VendorsMicrosoftwindows_10all versions
Vulnerabilities

Microsoft Windows 10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4056CVEs
CVE-2023-21701
Microsoft Protected Extensible Authentication Protocol (PEAP) Denial of Service Vulnerability
Published 2023-02-14 · Modified
7.5EPSS 0.017
CVE-2023-21702
Windows iSCSI Service Denial of Service Vulnerability
Published 2023-02-14 · Modified
7.5EPSS 0.017
CVE-2023-21811
Windows iSCSI Service Denial of Service Vulnerability
Published 2023-02-14 · Modified
7.5EPSS 0.017
CVE-2023-24859
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Published 2023-03-14 · Modified
7.5EPSS 0.017
CVE-2023-21813
Windows Secure Channel Denial of Service Vulnerability
Published 2023-02-14 · Modified
7.5EPSS 0.017
CVE-2022-37978
Windows Active Directory Certificate Services Security Feature Bypass
Published 2022-10-11 · Modified
7.5EPSS 0.015
CVE-2022-22040
Internet Information Services Dynamic Compression Module Denial of Service Vulnerability
Published 2022-07-12 · Modified
7.5EPSS 0.015
CVE-2023-24856
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Published 2023-03-14 · Modified
7.5EPSS 0.015
CVE-2022-30194
Windows WebBrowser Control Remote Code Execution Vulnerability
Published 2022-08-09 · Modified
7.5EPSS 0.015
CVE-2023-24858
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Published 2023-03-14 · Modified
7.5EPSS 0.014
CVE-2022-24495
Windows Direct Show Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
7.5EPSS 0.013
CVE-2022-41118
Windows Scripting Languages Remote Code Execution Vulnerability
Published 2022-11-09 · Modified
7.5EPSS 0.012
CVE-2022-30144
Windows Bluetooth Service Remote Code Execution Vulnerability
Published 2022-08-09 · Modified
7.5EPSS 0.009
CVE-2023-29413
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor service.
Published 2023-04-18 · Modified
7.5EPSS 0.007
CVE-2018-8469
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8463.
Published 2018-09-13 · Modified
7.41 PoCEPSS 0.154
CVE-2018-8463
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8469.
Published 2018-09-13 · Modified
7.41 PoCEPSS 0.154
CVE-2021-38665
Remote Desktop Protocol Client Information Disclosure Vulnerability
Published 2021-11-10 · Modified
7.4EPSS 0.070
CVE-2017-3085
Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect.
Published 2017-08-11 · Modified
7.4EPSS 0.045
CVE-2019-0136
Insufficient access control in the Intel(R) PROSet/Wireless WiFi Software driver before version 21.10 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
Published 2019-06-13 · Modified
7.4EPSS 0.041
CVE-2021-31186
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Published 2021-05-11 · Modified
7.4EPSS 0.030
CVE-2022-30209
Windows IIS Server Elevation of Privilege Vulnerability
Published 2022-07-12 · Modified
7.4EPSS 0.026
CVE-2022-26913
Windows Authentication Information Disclosure Vulnerability
Published 2022-05-10 · Modified
7.4EPSS 0.025
CVE-2020-0917
An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0918.
Published 2020-04-15 · Modified
7.4EPSS 0.016
CVE-2022-30203
Windows Boot Manager Security Feature Bypass Vulnerability
Published 2022-07-12 · Modified
7.4EPSS 0.015
CVE-2020-0918
An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0917.
Published 2020-04-15 · Modified
7.4EPSS 0.013
CVE-2023-21820
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
7.4EPSS 0.006
CVE-2016-0018
Microsoft Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 R2, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "DLL Loading Remote Code Execution Vulnerability."
Published 2016-01-13 · Modified
7.3EPSS 0.135
CVE-2022-35793
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2022-08-09 · Modified
7.3EPSS 0.091
CVE-2016-0006
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles reparse points, which allows local users to gain privileges via a crafted application, aka "Windows Mount Point Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0007.
Published 2016-01-13 · Modified
7.31 PoCEPSS 0.040
CVE-2016-3252
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3249, CVE-2016-3254, and CVE-2016-3286.
Published 2016-07-13 · Modified
7.3EPSS 0.038
CVE-2017-8460
Windows PDF in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows information disclosure when a user opens a specially crafted PDF file, aka "Windows PDF Information Disclosure Vulnerability".
Published 2017-06-15 · Modified
7.3EPSS 0.033
CVE-2016-7211
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." a different vulnerability than CVE-2016-3266, CVE-2016-3376, and CVE-2016-7185.
Published 2016-10-14 · Modified
7.3EPSS 0.030
CVE-2020-1574
Microsoft Windows Codecs Library Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
7.3EPSS 0.026
CVE-2016-3249
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3252, CVE-2016-3254, and CVE-2016-3286.
Published 2016-07-13 · Modified
7.3EPSS 0.025
CVE-2016-3250
The kernel-mode drivers in Microsoft Windows Server 2012 and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
Published 2016-07-13 · Modified
7.3EPSS 0.025
CVE-2016-3286
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3249, CVE-2016-3252, and CVE-2016-3254.
Published 2016-07-13 · Modified
7.3EPSS 0.025
CVE-2017-8494
Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a locally-authenticated attacker to run a specially crafted application on a targeted system when Windows Secure Kernel Mode fails to properly handle objects in memory, aka "Windows Elevation of Privilege Vulnerability".
Published 2017-06-15 · Modified
7.3EPSS 0.019
CVE-2017-0298
A DCOM object in Helppane.exe in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016, when configured to run as the interactive user, allows an authenticated attacker to run arbitrary code in another user's session, aka "Windows COM Session Elevation of Privilege Vulnerability."
Published 2017-06-15 · Modified
7.3EPSS 0.019
CVE-2022-30170
Windows Credential Roaming Service Elevation of Privilege Vulnerability
Published 2022-09-13 · Modified
7.3EPSS 0.016
CVE-2016-1014
Untrusted search path vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows local users to gain privileges via a Trojan horse resource in an unspecified directory.
Published 2016-04-09 · Modified
7.3EPSS 0.012
← Prev71 / 102Next →