Microsoft Windows 10 Version 1809 vulnerabilities
3,581 known vulnerabilities affecting microsoft/windows_10_version_1809.
Total CVEs
3,581
CISA KEV
117
actively exploited
Public exploits
98
Exploited in wild
156
Severity breakdown
CRITICAL104HIGH2569MEDIUM894LOW14
Vulnerabilities
Page 70 of 180
CVE-2025-49660P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.75582025-07-08
CVE-2025-49660 [HIGH] CWE-416 CVE-2025-49660: Use after free in Windows Event Tracing allows an authorized attacker to elevate privileges locally.
Use after free in Windows Event Tracing allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-23672P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.85112026-03-10
CVE-2026-23672 [HIGH] CWE-125 CVE-2026-23672: Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
nvd
CVE-2026-25174P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.85112026-03-10
CVE-2026-25174 [HIGH] CWE-125 CVE-2026-25174: Out-of-bounds read in Windows Extensible File Allocation allows an authorized attacker to elevate pr
Out-of-bounds read in Windows Extensible File Allocation allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50479P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50479 [HIGH] CWE-822 CVE-2026-50479: Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate pri
Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-47991P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.75582025-07-08
CVE-2025-47991 [HIGH] CWE-416 CVE-2025-47991: Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privi
Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-48000P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.75582025-07-08
CVE-2025-48000 [HIGH] CWE-362 CVE-2025-48000: Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevat
Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50697P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50697 [HIGH] CWE-200 CVE-2026-50697: Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver
Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-26248P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.5696≥ 10.0.0, < 10.0.17763.56962024-04-09
CVE-2024-26248 [HIGH] CWE-303 CVE-2024-26248: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2025-54895P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.77922025-09-09
CVE-2025-54895 [HIGH] CWE-190 CVE-2025-54895: Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker
Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50498P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50498 [HIGH] CWE-125 CVE-2026-50498: Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
nvd
CVE-2026-49790P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-49790 [HIGH] CWE-122 CVE-2026-49790: Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
nvd
CVE-2026-34336P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.87552026-05-12
CVE-2026-34336 [HIGH] CWE-122 CVE-2026-34336: Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate
Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50441P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50441 [HIGH] CWE-822 CVE-2026-50441: Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker
Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56176P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-56176 [HIGH] CWE-125 CVE-2026-56176: Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges loca
Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-55004P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-55004 [HIGH] CWE-415 CVE-2026-55004: Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally
Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26184P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.86442026-04-14
CVE-2026-26184 [HIGH] CWE-126 CVE-2026-26184: Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privilege
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50667P3HIGHCVSS 7.0≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50667 [HIGH] CWE-362 CVE-2026-50667: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-38119P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.62932024-09-10
CVE-2024-38119 [HIGH] CWE-416 CVE-2024-38119: Windows Network Address Translation (NAT) Remote Code Execution Vulnerability
Windows Network Address Translation (NAT) Remote Code Execution Vulnerability
nvd
CVE-2024-30092P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.64142024-10-08
CVE-2024-30092 [HIGH] CWE-20 CVE-2024-30092: Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2023-24932MEDIUMCVSS 6.7Exploited≥ 10.0.17763.0, < 10.0.17763.7558≥ 10.0.0, < 10.0.17763.60542023-05-09
CVE-2023-24932 [MEDIUM] Secure Boot Security Feature Bypass Vulnerability
Secure Boot Security Feature Bypass Vulnerability
Secure Boot Security Feature Bypass Vulnerability
cvelistv5