VendorsMicrosoftwindows_10all versions
Vulnerabilities

Microsoft Windows 10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4056CVEs
CVE-2020-16898
Windows TCP/IP Remote Code Execution Vulnerability
Published 2020-10-16 · Modified
8.8EPSS 0.109
CVE-2016-7867
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buffer overflow / underflow vulnerability in the RegExp class related to bookmarking in searches. Successful exploitation could lead to arbitrary code execution.
Published 2016-12-15 · Modified
8.8EPSS 0.107
CVE-2016-7870
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buffer overflow / underflow vulnerability in the RegExp class for specific search strategies. Successful exploitation could lead to arbitrary code execution.
Published 2016-12-15 · Modified
8.8EPSS 0.107
CVE-2019-1113
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'.
Published 2019-07-29 · Modified
8.8EPSS 0.100
CVE-2020-16915
Media Foundation Memory Corruption Vulnerability
Published 2020-10-16 · Modified
8.8EPSS 0.098
CVE-2019-1456
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts, aka 'OpenType Font Parsing Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1419.
Published 2019-11-12 · Modified
8.8EPSS 0.097
CVE-2021-1678
Windows Print Spooler Spoofing Vulnerability
Published 2021-01-12 · Modified
8.8EPSS 0.093
CVE-2020-0684
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
Published 2020-03-12 · Modified
8.8EPSS 0.090
CVE-2016-4222
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4173, CVE-2016-4174, CVE-2016-4226, CVE-2016-4227, CVE-2016-4228, CVE-2016-4229, CVE-2016-4230, CVE-2016-4231, and CVE-2016-4248.
Published 2016-07-13 · Modified
8.8EPSS 0.085
CVE-2016-7875
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable integer overflow vulnerability in the BitmapData class. Successful exploitation could lead to arbitrary code execution.
Published 2016-12-15 · Modified
8.8EPSS 0.083
CVE-2016-7878
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the PSDK's MediaPlayer class. Successful exploitation could lead to arbitrary code execution.
Published 2016-12-15 · Modified
8.8EPSS 0.079
CVE-2016-7872
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the MovieClip class related to objects at multiple presentation levels. Successful exploitation could lead to arbitrary code execution.
Published 2016-12-15 · Modified
8.8EPSS 0.077
CVE-2016-7879
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the NetConnection class when handling an attached script object. Successful exploitation could lead to arbitrary code execution.
Published 2016-12-15 · Modified
8.8EPSS 0.077
CVE-2021-36947
Windows Print Spooler Remote Code Execution Vulnerability
Published 2021-08-12 · Modified
8.8EPSS 0.075
CVE-2016-4223
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2016-4224 and CVE-2016-4225.
Published 2016-07-13 · Modified
8.8EPSS 0.074
CVE-2016-4224
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2016-4223 and CVE-2016-4225.
Published 2016-07-13 · Modified
8.8EPSS 0.074
CVE-2016-4225
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2016-4223 and CVE-2016-4224.
Published 2016-07-13 · Modified
8.8EPSS 0.074
CVE-2020-1238
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1239.
Published 2020-06-09 · Modified
8.8EPSS 0.070
CVE-2018-4945
Adobe Flash Player versions 29.0.0.171 and earlier have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Published 2018-07-09 · Modified
8.8EPSS 0.067
CVE-2016-7871
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable memory corruption vulnerability in the Worker class. Successful exploitation could lead to arbitrary code execution.
Published 2016-12-15 · Modified
8.8EPSS 0.067
CVE-2020-1239
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1238.
Published 2020-06-09 · Modified
8.8EPSS 0.059
CVE-2018-8126
A security feature bypass vulnerability exists when Internet Explorer fails to validate User Mode Code Integrity (UMCI) policies, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11.
Published 2018-05-09 · Modified
8.8EPSS 0.056
CVE-2019-7845
Adobe Flash Player versions 32.0.0.192 and earlier, 32.0.0.192 and earlier, and 32.0.0.192 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2019-06-12 · Modified
8.8EPSS 0.055
CVE-2020-0801
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0807, CVE-2020-0809, CVE-2020-0869.
Published 2020-03-12 · Modified
8.8EPSS 0.053
CVE-2019-0995
A security feature bypass vulnerability exists when urlmon.dll improperly handles certain Mark of the Web queries, aka 'Internet Explorer Security Feature Bypass Vulnerability'.
Published 2019-05-16 · Modified
8.8EPSS 0.049
CVE-2022-30165
Windows Kerberos Elevation of Privilege Vulnerability
Published 2022-06-15 · Modified
8.8EPSS 0.049
CVE-2020-1585
Microsoft Windows Codecs Library Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
8.8EPSS 0.049
CVE-2022-21984
Windows DNS Server Remote Code Execution Vulnerability
Published 2022-02-09 · Modified
8.8EPSS 0.048
CVE-2020-0869
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0801, CVE-2020-0807, CVE-2020-0809.
Published 2020-03-12 · Modified
8.8EPSS 0.047
CVE-2016-7890
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have security bypass vulnerability in the implementation of the same origin policy.
Published 2016-12-15 · Modified
8.8EPSS 0.046
CVE-2022-26927
Windows Graphics Component Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
8.8EPSS 0.044
CVE-2020-1129
Microsoft Windows Codecs Library Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
8.8EPSS 0.042
CVE-2017-8664
Windows Hyper-V in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability".
Published 2017-08-08 · Modified
8.8EPSS 0.040
CVE-2019-1140
Chakra Scripting Engine Memory Corruption Vulnerability
Published 2019-08-14 · Modified
8.8EPSS 0.038
CVE-2020-1012
WinINet API Elevation of Privilege Vulnerability
Published 2020-09-11 · Modified
8.8EPSS 0.037
CVE-2022-35841
Windows Enterprise App Management Service Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
8.8EPSS 0.036
CVE-2020-17759
An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrary command execution if the user clicks on a specially crafted URL. AKA: WINNOTE-19941.
Published 2021-06-24 · Modified
8.8EPSS 0.034
CVE-2021-24091
Windows Camera Codec Pack Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
8.8EPSS 0.034
CVE-2020-1255
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
Published 2020-06-09 · Modified
8.8EPSS 0.034
CVE-2020-1509
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
Published 2020-08-17 · Modified
8.8EPSS 0.033
← Prev20 / 102Next →