VendorsMicrosoftwindows_10all versions
Vulnerabilities

Microsoft Windows 10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4056CVEs
CVE-2017-8495
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to bypass Extended Protection for Authentication when Kerberos fails to prevent tampering with the SNAME field during ticket exchange, aka "Kerberos SNAME Security Feature Bypass Vulnerability" or Orpheus' Lyre.
Published 2017-07-11 · Modified
7.5EPSS 0.046
CVE-2020-0909
A denial of service vulnerability exists when Hyper-V on a Windows Server fails to properly handle specially crafted network packets.To exploit the vulnerability, an attacker would send specially crafted network packets to the Hyper-V Server.The security update addresses the vulnerability by resolving the conditions where Hyper-V would fail to properly handle these network packets., aka 'Windows Hyper-V Denial of Service Vulnerability'.
Published 2020-05-21 · Modified
7.5EPSS 0.046
CVE-2019-0865
A denial of service vulnerability exists when SymCrypt improperly handles a specially crafted digital signature.An attacker could exploit the vulnerability by creating a specially crafted connection or message.The security update addresses the vulnerability by correcting the way SymCrypt handles digital signatures., aka 'SymCrypt Denial of Service Vulnerability'.
Published 2019-07-15 · Modified
7.5EPSS 0.045
CVE-2020-1459
Windows ARM Information Disclosure Vulnerability
Published 2020-08-17 · Modified
7.5EPSS 0.045
CVE-2022-21883
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Published 2022-01-11 · Modified
7.5EPSS 0.044
CVE-2019-0637
A security feature bypass vulnerability exists when Windows Defender Firewall incorrectly applies firewall profiles to cellular network connections, aka 'Windows Defender Firewall Security Feature Bypass Vulnerability'.
Published 2019-03-06 · Modified
7.5EPSS 0.043
CVE-2022-21848
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Published 2022-01-11 · Modified
7.5EPSS 0.042
CVE-2019-1255
A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denial of Service Vulnerability'.
Published 2019-09-23 · Modified
7.5EPSS 0.041
CVE-2020-0645
A tampering vulnerability exists when Microsoft IIS Server improperly handles malformed request headers, aka 'Microsoft IIS Server Tampering Vulnerability'.
Published 2020-03-12 · Modified
7.5EPSS 0.039
CVE-2021-24111
.NET Framework Denial of Service Vulnerability
Published 2021-02-25 · Modified
7.5EPSS 0.038
CVE-2021-31183
Windows TCP/IP Driver Denial of Service Vulnerability
Published 2021-07-14 · Modified
7.5EPSS 0.038
CVE-2021-1734
Windows Remote Procedure Call Information Disclosure Vulnerability
Published 2021-02-25 · Modified
7.5EPSS 0.038
CVE-2021-42284
Windows Hyper-V Denial of Service Vulnerability
Published 2021-11-10 · Modified
7.5EPSS 0.037
CVE-2018-0786
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NET Security Feature Bypass Vulnerability."
Published 2018-01-10 · Modified
7.5EPSS 0.037
CVE-2022-34720
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Published 2022-09-13 · Modified
7.5EPSS 0.036
CVE-2022-26832
.NET Framework Denial of Service Vulnerability
Published 2022-04-15 · Modified
7.5EPSS 0.036
CVE-2021-26879
Windows Network Address Translation (NAT) Denial of Service Vulnerability
Published 2021-03-11 · Modified
7.5EPSS 0.036
CVE-2022-26915
Windows Secure Channel Denial of Service Vulnerability
Published 2022-04-15 · Modified
7.5EPSS 0.036
CVE-2021-26433
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
Published 2021-08-12 · Modified
7.5EPSS 0.035
CVE-2022-21904
Windows GDI Information Disclosure Vulnerability
Published 2022-01-11 · Modified
7.5EPSS 0.035
CVE-2021-36926
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
Published 2021-08-12 · Modified
7.5EPSS 0.035
CVE-2021-36932
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
Published 2021-08-12 · Modified
7.5EPSS 0.035
CVE-2021-36933
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
Published 2021-08-12 · Modified
7.5EPSS 0.035
CVE-2022-30150
Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability
Published 2022-06-15 · Modified
7.5EPSS 0.034
CVE-2022-21843
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
7.5EPSS 0.034
CVE-2022-26831
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
Published 2022-04-15 · Modified
7.5EPSS 0.033
CVE-2021-36960
Windows SMB Information Disclosure Vulnerability
Published 2021-09-15 · Modified
7.5EPSS 0.033
CVE-2021-33788
Windows LSA Denial of Service Vulnerability
Published 2021-07-14 · Modified
7.5EPSS 0.033
CVE-2021-34476
Bowser.sys Denial of Service Vulnerability
Published 2021-07-14 · Modified
7.5EPSS 0.033
CVE-2021-34490
Windows TCP/IP Driver Denial of Service Vulnerability
Published 2021-07-14 · Modified
7.5EPSS 0.033
CVE-2021-33772
Windows TCP/IP Driver Denial of Service Vulnerability
Published 2021-07-14 · Modified
7.5EPSS 0.033
CVE-2021-33785
Windows AF_UNIX Socket Provider Denial of Service Vulnerability
Published 2021-07-14 · Modified
7.5EPSS 0.033
CVE-2019-7108
Adobe Flash Player versions 32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .
Published 2019-05-23 · Modified
7.5EPSS 0.032
CVE-2021-31968
Windows Remote Desktop Services Denial of Service Vulnerability
Published 2021-06-08 · Modified
7.5EPSS 0.032
CVE-2022-21911
.NET Framework Denial of Service Vulnerability
Published 2022-01-11 · Modified
7.5EPSS 0.031
CVE-2019-0941
Microsoft IIS Server Denial of Service Vulnerability
Published 2019-06-12 · Modified
7.5EPSS 0.030
CVE-2022-21889
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Published 2022-01-11 · Modified
7.5EPSS 0.030
CVE-2022-21890
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Published 2022-01-11 · Modified
7.5EPSS 0.030
CVE-2021-43222
Microsoft Message Queuing Information Disclosure Vulnerability
Published 2021-12-15 · Modified
7.5EPSS 0.030
CVE-2021-43236
Microsoft Message Queuing Information Disclosure Vulnerability
Published 2021-12-15 · Modified
7.5EPSS 0.030
← Prev69 / 102Next →