Microsoft Windows 10 Version 1809 vulnerabilities
3,581 known vulnerabilities affecting microsoft/windows_10_version_1809.
Total CVEs
3,581
CISA KEV
117
actively exploited
Public exploits
98
Exploited in wild
156
Severity breakdown
CRITICAL104HIGH2569MEDIUM894LOW14
Vulnerabilities
Page 51 of 180
CVE-2022-34702P3HIGHCVSS 8.1≥ 10.0.17763.0, < 10.0.17763.3287≥ 10.0.0, < 10.0.17763.32872022-08-09
CVE-2022-34702 [HIGH] CWE-362 CVE-2022-34702: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2022-38051P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.3532≥ 10.0.0, < 10.0.17763.35322022-10-11
CVE-2022-38051 [HIGH] CVE-2022-38051: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2024-21307P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.5329≥ 10.0.0, < 10.0.17763.53292024-01-09
CVE-2024-21307 [HIGH] CWE-416 CVE-2024-21307: Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2022-30140P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.3046≥ 10.0.0, < 10.0.17763.30462022-06-15
CVE-2022-30140 [HIGH] CVE-2022-30140: Windows iSCSI Discovery Service Remote Code Execution Vulnerability
Windows iSCSI Discovery Service Remote Code Execution Vulnerability
nvd
CVE-2023-28274P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.4252≥ 10.0.0, < 10.0.17763.42522023-04-11
CVE-2023-28274 [HIGH] CWE-20 CVE-2023-28274: Windows Win32k Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
nvd
CVE-2024-30022P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.5820≥ 10.0.0, < 10.0.17763.58202024-05-14
CVE-2024-30022 [HIGH] CWE-197 CVE-2024-30022: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-30024P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.5820≥ 10.0.0, < 10.0.17763.58202024-05-14
CVE-2024-30024 [HIGH] CWE-197 CVE-2024-30024: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-30023P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.5820≥ 10.0.0, < 10.0.17763.58202024-05-14
CVE-2024-30023 [HIGH] CWE-197 CVE-2024-30023: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2025-32713P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.74342025-06-10
CVE-2025-32713 [HIGH] CWE-122 CVE-2025-32713: Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-24474P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.2803≥ 10.0.0, < 10.0.17763.28032022-04-15
CVE-2022-24474 [HIGH] CVE-2022-24474: Windows Win32k Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
nvd
CVE-2026-25181P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.85112026-03-10
CVE-2026-25181 [HIGH] CWE-125 CVE-2026-25181: Out-of-bounds read in Windows GDI+ allows an unauthorized attacker to disclose information over a ne
Out-of-bounds read in Windows GDI+ allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-32183P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.86442026-04-14
CVE-2026-32183 [HIGH] CWE-77 CVE-2026-32183: Improper neutralization of special elements used in a command ('command injection') in Windows Snipp
Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an unauthorized attacker to execute code locally.
nvd
CVE-2024-38028P3HIGHCVSS 7.2≥ 10.0.17763.0, < 10.0.17763.60542024-07-09
CVE-2024-38028 [HIGH] CWE-125 CVE-2024-38028: Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
nvd
CVE-2024-38025P3HIGHCVSS 7.2≥ 10.0.17763.0, < 10.0.17763.60542024-07-09
CVE-2024-38025 [HIGH] CWE-122 CVE-2024-38025: Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
nvd
CVE-2025-24995P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.70092025-03-11
CVE-2025-24995 [HIGH] CWE-122 CVE-2025-24995: Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacke
Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24048P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.70092025-03-11
CVE-2025-24048 [HIGH] CWE-122 CVE-2025-24048: Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privile
Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24050P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.70092025-03-11
CVE-2025-24050 [HIGH] CWE-122 CVE-2025-24050: Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privile
Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50173P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.76782025-08-12
CVE-2025-50173 [HIGH] CWE-1390 CVE-2025-50173: Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally
Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-36401P3HIGHCVSS 7.2≥ 10.0.17763.0, < 10.0.17763.5122≥ 10.0.0, < 10.0.17763.51222023-11-14
CVE-2023-36401 [HIGH] CWE-190 CVE-2023-36401: Microsoft Remote Registry Service Remote Code Execution Vulnerability
Microsoft Remote Registry Service Remote Code Execution Vulnerability
nvd
CVE-2026-35424P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.87552026-05-12
CVE-2026-35424 [HIGH] CWE-401 CVE-2026-35424: Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol a
Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.
nvd