VendorsMicrosoftwindows_10all versions
Vulnerabilities

Microsoft Windows 10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4056CVEs
CVE-2022-34691
Active Directory Domain Services Elevation of Privilege Vulnerability
Published 2022-08-09 · Modified
8.8EPSS 0.021
CVE-2020-1506
Windows Start-Up Application Elevation of Privilege Vulnerability
Published 2020-09-11 · Modified
8.8EPSS 0.021
CVE-2021-31971
Windows HTML Platforms Security Feature Bypass Vulnerability
Published 2021-06-08 · Modified
8.8EPSS 0.021
CVE-2021-42275
Microsoft COM for Windows Remote Code Execution Vulnerability
Published 2021-11-10 · Modified
8.8EPSS 0.021
CVE-2022-30221
Windows Graphics Component Remote Code Execution Vulnerability
Published 2022-07-12 · Modified
8.8EPSS 0.021
CVE-2021-34446
Windows HTML Platforms Security Feature Bypass Vulnerability
Published 2021-07-16 · Modified
8.8EPSS 0.020
CVE-2021-34447
Windows MSHTML Platform Remote Code Execution Vulnerability
Published 2021-07-16 · Modified
8.8EPSS 0.020
CVE-2022-38031
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.8EPSS 0.016
CVE-2022-38040
Microsoft ODBC Driver Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.8EPSS 0.016
CVE-2022-37982
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.8EPSS 0.016
CVE-2021-41342
Windows MSHTML Platform Remote Code Execution Vulnerability
Published 2021-10-13 · Modified
8.8EPSS 0.016
CVE-2022-37975
Windows Group Policy Elevation of Privilege Vulnerability
Published 2022-10-11 · Modified
8.8EPSS 0.016
CVE-2022-41047
Microsoft ODBC Driver Remote Code Execution Vulnerability
Published 2022-11-09 · Modified
8.8EPSS 0.016
CVE-2022-41048
Microsoft ODBC Driver Remote Code Execution Vulnerability
Published 2022-11-09 · Modified
8.8EPSS 0.016
CVE-2021-41378
Windows NTFS Remote Code Execution Vulnerability
Published 2021-11-10 · Modified
8.8EPSS 0.016
CVE-2020-0792
An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0715, CVE-2020-0745.
Published 2020-02-11 · Modified
8.8EPSS 0.013
CVE-2020-0981
A security feature bypass vulnerability exists when Windows fails to properly handle token relationships.An attacker who successfully exploited the vulnerability could allow an application with a certain integrity level to execute code at a different integrity level, leading to a sandbox escape.The update addresses the vulnerability by correcting how Windows handles token relationships, aka 'Windows Token Security Feature Bypass Vulnerability'.
Published 2020-04-15 · Modified
8.8EPSS 0.013
CVE-2019-1053
Windows Shell Elevation of Privilege Vulnerability
Published 2019-06-12 · Modified
8.8EPSS 0.013
CVE-2018-8219
An elevation of privilege vulnerability exists when Windows Hyper-V instruction emulation fails to properly enforce privilege levels, aka "Hypervisor Code Integrity Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
Published 2018-06-14 · Modified
8.8EPSS 0.012
CVE-2017-8503
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to escape from the AppContainer sandbox, aka "Microsoft Edge Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8642.
Published 2017-08-08 · Modified
8.8EPSS 0.012
CVE-2021-26865
Windows Container Execution Agent Elevation of Privilege Vulnerability
Published 2021-03-11 · Modified
8.8EPSS 0.011
CVE-2023-21695
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
8.8EPSS 0.010
CVE-2022-22026
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Published 2022-07-12 · Modified
8.8EPSS 0.010
CVE-2021-21552
Dell Wyse Windows Embedded System versions WIE10 LTSC 2019 and earlier contain an improper authorization vulnerability. A local authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass the restricted environment and perform unauthorized actions on the affected system.
Published 2021-05-21 · Modified
8.8EPSS 0.010
CVE-2017-8590
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way that the Windows Common Log File System (CLFS) driver handles objects in memory, aka "Windows CLFS Elevation of Privilege Vulnerability".
Published 2017-07-11 · Modified
8.8EPSS 0.010
CVE-2020-16891
Windows Hyper-V Remote Code Execution Vulnerability
Published 2020-10-16 · Modified
8.8EPSS 0.009
CVE-2021-36967
Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability
Published 2021-09-15 · Modified
8.8EPSS 0.009
CVE-2020-1080
Windows Hyper-V Elevation of Privilege Vulnerability
Published 2020-10-16 · Modified
8.8EPSS 0.009
CVE-2022-23257
Windows Hyper-V Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
8.8EPSS 0.006
CVE-2019-19160
Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into the configure file(rxp).
Published 2020-06-29 · Modified
8.8EPSS 0.006
CVE-2021-36954
Windows Bind Filter Driver Elevation of Privilege Vulnerability
Published 2021-09-15 · Modified
8.8EPSS 0.005
CVE-2022-38016
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
Published 2022-10-11 · Modified
8.8EPSS 0.005
CVE-2021-42283
NTFS Elevation of Privilege Vulnerability
Published 2021-11-10 · Modified
8.8EPSS 0.005
CVE-2016-8008
Privilege escalation vulnerability in Windows 7 and Windows 10 in McAfee Security Scan Plus (SSP) 3.11.376 allows attackers to load a replacement of the version.dll file via McAfee McUICnt.exe onto a Windows system.
Published 2017-03-14 · Modified
8.8EPSS 0.004
CVE-2020-1118
A denial of service vulnerability exists in the Windows implementation of Transport Layer Security (TLS) when it improperly handles certain key exchanges, aka 'Microsoft Windows Transport Layer Security Denial of Service Vulnerability'.
Published 2020-05-21 · Modified
8.6EPSS 0.147
CVE-2021-31977
Windows Hyper-V Denial of Service Vulnerability
Published 2021-06-08 · Modified
8.6EPSS 0.032
CVE-2021-33755
Windows Hyper-V Denial of Service Vulnerability
Published 2021-07-14 · Modified
8.6EPSS 0.031
CVE-2019-5098
An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.29010. A specially crafted pixel shader can cause out-of-bounds memory read. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.
Published 2019-12-05 · Modified
8.6EPSS 0.020
CVE-2019-0887
A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
Published 2019-07-15 · Modified
8.5EPSS 0.710
CVE-2020-0655
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
Published 2020-02-11 · Modified
8.5EPSS 0.657
← Prev23 / 102Next →