Windows 10 1809
by Microsoft
CVEs (3,876)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-31955 | Med | 0.54 | 5.5 | 0.81 | KEV | Jun 8, 2021 | Windows Kernel Information Disclosure Vulnerability | |
| CVE-2020-17140 | Hig | 0.54 | 8.1 | 0.13 | Dec 10, 2020 | Windows SMB Information Disclosure Vulnerability | ||
| CVE-2019-0943 | Hig | 0.54 | 7.8 | 0.03 | Jun 12, 2019 | An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then… | ||
| CVE-2026-71331 | Hig | 0.53 | 8.1 | 0.00 | Aug 11, 2026 | Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-66802 | Hig | 0.53 | 8.1 | 0.00 | Aug 11, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-65796 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-65789 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-65679 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62889 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62820 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62819 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine | ||
| CVE-2026-62792 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62781 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62778 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-45635 | Hig | 0.53 | 8.1 | 0.01 | Jun 9, 2026 | Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-45599 | Hig | 0.53 | 8.1 | 0.01 | Jun 9, 2026 | Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-40415 | Hig | 0.53 | 8.1 | 0.01 | May 12, 2026 | Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-33827 | Hig | 0.53 | 8.1 | 0.01 | Apr 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-21525 | Med | 0.53 | 6.2 | 0.05 | KEV | Feb 10, 2026 | Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally. | |
| CVE-2026-20856 | Hig | 0.53 | 8.1 | 0.01 | Jan 13, 2026 | Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network. |
- risk 0.54cvss 5.5epss 0.81
Windows Kernel Information Disclosure Vulnerability
- risk 0.54cvss 8.1epss 0.13
Windows SMB Information Disclosure Vulnerability
- risk 0.54cvss 7.8epss 0.03
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then…
- risk 0.53cvss 8.1epss 0.00
Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
- risk 0.53cvss 8.1epss 0.01
Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.
- risk 0.53cvss 8.1epss 0.01
Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 6.2epss 0.05
Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.
- risk 0.53cvss 8.1epss 0.01
Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
Page 32 of 194