VendorsMicrosoftwindows_10any version
Vulnerabilities

Microsoft Windows 10 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3182CVEs
CVE-2020-1348
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
Published 2020-06-09 · Modified
6.5EPSS 0.052
CVE-2019-1411
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1432.
Published 2019-11-12 · Modified
6.5EPSS 0.052
CVE-2020-1468
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
Published 2020-07-14 · Modified
6.5EPSS 0.052
CVE-2017-8599
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page with malicious content when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability".
Published 2017-07-11 · Modified
6.5EPSS 0.051
CVE-2017-2938
Adobe Flash Player versions 24.0.0.186 and earlier have a security bypass vulnerability related to handling TCP connections.
Published 2017-01-11 · Modified
6.5EPSS 0.051
CVE-2020-1179
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0963, CVE-2020-1141, CVE-2020-1145.
Published 2020-05-21 · Modified
6.5EPSS 0.050
CVE-2019-7090
Flash Player Desktop Runtime versions 32.0.0.114 and earlier, Flash Player for Google Chrome versions 32.0.0.114 and earlier, and Flash Player for Microsoft Edge and Internet Explorer 11 versions 32.0.0.114 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
Published 2019-05-24 · Modified
6.5EPSS 0.048
CVE-2020-0963
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1141, CVE-2020-1145, CVE-2020-1179.
Published 2020-05-21 · Modified
6.5EPSS 0.046
CVE-2020-1256
Windows GDI Information Disclosure Vulnerability
Published 2020-09-11 · Modified
6.5EPSS 0.046
CVE-2020-1097
Windows Graphics Component Information Disclosure Vulnerability
Published 2020-09-11 · Modified
6.5EPSS 0.046
CVE-2016-4271
Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-4277 and CVE-2016-4278, aka a "local-with-filesystem Flash sandbox bypass" issue.
Published 2016-09-14 · Modified
6.5EPSS 0.046
CVE-2020-1091
Windows Graphics Component Information Disclosure Vulnerability
Published 2020-09-11 · Modified
6.5EPSS 0.045
CVE-2021-28323
Windows DNS Information Disclosure Vulnerability
Published 2021-04-13 · Modified
6.5EPSS 0.043
CVE-2019-1010
Windows GDI Information Disclosure Vulnerability
Published 2019-06-12 · Modified
6.5EPSS 0.043
CVE-2019-1012
Windows GDI Information Disclosure Vulnerability
Published 2019-06-12 · Modified
6.5EPSS 0.043
CVE-2019-1050
Windows GDI Information Disclosure Vulnerability
Published 2019-06-12 · Modified
6.5EPSS 0.043
CVE-2016-4277
Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-4271 and CVE-2016-4278.
Published 2016-09-14 · Modified
6.5EPSS 0.042
CVE-2017-3080
Adobe Flash Player versions 26.0.0.131 and earlier have a security bypass vulnerability related to the Flash API used by Internet Explorer. Successful exploitation could lead to information disclosure.
Published 2017-07-14 · Modified
6.5EPSS 0.042
CVE-2018-4933
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
Published 2018-05-19 · Modified
6.5EPSS 0.041
CVE-2016-4278
Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-4271 and CVE-2016-4277.
Published 2016-09-14 · Modified
6.5EPSS 0.041
CVE-2019-0761
A security feature bypass vulnerability exists when Internet Explorer fails to validate the correct Security Zone of requests for specific URLs, aka 'Internet Explorer Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0768.
Published 2019-04-09 · Modified
6.5EPSS 0.039
CVE-2017-3100
Adobe Flash Player versions 26.0.0.131 and earlier have an exploitable memory corruption vulnerability in the Action Script 2 BitmapData class. Successful exploitation could lead to memory address disclosure.
Published 2017-07-14 · Modified
6.5EPSS 0.037
CVE-2017-11305
A regression affecting Adobe Flash Player version 27.0.0.187 (and earlier versions) causes the unintended reset of the global settings preference file when a user clears browser data.
Published 2017-12-13 · Modified
6.5EPSS 0.036
CVE-2019-0764
A tampering vulnerability exists when Microsoft browsers do not properly validate input under specific conditions, aka 'Microsoft Browsers Tampering Vulnerability'.
Published 2019-04-09 · Modified
6.5EPSS 0.036
CVE-2021-1679
Windows CryptoAPI Denial of Service Vulnerability
Published 2021-01-12 · Modified
6.5EPSS 0.035
CVE-2019-0921
An spoofing vulnerability exists when Internet Explorer improperly handles URLs, aka 'Internet Explorer Spoofing Vulnerability'.
Published 2019-05-16 · Modified
6.5EPSS 0.033
CVE-2021-34507
Windows Remote Assistance Information Disclosure Vulnerability
Published 2021-07-14 · Modified
6.5EPSS 0.032
CVE-2022-29112
Windows Graphics Component Information Disclosure Vulnerability
Published 2022-05-10 · Modified
6.5EPSS 0.032
CVE-2021-24080
Windows Trust Verification API Denial of Service Vulnerability
Published 2021-02-25 · Modified
6.5EPSS 0.031
CVE-2022-26936
Windows Server Service Information Disclosure Vulnerability
Published 2022-05-10 · Modified
6.5EPSS 0.029
CVE-2021-33783
Windows SMB Information Disclosure Vulnerability
Published 2021-07-14 · Modified
6.5EPSS 0.028
CVE-2022-21915
Windows GDI+ Information Disclosure Vulnerability
Published 2022-01-11 · Modified
6.5EPSS 0.027
CVE-2021-41332
Windows Print Spooler Information Disclosure Vulnerability
Published 2021-10-13 · Modified
6.5EPSS 0.027
CVE-2021-38629
Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
Published 2021-09-15 · Modified
6.5EPSS 0.027
CVE-2022-22042
Windows Hyper-V Information Disclosure Vulnerability
Published 2022-07-12 · Modified
6.5EPSS 0.027
CVE-2021-24082
Microsoft.PowerShell.Utility Module WDAC Security Feature Bypass Vulnerability
Published 2021-02-25 · Modified
6.5EPSS 0.026
CVE-2022-44707
Windows Kernel Denial of Service Vulnerability
Published 2022-12-13 · Modified
6.5EPSS 0.026
CVE-2017-0174
Windows NetBIOS in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a denial of service vulnerability when it improperly handles NetBIOS packets, aka "Windows NetBIOS Denial of Service Vulnerability".
Published 2017-08-08 · Modified
6.5EPSS 0.026
CVE-2022-24498
Windows iSCSI Target Service Information Disclosure Vulnerability
Published 2022-04-15 · Modified
6.5EPSS 0.026
CVE-2022-30208
Windows Security Account Manager (SAM) Denial of Service Vulnerability
Published 2022-07-12 · Modified
6.5EPSS 0.025
← Prev64 / 80Next →