VendorsMicrosoftwindows_10all versions
Vulnerabilities

Microsoft Windows 10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4056CVEs
CVE-2020-17052
Scripting Engine Memory Corruption Vulnerability
Published 2020-11-11 · Modified
8.1EPSS 0.027
CVE-2021-34492
Windows Certificate Spoofing Vulnerability
Published 2021-07-14 · Modified
8.1EPSS 0.024
CVE-2022-22038
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2022-07-12 · Modified
8.1EPSS 0.024
CVE-2021-33781
Azure AD Security Feature Bypass Vulnerability
Published 2021-07-14 · Modified
8.1EPSS 0.024
CVE-2022-24545
Windows Kerberos Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
8.1EPSS 0.022
CVE-2020-1056
An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacker could host a website that is used to attempt to exploit the vulnerability, aka 'Microsoft Edge Elevation of Privilege Vulnerability'.
Published 2020-05-21 · Modified
8.1EPSS 0.021
CVE-2022-34714
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Published 2022-08-09 · Modified
8.1EPSS 0.019
CVE-2022-35794
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Published 2022-08-09 · Modified
8.1EPSS 0.019
CVE-2022-35767
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Published 2022-08-09 · Modified
8.1EPSS 0.017
CVE-2022-35766
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Published 2022-08-09 · Modified
8.1EPSS 0.017
CVE-2020-17048
Chakra Scripting Engine Memory Corruption Vulnerability
Published 2020-11-11 · Modified
8.1EPSS 0.016
CVE-2022-41081
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.1EPSS 0.016
CVE-2022-38000
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.1EPSS 0.014
CVE-2022-22035
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.1EPSS 0.013
CVE-2022-34702
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Published 2022-08-09 · Modified
8.1EPSS 0.012
CVE-2022-30198
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.1EPSS 0.012
CVE-2022-33634
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.1EPSS 0.012
CVE-2022-24504
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.1EPSS 0.012
CVE-2022-38047
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.1EPSS 0.012
CVE-2022-44670
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Published 2022-12-13 · Modified
8.1EPSS 0.012
CVE-2022-41039
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-11-09 · Modified
8.1EPSS 0.011
CVE-2022-44676
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Published 2022-12-13 · Modified
8.1EPSS 0.011
CVE-2022-41088
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-11-09 · Modified
8.1EPSS 0.010
CVE-2023-21712
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2023-04-27 · Modified
8.1EPSS 0.010
CVE-2021-33113
Improper input validation for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and Killer(TM) WiFi in Windows 10 and 11 may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access.
Published 2022-02-09 · Modified
8.1EPSS 0.007
CVE-2019-0720
Hyper-V Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
8.0EPSS 0.038
CVE-2018-8209
An information disclosure vulnerability exists when Windows allows a normal user to access the Wireless LAN profile of an administrative user, aka "Windows Wireless Network Profile Information Disclosure Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
Published 2018-06-14 · Modified
8.0EPSS 0.028
CVE-2020-1552
Windows Work Folder Service Elevation of Privilege Vulnerability
Published 2020-08-17 · Modified
8.0EPSS 0.024
CVE-2023-36697
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-10-10 · Modified
8.0EPSS 0.021
CVE-2021-1726
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-02-25 · Modified
8.0EPSS 0.021
CVE-2022-21905
Windows Hyper-V Security Feature Bypass Vulnerability
Published 2022-01-11 · Modified
8.0EPSS 0.007
CVE-2021-40464
Windows Nearby Sharing Elevation of Privilege Vulnerability
Published 2021-10-13 · Modified
8.0EPSS 0.006
CVE-2021-34537
Windows Bluetooth Driver Elevation of Privilege Vulnerability
Published 2021-08-12 · Modified
8.0EPSS 0.005
CVE-2017-8584
Windows 10 1607 and Windows Server 2016 allow an attacker to execute code remotely via a specially crafted WiFi packet aka "HoloLens Remote Code Execution Vulnerability."
Published 2017-07-11 · Modified
7.9EPSS 0.042
CVE-2017-0095
Hyper-V in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly validate vSMB packet data, which allows attackers to execute arbitrary code on a target OS, aka "Hyper-V vSMB Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0021.
Published 2017-03-17 · Modified
7.9EPSS 0.039
CVE-2020-1507
Microsoft COM for Windows Elevation of Privilege Vulnerability
Published 2020-09-11 · Modified
7.9EPSS 0.027
CVE-2022-21995
Windows Hyper-V Remote Code Execution Vulnerability
Published 2022-02-09 · Modified
7.9EPSS 0.010
CVE-2020-1147
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
Published 2020-07-14 · Analyzed
7.8KEV2 PoCEPSS 0.940
CVE-2018-4878
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.
Published 2018-02-06 · Analyzed
7.8KEV3 PoCEPSS 0.895
CVE-2016-0041
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Internet Explorer 10 and 11 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "DLL Loading Remote Code Execution Vulnerability."
Published 2016-02-10 · Modified
7.81 PoCEPSS 0.829
← Prev25 / 102Next →