VendorsMicrosoftwindows_10all versions
Vulnerabilities

Microsoft Windows 10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4056CVEs
CVE-2021-28312
Windows NTFS Denial of Service Vulnerability
Published 2021-04-13 · Modified
6.5EPSS 0.066
CVE-2020-0853
An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails to properly handle objects in memory, aka 'Windows Imaging Component Information Disclosure Vulnerability'.
Published 2020-03-12 · Modified
6.5EPSS 0.066
CVE-2019-0614
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0774.
Published 2019-04-08 · Modified
6.5EPSS 0.066
CVE-2019-0746
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge, aka 'Scripting Engine Information Disclosure Vulnerability'.
Published 2019-04-08 · Modified
6.5EPSS 0.066
CVE-2019-0930
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory, aka 'Internet Explorer Information Disclosure Vulnerability'.
Published 2019-05-16 · Modified
6.5EPSS 0.066
CVE-2021-28442
Windows TCP/IP Information Disclosure Vulnerability
Published 2021-04-13 · Modified
6.5EPSS 0.065
CVE-2020-1397
An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails to properly handle objects in memory, aka 'Windows Imaging Component Information Disclosure Vulnerability'.
Published 2020-07-14 · Modified
6.5EPSS 0.064
CVE-2020-0880
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0774, CVE-2020-0874, CVE-2020-0879, CVE-2020-0882.
Published 2020-03-12 · Modified
6.5EPSS 0.063
CVE-2020-0882
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0774, CVE-2020-0874, CVE-2020-0879, CVE-2020-0880.
Published 2020-03-12 · Modified
6.5EPSS 0.063
CVE-2019-1356
An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory, aka 'Microsoft Edge based on Edge HTML Information Disclosure Vulnerability'.
Published 2019-10-10 · Modified
6.5EPSS 0.062
CVE-2019-0821
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0703, CVE-2019-0704.
Published 2019-04-09 · Modified
6.5EPSS 0.062
CVE-2017-8587
Windows Explorer in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511 allows a denial of service vulnerability when it attempts to open a non-existent file, aka "Windows Explorer Denial of Service Vulnerability".
Published 2017-07-11 · Modified
6.5EPSS 0.059
CVE-2020-0952
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
Published 2020-04-15 · Modified
6.5EPSS 0.059
CVE-2020-1232
An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosure Vulnerability'.
Published 2020-06-09 · Modified
6.5EPSS 0.059
CVE-2020-0774
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0874, CVE-2020-0879, CVE-2020-0880, CVE-2020-0882.
Published 2020-03-12 · Modified
6.5EPSS 0.059
CVE-2019-1299
An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory, aka 'Microsoft Edge based on Edge HTML Information Disclosure Vulnerability'.
Published 2019-09-11 · Modified
6.5EPSS 0.058
CVE-2019-1286
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1252.
Published 2019-09-11 · Modified
6.5EPSS 0.058
CVE-2019-1465
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1466, CVE-2019-1467.
Published 2019-12-10 · Modified
6.5EPSS 0.056
CVE-2019-1466
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1465, CVE-2019-1467.
Published 2019-12-10 · Modified
6.5EPSS 0.056
CVE-2019-1467
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1465, CVE-2019-1466.
Published 2019-12-10 · Modified
6.5EPSS 0.056
CVE-2018-8276
A security feature bypass vulnerability exists in the Microsoft Chakra scripting engine that allows Control Flow Guard (CFG) to be bypassed, aka "Scripting Engine Security Feature Bypass Vulnerability." This affects Microsoft Edge, ChakraCore.
Published 2018-07-11 · Modified
6.5EPSS 0.056
CVE-2019-0704
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0703, CVE-2019-0821.
Published 2019-04-08 · Modified
6.5EPSS 0.056
CVE-2018-8113
A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mark of the Web Tagging (MOTW), aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11.
Published 2018-06-14 · Modified
6.5EPSS 0.054
CVE-2019-0990
Chakra Scripting Engine Memory Corruption Vulnerability
Published 2019-06-12 · Modified
6.5EPSS 0.054
CVE-2019-1023
Scripting Engine Information Disclosure Vulnerability
Published 2019-06-12 · Modified
6.5EPSS 0.054
CVE-2017-8602
Microsoft browsers on Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a spoofing vulnerability in the way they parse HTTP content, aka "Microsoft Browser Spoofing Vulnerability."
Published 2017-07-11 · Modified
6.5EPSS 0.053
CVE-2020-1433
An information disclosure vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka 'Microsoft Edge PDF Information Disclosure Vulnerability'.
Published 2020-07-14 · Modified
6.5EPSS 0.053
CVE-2020-1348
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
Published 2020-06-09 · Modified
6.5EPSS 0.052
CVE-2019-1411
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1432.
Published 2019-11-12 · Modified
6.5EPSS 0.052
CVE-2020-1468
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
Published 2020-07-14 · Modified
6.5EPSS 0.052
CVE-2017-8599
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page with malicious content when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability".
Published 2017-07-11 · Modified
6.5EPSS 0.051
CVE-2017-2938
Adobe Flash Player versions 24.0.0.186 and earlier have a security bypass vulnerability related to handling TCP connections.
Published 2017-01-11 · Modified
6.5EPSS 0.051
CVE-2020-1179
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0963, CVE-2020-1141, CVE-2020-1145.
Published 2020-05-21 · Modified
6.5EPSS 0.050
CVE-2019-7090
Flash Player Desktop Runtime versions 32.0.0.114 and earlier, Flash Player for Google Chrome versions 32.0.0.114 and earlier, and Flash Player for Microsoft Edge and Internet Explorer 11 versions 32.0.0.114 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
Published 2019-05-24 · Modified
6.5EPSS 0.048
CVE-2020-0963
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1141, CVE-2020-1145, CVE-2020-1179.
Published 2020-05-21 · Modified
6.5EPSS 0.046
CVE-2020-1256
Windows GDI Information Disclosure Vulnerability
Published 2020-09-11 · Modified
6.5EPSS 0.046
CVE-2020-1097
Windows Graphics Component Information Disclosure Vulnerability
Published 2020-09-11 · Modified
6.5EPSS 0.046
CVE-2016-4271
Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-4277 and CVE-2016-4278, aka a "local-with-filesystem Flash sandbox bypass" issue.
Published 2016-09-14 · Modified
6.5EPSS 0.046
CVE-2020-1091
Windows Graphics Component Information Disclosure Vulnerability
Published 2020-09-11 · Modified
6.5EPSS 0.045
CVE-2021-28323
Windows DNS Information Disclosure Vulnerability
Published 2021-04-13 · Modified
6.5EPSS 0.043
← Prev80 / 102Next →