Windows 10 1809
by Microsoft
CVEs (3,876)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-33765 | Med | 0.40 | 6.2 | 0.01 | Jul 14, 2021 | Windows Installer Spoofing Vulnerability | ||
| CVE-2021-31961 | Med | 0.40 | 6.1 | 0.01 | Jul 14, 2021 | Windows InstallService Elevation of Privilege Vulnerability | ||
| CVE-2021-26413 | Med | 0.40 | 6.2 | 0.01 | Apr 13, 2021 | Windows Installer Spoofing Vulnerability | ||
| CVE-2021-26892 | Med | 0.40 | 6.2 | 0.01 | Mar 11, 2021 | Windows Extensible Firmware Interface Security Feature Bypass Vulnerability | ||
| CVE-2021-26886 | Med | 0.40 | 6.1 | 0.01 | Mar 11, 2021 | User Profile Service Denial of Service Vulnerability | ||
| CVE-2020-1598 | Med | 0.40 | 6.1 | 0.01 | Sep 11, 2020 | An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could… | ||
| CVE-2019-1125 | Med | 0.40 | 5.6 | 0.05 | Sep 3, 2019 | An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would… | ||
| CVE-2025-27735 | Med | 0.39 | 6.0 | 0.00 | Apr 8, 2025 | Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2025-21350 | Med | 0.39 | 5.9 | 0.02 | Feb 11, 2025 | Windows Kerberos Denial of Service Vulnerability | ||
| CVE-2025-21347 | Med | 0.39 | 6.0 | 0.01 | Feb 11, 2025 | Windows Deployment Services Denial of Service Vulnerability | ||
| CVE-2022-37985 | Med | 0.39 | 5.5 | 0.39 | Oct 11, 2022 | Windows Graphics Component Information Disclosure Vulnerability | ||
| CVE-2022-34709 | Med | 0.39 | 6.0 | 0.01 | Aug 9, 2022 | Windows Defender Credential Guard Security Feature Bypass Vulnerability | ||
| CVE-2019-1153 | Med | 0.39 | 5.5 | 0.03 | Aug 14, 2019 | An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this… | ||
| CVE-2019-1148 | Med | 0.39 | 5.5 | 0.03 | Aug 14, 2019 | An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this… | ||
| CVE-2026-68819 | Med | 0.38 | 5.9 | 0.01 | Aug 11, 2026 | Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network. | ||
| CVE-2025-48823 | Med | 0.38 | 5.9 | 0.01 | Jul 8, 2025 | Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-29954 | Med | 0.38 | 5.9 | 0.01 | May 13, 2025 | Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. | ||
| CVE-2025-27471 | Med | 0.38 | 5.9 | 0.01 | Apr 8, 2025 | Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network. | ||
| CVE-2025-21242 | Med | 0.38 | 5.9 | 0.02 | Jan 14, 2025 | Windows Kerberos Information Disclosure Vulnerability | ||
| CVE-2024-21344 | Med | 0.38 | 5.9 | 0.02 | Feb 13, 2024 | Windows Network Address Translation (NAT) Denial of Service Vulnerability |
- risk 0.40cvss 6.2epss 0.01
Windows Installer Spoofing Vulnerability
- risk 0.40cvss 6.1epss 0.01
Windows InstallService Elevation of Privilege Vulnerability
- risk 0.40cvss 6.2epss 0.01
Windows Installer Spoofing Vulnerability
- risk 0.40cvss 6.2epss 0.01
Windows Extensible Firmware Interface Security Feature Bypass Vulnerability
- risk 0.40cvss 6.1epss 0.01
User Profile Service Denial of Service Vulnerability
- risk 0.40cvss 6.1epss 0.01
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could…
- risk 0.40cvss 5.6epss 0.05
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would…
- risk 0.39cvss 6.0epss 0.00
Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
- risk 0.39cvss 5.9epss 0.02
Windows Kerberos Denial of Service Vulnerability
- risk 0.39cvss 6.0epss 0.01
Windows Deployment Services Denial of Service Vulnerability
- risk 0.39cvss 5.5epss 0.39
Windows Graphics Component Information Disclosure Vulnerability
- risk 0.39cvss 6.0epss 0.01
Windows Defender Credential Guard Security Feature Bypass Vulnerability
- risk 0.39cvss 5.5epss 0.03
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this…
- risk 0.39cvss 5.5epss 0.03
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this…
- risk 0.38cvss 5.9epss 0.01
Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.
- risk 0.38cvss 5.9epss 0.01
Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a network.
- risk 0.38cvss 5.9epss 0.01
Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
- risk 0.38cvss 5.9epss 0.01
Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network.
- risk 0.38cvss 5.9epss 0.02
Windows Kerberos Information Disclosure Vulnerability
- risk 0.38cvss 5.9epss 0.02
Windows Network Address Translation (NAT) Denial of Service Vulnerability
Page 152 of 194