Windows 10 1809
by Microsoft
CVEs (3,841)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-30040 | Hig | 0.70 | 8.8 | 0.04 | KEV | May 14, 2024 | Windows MSHTML Platform Security Feature Bypass Vulnerability | |
| CVE-2023-38545 | Cri | 0.70 | 9.8 | 0.78 | Oct 18, 2023 | This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255… | ||
| CVE-2023-32049 | Hig | 0.70 | 8.8 | 0.04 | KEV | Jul 11, 2023 | Windows SmartScreen Security Feature Bypass Vulnerability | |
| CVE-2023-23376 | Hig | 0.70 | 7.8 | 0.11 | KEV | Feb 14, 2023 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2022-34721 | Cri | 0.70 | 9.8 | 0.79 | Sep 13, 2022 | Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | ||
| CVE-2020-1054 | Hig | 0.70 | 7.8 | 0.53 | KEV | May 21, 2020 | An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1143. | |
| CVE-2019-1181 | Cri | 0.70 | 9.8 | 0.76 | Aug 14, 2019 | A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and… | ||
| CVE-2018-8639 | Hig | 0.70 | 7.8 | 0.22 | KEV | Dec 12, 2018 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server… | |
| CVE-2025-26633 | Hig | 0.69 | 7.0 | 0.30 | KEV | Mar 11, 2025 | Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. | |
| CVE-2024-49112 | Cri | 0.69 | 9.8 | 0.71 | Dec 12, 2024 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | ||
| CVE-2024-38063 | Cri | 0.69 | 9.8 | 0.71 | Aug 13, 2024 | Windows TCP/IP Remote Code Execution Vulnerability | ||
| CVE-2024-30088 | Hig | 0.69 | 7.0 | 0.68 | KEV | Jun 11, 2024 | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2024-30051 | Hig | 0.69 | 7.8 | 0.06 | KEV | May 14, 2024 | Windows DWM Core Library Elevation of Privilege Vulnerability | |
| CVE-2024-26169 | Hig | 0.69 | 7.8 | 0.04 | KEV | Mar 12, 2024 | Windows Error Reporting Service Elevation of Privilege Vulnerability | |
| CVE-2022-41073 | Hig | 0.69 | 7.8 | 0.02 | KEV | Nov 9, 2022 | Windows Print Spooler Elevation of Privilege Vulnerability | |
| CVE-2022-24521 | Hig | 0.69 | 7.8 | 0.07 | KEV | Apr 15, 2022 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2021-36955 | Hig | 0.69 | 7.8 | 0.04 | KEV | Sep 15, 2021 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2021-26424 | Cri | 0.69 | 9.9 | 0.61 | Aug 12, 2021 | Windows TCP/IP Remote Code Execution Vulnerability | ||
| CVE-2020-0638 | Hig | 0.69 | 7.8 | 0.03 | KEV | Jan 14, 2020 | An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'. | |
| CVE-2019-1388 | Hig | 0.69 | 7.8 | 0.09 | KEV | Nov 12, 2019 | An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'. |
- risk 0.70cvss 8.8epss 0.04
Windows MSHTML Platform Security Feature Bypass Vulnerability
- risk 0.70cvss 9.8epss 0.78
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255…
- risk 0.70cvss 8.8epss 0.04
Windows SmartScreen Security Feature Bypass Vulnerability
- risk 0.70cvss 7.8epss 0.11
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- risk 0.70cvss 9.8epss 0.79
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
- risk 0.70cvss 7.8epss 0.53
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1143.
- risk 0.70cvss 9.8epss 0.76
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and…
- risk 0.70cvss 7.8epss 0.22
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server…
- risk 0.69cvss 7.0epss 0.30
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
- risk 0.69cvss 9.8epss 0.71
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- risk 0.69cvss 9.8epss 0.71
Windows TCP/IP Remote Code Execution Vulnerability
- risk 0.69cvss 7.0epss 0.68
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.69cvss 7.8epss 0.06
Windows DWM Core Library Elevation of Privilege Vulnerability
- risk 0.69cvss 7.8epss 0.04
Windows Error Reporting Service Elevation of Privilege Vulnerability
- risk 0.69cvss 7.8epss 0.02
Windows Print Spooler Elevation of Privilege Vulnerability
- risk 0.69cvss 7.8epss 0.07
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- risk 0.69cvss 7.8epss 0.04
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- risk 0.69cvss 9.9epss 0.61
Windows TCP/IP Remote Code Execution Vulnerability
- risk 0.69cvss 7.8epss 0.03
An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'.
- risk 0.69cvss 7.8epss 0.09
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'.
Page 3 of 193