VendorsMicrosoftwindows_10any version
Vulnerabilities

Microsoft Windows 10 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3182CVEs
CVE-2022-22015
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Published 2022-05-10 · Modified
6.5EPSS 0.025
CVE-2021-28328
Windows DNS Information Disclosure Vulnerability
Published 2021-04-13 · Modified
6.5EPSS 0.025
CVE-2022-35837
Windows Graphics Component Information Disclosure Vulnerability
Published 2022-09-13 · Modified
6.5EPSS 0.025
CVE-2019-1081
Microsoft Browser Information Disclosure Vulnerability
Published 2019-06-12 · Modified
6.5EPSS 0.023
CVE-2022-38006
Windows Graphics Component Information Disclosure Vulnerability
Published 2022-09-13 · Modified
6.5EPSS 0.023
CVE-2023-36909
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Published 2023-08-08 · Modified
6.5EPSS 0.021
CVE-2022-37977
Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
Published 2022-10-11 · Modified
6.5EPSS 0.019
CVE-2021-28444
Windows Hyper-V Security Feature Bypass Vulnerability
Published 2021-04-13 · Modified
6.5EPSS 0.017
CVE-2022-38033
Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability
Published 2022-10-11 · Modified
6.5EPSS 0.017
CVE-2022-35770
Windows NTLM Spoofing Vulnerability
Published 2022-10-11 · Modified
6.5EPSS 0.017
CVE-2021-40460
Windows Remote Procedure Call Runtime Security Feature Bypass Vulnerability
Published 2021-10-13 · Modified
6.5EPSS 0.016
CVE-2022-41097
Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability
Published 2022-11-09 · Modified
6.5EPSS 0.016
CVE-2023-24857
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Published 2023-03-14 · Modified
6.5EPSS 0.015
CVE-2021-38505
Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applications that wish to prevent copied data from being recorded in Cloud History must use specific clipboard formats; and Firefox before versions 94 and ESR 91.3 did not implement them. This could have caused sensitive data to be recorded to a user's Microsoft account. *This bug only affects Firefox for Windows 10+ with Cloud Clipboard enabled. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
Published 2021-12-08 · Modified
6.5EPSS 0.011
CVE-2022-26935
Windows WLAN AutoConfig Service Information Disclosure Vulnerability
Published 2022-05-10 · Modified
6.5EPSS 0.010
CVE-2023-36908
Windows Hyper-V Information Disclosure Vulnerability
Published 2023-08-08 · Modified
6.5EPSS 0.010
CVE-2022-29121
Windows WLAN AutoConfig Service Denial of Service Vulnerability
Published 2022-05-10 · Modified
6.5EPSS 0.009
CVE-2022-38015
Windows Hyper-V Denial of Service Vulnerability
Published 2022-11-09 · Modified
6.5EPSS 0.007
CVE-2022-44679
Windows Graphics Component Information Disclosure Vulnerability
Published 2022-12-13 · Modified
6.5EPSS 0.005
CVE-2021-33110
Improper input validation for some Intel(R) Wireless Bluetooth(R) products and Killer(TM) Bluetooth(R) products in Windows 10 and 11 before version 22.80 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
Published 2022-02-09 · Modified
6.5EPSS 0.005
CVE-2020-15707
GRUB2 contained integer overflows when handling the initrd command, leading to a heap-based buffer overflow.
Published 2020-07-29 · Modified
6.4EPSS 0.016
CVE-2020-15705
GRUB2: avoid loading unsigned kernels when GRUB is booted directly under secureboot without shim
Published 2020-07-29 · Modified
6.4EPSS 0.014
CVE-2020-15706
GRUB2 contains a race condition leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing.
Published 2020-07-29 · Modified
6.4EPSS 0.010
CVE-2022-41086
Windows Group Policy Elevation of Privilege Vulnerability
Published 2022-11-09 · Modified
6.4EPSS 0.003
CVE-2018-0967
A denial of service vulnerability exists in the way that Windows SNMP Service handles malformed SNMP traps, aka "Windows SNMP Service Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-04-12 · Modified
6.3EPSS 0.185
CVE-2017-0185
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0182, CVE-2017-0183, CVE-2017-0184, and CVE-2017-0186.
Published 2017-04-12 · Modified
6.3EPSS 0.057
CVE-2018-0885
The Microsoft Hyper-V Network Switch in 64-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows a denial of service vulnerability due to how input from a privileged user on a guest operating system is validated, aka "Hyper-V Denial of Service Vulnerability".
Published 2018-03-14 · Modified
6.3EPSS 0.053
CVE-2017-0186
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0182, CVE-2017-0183, CVE-2017-0184, and CVE-2017-0185.
Published 2017-04-12 · Modified
6.3EPSS 0.046
CVE-2017-0182
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0183, CVE-2017-0184, CVE-2017-0185, and CVE-2017-0186.
Published 2017-04-12 · Modified
6.3EPSS 0.044
CVE-2017-0183
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0182, CVE-2017-0184, CVE-2017-0185, and CVE-2017-0186.
Published 2017-04-12 · Modified
6.3EPSS 0.044
CVE-2017-0179
A denial of service vulnerability exists when Microsoft Hyper-V running on a Windows 10, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0182, CVE-2017-0183, CVE-2017-0184, CVE-2017-0185, and CVE-2017-0186.
Published 2017-04-12 · Modified
6.3EPSS 0.043
CVE-2021-27079
Windows Media Photo Codec Information Disclosure Vulnerability
Published 2021-04-13 · Modified
6.3EPSS 0.029
CVE-2016-3302
Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607, when the lock screen is enabled, do not properly restrict the loading of web content, which allows physically proximate attackers to execute arbitrary code via a (1) crafted Wi-Fi access point or (2) crafted mobile-broadband device, aka "Windows Lock Screen Elevation of Privilege Vulnerability."
Published 2016-09-14 · Modified
6.3EPSS 0.024
CVE-2016-0049
Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 does not properly validate password changes, which allows remote attackers to bypass authentication by deploying a crafted Key Distribution Center (KDC) and then performing a sign-in action, aka "Windows Kerberos Security Feature Bypass."
Published 2016-02-10 · Modified
6.21 PoCEPSS 0.131
CVE-2020-16910
Windows Security Feature Bypass Vulnerability
Published 2020-10-16 · Modified
6.2EPSS 0.028
CVE-2019-0635
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.
Published 2019-03-06 · Modified
6.2EPSS 0.024
CVE-2019-0928
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'.
Published 2019-09-11 · Modified
6.2EPSS 0.017
CVE-2021-33765
Windows Installer Spoofing Vulnerability
Published 2021-07-14 · Modified
6.2EPSS 0.007
CVE-2021-26413
Windows Installer Spoofing Vulnerability
Published 2021-04-13 · Modified
6.2EPSS 0.007
CVE-2023-21697
Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability
Published 2023-02-14 · Modified
6.2EPSS 0.005
← Prev65 / 80Next →