VendorsMicrosoftwindows_10all versions
Vulnerabilities

Microsoft Windows 10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4056CVEs
CVE-2022-24540
Windows ALPC Elevation of Privilege Vulnerability
Published 2022-04-15 · Modified
7.0EPSS 0.004
CVE-2022-26827
Windows File Server Resource Management Service Elevation of Privilege Vulnerability
Published 2022-04-15 · Modified
7.0EPSS 0.004
CVE-2023-21771
Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.0EPSS 0.004
CVE-2022-38021
Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
Published 2022-10-11 · Modified
7.0EPSS 0.004
CVE-2022-38027
Windows Storage Elevation of Privilege Vulnerability
Published 2022-10-11 · Modified
7.0EPSS 0.004
CVE-2022-23283
Windows ALPC Elevation of Privilege Vulnerability
Published 2022-03-09 · Modified
7.0EPSS 0.004
CVE-2019-19235
AsLdrSrv.exe in ASUS ATK Package before V1.0.0061 (for Windows 10 notebook PCs) could lead to unsigned code execution with no additional execution. The user must put an application at a particular path, with a particular file name.
Published 2019-12-18 · Modified
7.0EPSS 0.004
CVE-2022-24505
Windows ALPC Elevation of Privilege Vulnerability
Published 2022-03-09 · Modified
7.0EPSS 0.004
CVE-2022-26828
Windows Bluetooth Driver Elevation of Privilege Vulnerability
Published 2022-04-15 · Modified
7.0EPSS 0.004
CVE-2022-26807
Windows Work Folder Service Elevation of Privilege Vulnerability
Published 2022-04-15 · Modified
7.0EPSS 0.003
CVE-2022-24482
Windows ALPC Elevation of Privilege Vulnerability
Published 2022-04-15 · Modified
7.0EPSS 0.003
CVE-2022-44669
Windows Error Reporting Elevation of Privilege Vulnerability
Published 2022-12-13 · Modified
7.0EPSS 0.003
CVE-2015-2511
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2517, CVE-2015-2518, and CVE-2015-2546.
Published 2015-09-09 · Modified
6.91 PoCEPSS 0.039
CVE-2015-2518
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2546.
Published 2015-09-09 · Modified
6.91 PoCEPSS 0.039
CVE-2015-2517
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2511, CVE-2015-2518, and CVE-2015-2546.
Published 2015-09-09 · Modified
6.91 PoCEPSS 0.039
CVE-2015-6100
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-6101.
Published 2015-11-11 · Modified
6.91 PoCEPSS 0.032
CVE-2015-6101
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-6100.
Published 2015-11-11 · Modified
6.91 PoCEPSS 0.031
CVE-2018-8592
An elevation of privilege vulnerability exists in Windows 10 version 1809 when installed from physical media (USB, DVD, etc, aka "Windows Elevation Of Privilege Vulnerability." This affects Windows 10, Windows Server 2019.
Published 2018-11-14 · Modified
6.9EPSS 0.013
CVE-2022-21928
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
6.9EPSS 0.007
CVE-2022-22023
Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability
Published 2022-07-12 · Modified
6.9EPSS 0.006
CVE-2021-3519
A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes.
Published 2021-11-12 · Modified
6.9EPSS 0.002
CVE-2016-7237
Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote authenticated users to cause a denial of service (system hang) via a crafted request, aka "Local Security Authority Subsystem Service Denial of Service Vulnerability."
Published 2016-11-10 · Modified
6.81 PoCEPSS 0.669
CVE-2016-0128
The SAM and LSAD protocol implementations in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 do not properly establish an RPC channel, which allows man-in-the-middle attackers to perform protocol-downgrade attacks and impersonate users by modifying the client-server data stream, aka "Windows SAM and LSAD Downgrade Vulnerability" or "BADLOCK."
Published 2016-04-12 · Modified
6.8EPSS 0.209
CVE-2015-6111
IPSec in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles encryption negotiation, which allows remote authenticated users to cause a denial of service (system hang) via crafted IP traffic, aka "Windows IPSec Denial of Service Vulnerability."
Published 2015-11-11 · Modified
6.8EPSS 0.078
CVE-2018-8438
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8436, CVE-2018-8437.
Published 2018-09-13 · Modified
6.8EPSS 0.072
CVE-2017-8623
Windows Hyper-V in Windows 10 1607, 1703, and Windows Server 2016 allows a denial of service vulnerability when it fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service Vulnerability".
Published 2017-08-08 · Modified
6.8EPSS 0.065
CVE-2019-0678
An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacker could host a website that is used to attempt to exploit the vulnerability, aka 'Microsoft Edge Elevation of Privilege Vulnerability'.
Published 2019-04-08 · Modified
6.8EPSS 0.061
CVE-2019-1230
An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Information Disclosure Vulnerability'.
Published 2019-10-10 · Modified
6.8EPSS 0.058
CVE-2019-0972
Local Security Authority Subsystem Service Denial of Service Vulnerability
Published 2019-06-12 · Modified
6.8EPSS 0.058
CVE-2019-0712
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1309, CVE-2019-1310, CVE-2019-1399.
Published 2019-11-12 · Modified
6.8EPSS 0.056
CVE-2019-1310
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0712, CVE-2019-1309, CVE-2019-1399.
Published 2019-11-12 · Modified
6.8EPSS 0.055
CVE-2019-1309
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0712, CVE-2019-1310, CVE-2019-1399.
Published 2019-11-12 · Modified
6.8EPSS 0.055
CVE-2020-0993
A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries, aka 'Windows DNS Denial of Service Vulnerability'.
Published 2020-04-15 · Modified
6.8EPSS 0.052
CVE-2019-1292
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.
Published 2019-09-11 · Modified
6.8EPSS 0.051
CVE-2019-0716
Windows Denial of Service Vulnerability
Published 2019-08-14 · Modified
6.8EPSS 0.044
CVE-2018-8307
A security feature bypass vulnerability exists when Microsoft WordPad improperly handles embedded OLE objects, aka "WordPad Security Feature Bypass Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-07-11 · Modified
6.8EPSS 0.037
CVE-2021-43216
Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
Published 2021-12-15 · Modified
6.8EPSS 0.032
CVE-2021-24075
Microsoft Windows VMSwitch Denial of Service Vulnerability
Published 2021-02-25 · Modified
6.8EPSS 0.025
CVE-2017-8628
Microsoft Bluetooth Driver in Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703 allows a spoofing vulnerability due to Microsoft's implementation of the Bluetooth stack, aka "Microsoft Bluetooth Driver Spoofing Vulnerability".
Published 2017-09-13 · Modified
6.8EPSS 0.023
CVE-2019-0690
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0695, CVE-2019-0701.
Published 2019-04-08 · Modified
6.8EPSS 0.019
← Prev77 / 102Next →