VendorsMicrosoftwindows_10any version
Vulnerabilities

Microsoft Windows 10 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3182CVEs
CVE-2022-30140
Windows iSCSI Discovery Service Remote Code Execution Vulnerability
Published 2022-06-15 · Modified
7.5EPSS 0.019
CVE-2022-30146
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-06-15 · Modified
7.5EPSS 0.019
CVE-2022-30149
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-06-15 · Modified
7.5EPSS 0.019
CVE-2022-24534
Win32 Stream Enumeration Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
7.5EPSS 0.019
CVE-2018-5174
In the Windows 10 April 2018 Update, Windows Defender SmartScreen honors the "SEE_MASK_FLAG_NO_UI" flag associated with downloaded files and will not show any UI. Files that are unknown and potentially dangerous will be allowed to run because SmartScreen will not prompt the user for a decision, and if the user is offline all files will be allowed to be opened because Windows won't prompt the user to ask what to do. Firefox incorrectly sets this flag when downloading files, leading to less secure behavior from SmartScreen. Note: this issue only affects Windows 10 users running the April 2018 update or later. It does not affect other Windows users or other operating systems. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
Published 2018-06-11 · Modified
7.5EPSS 0.018
CVE-2023-21816
Windows Active Directory Domain Services API Denial of Service Vulnerability
Published 2023-02-14 · Modified
7.5EPSS 0.017
CVE-2023-36907
Windows Cryptographic Services Information Disclosure Vulnerability
Published 2023-08-08 · Modified
7.5EPSS 0.017
CVE-2023-36905
Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability
Published 2023-08-08 · Modified
7.5EPSS 0.017
CVE-2022-24485
Win32 File Enumeration Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
7.5EPSS 0.017
CVE-2023-36913
Microsoft Message Queuing Information Disclosure Vulnerability
Published 2023-08-08 · Modified
7.5EPSS 0.017
CVE-2023-21813
Windows Secure Channel Denial of Service Vulnerability
Published 2023-02-14 · Modified
7.5EPSS 0.017
CVE-2023-21702
Windows iSCSI Service Denial of Service Vulnerability
Published 2023-02-14 · Modified
7.5EPSS 0.017
CVE-2023-24859
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Published 2023-03-14 · Modified
7.5EPSS 0.017
CVE-2023-21701
Microsoft Protected Extensible Authentication Protocol (PEAP) Denial of Service Vulnerability
Published 2023-02-14 · Modified
7.5EPSS 0.017
CVE-2023-21811
Windows iSCSI Service Denial of Service Vulnerability
Published 2023-02-14 · Modified
7.5EPSS 0.017
CVE-2023-21700
Windows iSCSI Discovery Service Denial of Service Vulnerability
Published 2023-02-14 · Modified
7.5EPSS 0.017
CVE-2022-37978
Windows Active Directory Certificate Services Security Feature Bypass
Published 2022-10-11 · Modified
7.5EPSS 0.015
CVE-2022-22040
Internet Information Services Dynamic Compression Module Denial of Service Vulnerability
Published 2022-07-12 · Modified
7.5EPSS 0.015
CVE-2023-24856
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Published 2023-03-14 · Modified
7.5EPSS 0.015
CVE-2022-30194
Windows WebBrowser Control Remote Code Execution Vulnerability
Published 2022-08-09 · Modified
7.5EPSS 0.015
CVE-2023-24858
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Published 2023-03-14 · Modified
7.5EPSS 0.014
CVE-2022-41118
Windows Scripting Languages Remote Code Execution Vulnerability
Published 2022-11-09 · Modified
7.5EPSS 0.012
CVE-2022-30144
Windows Bluetooth Service Remote Code Execution Vulnerability
Published 2022-08-09 · Modified
7.5EPSS 0.009
CVE-2023-29413
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor service.
Published 2023-04-18 · Modified
7.5EPSS 0.007
CVE-2018-8469
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8463.
Published 2018-09-13 · Modified
7.41 PoCEPSS 0.154
CVE-2021-38665
Remote Desktop Protocol Client Information Disclosure Vulnerability
Published 2021-11-10 · Modified
7.4EPSS 0.070
CVE-2017-3085
Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect.
Published 2017-08-11 · Modified
7.4EPSS 0.045
CVE-2019-0136
Insufficient access control in the Intel(R) PROSet/Wireless WiFi Software driver before version 21.10 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
Published 2019-06-13 · Modified
7.4EPSS 0.041
CVE-2021-31186
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Published 2021-05-11 · Modified
7.4EPSS 0.030
CVE-2022-30209
Windows IIS Server Elevation of Privilege Vulnerability
Published 2022-07-12 · Modified
7.4EPSS 0.026
CVE-2022-30203
Windows Boot Manager Security Feature Bypass Vulnerability
Published 2022-07-12 · Modified
7.4EPSS 0.015
CVE-2023-21820
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
7.4EPSS 0.006
CVE-2016-0018
Microsoft Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 R2, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "DLL Loading Remote Code Execution Vulnerability."
Published 2016-01-13 · Modified
7.3EPSS 0.135
CVE-2022-35793
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2022-08-09 · Modified
7.3EPSS 0.091
CVE-2016-0006
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles reparse points, which allows local users to gain privileges via a crafted application, aka "Windows Mount Point Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0007.
Published 2016-01-13 · Modified
7.31 PoCEPSS 0.040
CVE-2016-3252
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3249, CVE-2016-3254, and CVE-2016-3286.
Published 2016-07-13 · Modified
7.3EPSS 0.038
CVE-2017-8460
Windows PDF in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows information disclosure when a user opens a specially crafted PDF file, aka "Windows PDF Information Disclosure Vulnerability".
Published 2017-06-15 · Modified
7.3EPSS 0.033
CVE-2016-7211
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." a different vulnerability than CVE-2016-3266, CVE-2016-3376, and CVE-2016-7185.
Published 2016-10-14 · Modified
7.3EPSS 0.030
CVE-2016-3249
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3252, CVE-2016-3254, and CVE-2016-3286.
Published 2016-07-13 · Modified
7.3EPSS 0.025
CVE-2016-3250
The kernel-mode drivers in Microsoft Windows Server 2012 and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
Published 2016-07-13 · Modified
7.3EPSS 0.025
← Prev56 / 80Next →