VendorsMicrosoftwindows_10all versions
Vulnerabilities

Microsoft Windows 10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4056CVEs
CVE-2020-1174
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1051, CVE-2020-1175, CVE-2020-1176.
Published 2020-05-21 · Modified
9.3EPSS 0.037
CVE-2021-1668
Microsoft DTV-DVD Video Decoder Remote Code Execution Vulnerability
Published 2021-01-12 · Modified
9.3EPSS 0.036
CVE-2019-0909
Jet Database Engine Remote Code Execution Vulnerability
Published 2019-06-12 · Modified
9.3EPSS 0.036
CVE-2021-24090
Windows Error Reporting Elevation of Privilege Vulnerability
Published 2021-03-11 · Modified
9.3EPSS 0.035
CVE-2020-1339
Windows Media Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
9.3EPSS 0.034
CVE-2020-1061
A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles objects in memory, aka 'Microsoft Script Runtime Remote Code Execution Vulnerability'.
Published 2020-05-21 · Modified
9.3EPSS 0.033
CVE-2020-1508
Windows Media Audio Decoder Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
9.3EPSS 0.033
CVE-2022-24492
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.3EPSS 0.031
CVE-2019-1057
MS XML Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
9.3EPSS 0.031
CVE-2022-24541
Windows Server Service Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.3EPSS 0.030
CVE-2022-21851
Remote Desktop Client Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.3EPSS 0.028
CVE-2022-21850
Remote Desktop Client Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.3EPSS 0.028
CVE-2021-33740
Windows Media Remote Code Execution Vulnerability
Published 2021-07-14 · Modified
9.3EPSS 0.027
CVE-2022-26903
Windows Graphics Component Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.3EPSS 0.027
CVE-2022-21878
Windows Geolocation Service Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.3EPSS 0.027
CVE-2021-34439
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Published 2021-07-16 · Modified
9.3EPSS 0.026
CVE-2022-30141
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-06-15 · Modified
9.3EPSS 0.026
CVE-2022-26919
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.3EPSS 0.026
CVE-2022-21888
Windows Modern Execution Server Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.3EPSS 0.025
CVE-2022-21992
Windows Mobile Device Management Remote Code Execution Vulnerability
Published 2022-02-09 · Modified
9.3EPSS 0.025
CVE-2020-1057
Scripting Engine Memory Corruption Vulnerability
Published 2020-09-11 · Modified
9.3EPSS 0.022
CVE-2017-10855
Untrusted search path vulnerability in FENCE-Explorer for Windows V8.4.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published 2017-09-15 · Modified
9.3EPSS 0.011
CVE-2019-0721
A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0719.
Published 2019-11-12 · Modified
9.1EPSS 0.120
CVE-2019-0719
A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0721.
Published 2019-11-12 · Modified
9.1EPSS 0.114
CVE-2016-3312
ActiveSyncProvider in Microsoft Windows 10 Gold and 1511 allows attackers to discover credentials by leveraging failure of Universal Outlook to obtain a secure connection, aka "Universal Outlook Information Disclosure Vulnerability."
Published 2016-08-09 · Modified
9.1EPSS 0.097
CVE-2016-3345
The SMBv1 server in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Authenticated Remote Code Execution Vulnerability."
Published 2016-09-14 · Modified
9.0EPSS 0.325
CVE-2020-17096
Windows NTFS Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
9.0EPSS 0.195
CVE-2019-0856
A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.
Published 2019-04-09 · Modified
9.0EPSS 0.194
CVE-2016-3368
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow remote authenticated users to execute arbitrary code by leveraging a domain account to make a crafted request, aka "Windows Remote Code Execution Vulnerability."
Published 2016-09-14 · Modified
9.0EPSS 0.183
CVE-2019-0630
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0633.
Published 2019-03-06 · Modified
9.0EPSS 0.174
CVE-2016-0178
The RPC NDR Engine in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandles free operations, which allows remote attackers to execute arbitrary code via malformed RPC requests, aka "RPC Network Data Representation Engine Elevation of Privilege Vulnerability."
Published 2016-05-11 · Modified
9.0EPSS 0.167
CVE-2018-8450
A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-11-14 · Modified
9.0EPSS 0.161
CVE-2020-0662
A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.
Published 2020-02-11 · Modified
9.0EPSS 0.133
CVE-2019-0633
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0630.
Published 2019-03-06 · Modified
9.0EPSS 0.130
CVE-2019-0722
Windows Hyper-V Remote Code Execution Vulnerability
Published 2019-06-12 · Modified
9.0EPSS 0.047
CVE-2020-1317
An elevation of privilege vulnerability exists when Group Policy improperly checks access, aka 'Group Policy Elevation of Privilege Vulnerability'.
Published 2020-06-09 · Modified
9.0EPSS 0.044
CVE-2022-26826
Windows DNS Server Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.0EPSS 0.040
CVE-2021-1667
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2021-01-12 · Modified
9.0EPSS 0.036
CVE-2021-1701
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2021-01-12 · Modified
9.0EPSS 0.036
CVE-2021-1700
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2021-01-12 · Modified
9.0EPSS 0.036
← Prev18 / 102Next →