09
CVE-2024-21310 [HIGH] CWE-197 CVE-2024-21310: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-21851P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.2452≥ 10.0.0, < 10.0.17763.24522022-01-11
CVE-2022-21851 [HIGH] CVE-2022-21851: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2022-21850P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.2452≥ 10.0.0, < 10.0.17763.24522022-01-11
CVE-2022-21850 [HIGH] CVE-2022-21850: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2025-55681P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.79192025-10-14
CVE-2025-55681 [HIGH] CWE-125 CVE-2025-55681: Out-of-bounds read in Windows DWM allows an authorized attacker to elevate privileges locally. Out-of-bounds read in Windows DWM allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-34734P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.3406≥ 10.0.0, < 10.0.17763.34062022-09-13
CVE-2022-34734 [HIGH] CVE-2022-34734: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2022-34727P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.3406≥ 10.0.0, < 10.0.17763.34062022-09-13
CVE-2022-34727 [HIGH] CVE-2022-34727: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2022-34732P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.3406≥ 10.0.0, < 10.0.17763.34062022-09-13
CVE-2022-34732 [HIGH] CVE-2022-34732: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2022-34730P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.3406≥ 10.0.0, < 10.0.17763.34062022-09-13
CVE-2022-34730 [HIGH] CVE-2022-34730: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
Microsoft Windows 10 Version 1809 vulnerabilities | cvebase