VendorsMicrosoftwindows_10all versions
Vulnerabilities

Microsoft Windows 10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4056CVEs
CVE-2016-4160
Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1096, CVE-2016-1098, CVE-2016-1099, CVE-2016-1100, CVE-2016-1102, CVE-2016-1104, CVE-2016-4109, CVE-2016-4111, CVE-2016-4112, CVE-2016-4113, CVE-2016-4114, CVE-2016-4115, CVE-2016-4120, CVE-2016-4161, CVE-2016-4162, and CVE-2016-4163.
Published 2016-06-16 · Modified
9.8EPSS 0.063
CVE-2016-4163
Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1096, CVE-2016-1098, CVE-2016-1099, CVE-2016-1100, CVE-2016-1102, CVE-2016-1104, CVE-2016-4109, CVE-2016-4111, CVE-2016-4112, CVE-2016-4113, CVE-2016-4114, CVE-2016-4115, CVE-2016-4120, CVE-2016-4160, CVE-2016-4161, and CVE-2016-4162.
Published 2016-06-16 · Modified
9.8EPSS 0.063
CVE-2016-4162
Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1096, CVE-2016-1098, CVE-2016-1099, CVE-2016-1100, CVE-2016-1102, CVE-2016-1104, CVE-2016-4109, CVE-2016-4111, CVE-2016-4112, CVE-2016-4113, CVE-2016-4114, CVE-2016-4115, CVE-2016-4120, CVE-2016-4160, CVE-2016-4161, and CVE-2016-4163.
Published 2016-06-16 · Modified
9.8EPSS 0.063
CVE-2016-4120
Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1096, CVE-2016-1098, CVE-2016-1099, CVE-2016-1100, CVE-2016-1102, CVE-2016-1104, CVE-2016-4109, CVE-2016-4111, CVE-2016-4112, CVE-2016-4113, CVE-2016-4114, CVE-2016-4115, CVE-2016-4160, CVE-2016-4161, CVE-2016-4162, and CVE-2016-4163.
Published 2016-06-16 · Modified
9.8EPSS 0.063
CVE-2016-4161
Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1096, CVE-2016-1098, CVE-2016-1099, CVE-2016-1100, CVE-2016-1102, CVE-2016-1104, CVE-2016-4109, CVE-2016-4111, CVE-2016-4112, CVE-2016-4113, CVE-2016-4114, CVE-2016-4115, CVE-2016-4120, CVE-2016-4160, CVE-2016-4162, and CVE-2016-4163.
Published 2016-06-16 · Modified
9.8EPSS 0.063
CVE-2022-21849
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.8EPSS 0.062
CVE-2017-11899
Device Guard in Windows 10 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerability due to the way untrusted files are handled, aka "Microsoft Windows Security Feature Bypass Vulnerability".
Published 2017-12-12 · Modified
9.8EPSS 0.058
CVE-2021-36965
Windows WLAN AutoConfig Service Remote Code Execution Vulnerability
Published 2021-09-15 · Modified
9.8EPSS 0.046
CVE-2022-22012
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.8EPSS 0.040
CVE-2019-0736
Windows DHCP Client Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
9.8EPSS 0.040
CVE-2021-31962
Kerberos AppContainer Security Feature Bypass Vulnerability
Published 2021-06-08 · Modified
9.8EPSS 0.038
CVE-2022-29130
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.8EPSS 0.038
CVE-2020-17090
Microsoft Defender for Endpoint Security Feature Bypass Vulnerability
Published 2020-11-11 · Modified
9.8EPSS 0.033
CVE-2021-1694
Windows Update Stack Elevation of Privilege Vulnerability
Published 2021-01-12 · Modified
9.8EPSS 0.032
CVE-2021-33757
Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnerability
Published 2021-07-14 · Modified
9.8EPSS 0.029
CVE-2021-24077
Windows Fax Service Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
9.8EPSS 0.029
CVE-2022-34722
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
9.8EPSS 0.028
CVE-2021-43215
iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution
Published 2021-12-15 · Modified
9.8EPSS 0.027
CVE-2020-17040
Windows Hyper-V Security Feature Bypass Vulnerability
Published 2020-11-11 · Modified
9.8EPSS 0.027
CVE-2022-30133
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
Published 2022-08-09 · Modified
9.8EPSS 0.027
CVE-2021-27092
Azure AD Web Sign-in Security Feature Bypass Vulnerability
Published 2021-04-13 · Modified
9.8EPSS 0.026
CVE-2023-36910
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-08-08 · Modified
9.8EPSS 0.025
CVE-2021-1722
Windows Fax Service Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
9.8EPSS 0.024
CVE-2023-21803
Windows iSCSI Discovery Service Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
9.8EPSS 0.018
CVE-2023-36911
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-08-08 · Modified
9.8EPSS 0.017
CVE-2023-36903
Windows System Assessment Tool Elevation of Privilege Vulnerability
Published 2023-08-08 · Modified
9.8EPSS 0.016
CVE-2023-29411
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface.
Published 2023-04-18 · Modified
9.8EPSS 0.013
CVE-2023-29412
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface.
Published 2023-04-18 · Modified
9.8EPSS 0.012
CVE-2022-42971
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)
Published 2023-02-01 · Modified
9.8EPSS 0.011
CVE-2022-42970
A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)
Published 2023-02-01 · Modified
9.8EPSS 0.007
CVE-2020-7808
RAONWIZ Inc K Upload, arguments modiffication via missing support for integrity check vulnerability
Published 2020-05-21 · Modified
9.8EPSS 0.007
CVE-2015-2426
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Driver Vulnerability."
Published 2015-07-20 · Analyzed
9.3KEV1 PoCEPSS 0.866
CVE-2018-1000006
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that register custom protocol handlers can be tricked in arbitrary command execution if the user clicks on a specially crafted URL. This has been fixed in versions 1.8.2-beta.4, 1.7.11, and 1.6.16.
Published 2018-01-24 · Modified
9.32 PoCEPSS 0.845
CVE-2017-0290
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 does not properly scan a specially crafted file leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability."
Published 2017-05-09 · Modified
9.31 PoCEPSS 0.814
CVE-2022-21972
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.3EPSS 0.793
CVE-2019-1358
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1359.
Published 2019-10-10 · Modified
9.3EPSS 0.759
CVE-2020-1421
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
Published 2020-07-14 · Modified
9.3EPSS 0.745
CVE-2016-0117
The PDF library in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted PDF document, aka "Windows Remote Code Execution Vulnerability."
Published 2016-03-09 · Modified
9.3EPSS 0.719
CVE-2022-23270
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.3EPSS 0.704
CVE-2016-7212
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow remote attackers to execute arbitrary code via a crafted image file, aka "Windows Remote Code Execution Vulnerability."
Published 2016-11-10 · Modified
9.3EPSS 0.698
← Prev3 / 102Next →