Microsoft Windows 10 Version 1809 vulnerabilities
3,581 known vulnerabilities affecting microsoft/windows_10_version_1809.
Total CVEs
3,581
CISA KEV
117
actively exploited
Public exploits
98
Exploited in wild
156
Severity breakdown
CRITICAL104HIGH2569MEDIUM894LOW14
Vulnerabilities
Page 53 of 180
CVE-2026-58541P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-58541 [HIGH] CWE-843 CVE-2026-58541: Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized at
Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20861P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.82762026-01-13
CVE-2026-20861 [HIGH] CWE-362 CVE-2026-20861: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20867P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.82762026-01-13
CVE-2026-20867 [HIGH] CWE-362 CVE-2026-20867: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20866P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.82762026-01-13
CVE-2026-20866 [HIGH] CWE-362 CVE-2026-20866: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-45637P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-45637 [HIGH] CWE-416 CVE-2026-45637: Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-45593P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-45593 [HIGH] CWE-190 CVE-2026-45593: Use after free in Windows SDK allows an authorized attacker to elevate privileges locally.
Use after free in Windows SDK allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42983P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-42983 [HIGH] CWE-416 CVE-2026-42983: Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-38019P3HIGHCVSS 7.2≥ 10.0.17763.0, < 10.0.17763.60542024-07-09
CVE-2024-38019 [HIGH] CWE-190 CVE-2024-38019: Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
nvd
CVE-2025-49732P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.75582025-07-08
CVE-2025-49732 [HIGH] CWE-122 CVE-2025-49732: Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50344P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50344 [HIGH] CWE-285 CVE-2026-50344: Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.
Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58540P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-58540 [HIGH] CWE-285 CVE-2026-58540: Improper authorization in Windows Installer allows an authorized attacker to elevate privileges loca
Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50469P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50469 [HIGH] CWE-59 CVE-2026-50469: Improper link resolution before file access ('link following') in Windows Projected File System allo
Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-44802P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-44802 [HIGH] CWE-416 CVE-2026-44802: Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50490P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50490 [HIGH] CWE-416 CVE-2026-50490: Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49167P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-49167 [HIGH] CWE-416 CVE-2026-49167: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50306P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50306 [HIGH] CWE-190 CVE-2026-50306: Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50689P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50689 [HIGH] CWE-362 CVE-2026-50689: Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges local
Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54129P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-54129 [HIGH] CWE-416 CVE-2026-54129: Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50307P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50307 [HIGH] CWE-416 CVE-2026-50307: Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-44806P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-44806 [HIGH] CWE-401 CVE-2026-44806: Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unaut
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.
nvd