Windows 10 1909
by Microsoft
CVEs (4,279)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-0073 | Med | 0.36 | 5.0 | 0.05 | Oct 14, 2016 | The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, aka "Windows Kernel… | ||
| CVE-2016-3299 | Med | 0.36 | 5.3 | 0.14 | Aug 9, 2016 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow remote attackers to hijack network traffic or bypass intended Enhanced Protected Mode (EPM) or… | ||
| CVE-2016-0181 | Med | 0.36 | 5.5 | 0.02 | May 11, 2016 | Microsoft Windows 10 Gold and 1511 allows local users to bypass the Virtual Secure Mode Hypervisor Code Integrity (HVCI) protection mechanism and perform RWX markings of kernel-mode pages via a crafted application, aka "Hypervisor Code Integrity Security Feature Bypass." | ||
| CVE-2025-47160 | Med | 0.35 | 5.4 | 0.01 | Jun 10, 2025 | Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2025-29956 | Med | 0.35 | 5.4 | 0.01 | May 13, 2025 | Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-27472 | Med | 0.35 | 5.4 | 0.02 | Apr 8, 2025 | Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2024-35270 | Med | 0.35 | 5.3 | 0.01 | Jul 9, 2024 | Windows iSCSI Service Denial of Service Vulnerability | ||
| CVE-2024-21313 | Med | 0.35 | 5.3 | 0.01 | Jan 9, 2024 | Windows TCP/IP Information Disclosure Vulnerability | ||
| CVE-2023-44216 | Med | 0.35 | 5.3 | 0.02 | Sep 27, 2023 | PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can… | ||
| CVE-2023-35384 | Med | 0.35 | 5.4 | 0.02 | Aug 8, 2023 | Windows HTML Platforms Security Feature Bypass Vulnerability | ||
| CVE-2023-28226 | Med | 0.35 | 5.3 | 0.01 | Apr 11, 2023 | Windows Enroll Engine Security Feature Bypass Vulnerability | ||
| CVE-2023-21699 | Med | 0.35 | 5.3 | 0.01 | Feb 14, 2023 | Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability | ||
| CVE-2023-21682 | Med | 0.35 | 5.3 | 0.01 | Jan 10, 2023 | Windows Point-to-Point Protocol (PPP) Information Disclosure Vulnerability | ||
| CVE-2023-21525 | Med | 0.35 | 5.3 | 0.02 | Jan 10, 2023 | Remote Procedure Call Runtime Denial of Service Vulnerability | ||
| CVE-2022-30154 | Med | 0.35 | 5.3 | 0.02 | Jun 15, 2022 | Microsoft File Server Shadow Copy Agent Service (RVSS) Elevation of Privilege Vulnerability | ||
| CVE-2022-24503 | Med | 0.35 | 5.4 | 0.02 | Mar 9, 2022 | Remote Desktop Protocol Client Information Disclosure Vulnerability | ||
| CVE-2022-21924 | Med | 0.35 | 5.3 | 0.03 | Jan 11, 2022 | Workstation Service Remote Protocol Security Feature Bypass Vulnerability | ||
| CVE-2022-21913 | Med | 0.35 | 5.3 | 0.03 | Jan 11, 2022 | Local Security Authority (Domain Policy) Remote Protocol Security Feature Bypass | ||
| CVE-2021-33757 | Med | 0.35 | 5.3 | 0.03 | Jul 14, 2021 | Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnerability | ||
| CVE-2021-33744 | Med | 0.35 | 5.3 | 0.01 | Jul 14, 2021 | Windows Secure Kernel Mode Security Feature Bypass Vulnerability |
- risk 0.36cvss 5.0epss 0.05
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, aka "Windows Kernel…
- risk 0.36cvss 5.3epss 0.14
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow remote attackers to hijack network traffic or bypass intended Enhanced Protected Mode (EPM) or…
- risk 0.36cvss 5.5epss 0.02
Microsoft Windows 10 Gold and 1511 allows local users to bypass the Virtual Secure Mode Hypervisor Code Integrity (HVCI) protection mechanism and perform RWX markings of kernel-mode pages via a crafted application, aka "Hypervisor Code Integrity Security Feature Bypass."
- risk 0.35cvss 5.4epss 0.01
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.35cvss 5.4epss 0.01
Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network.
- risk 0.35cvss 5.4epss 0.02
Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.35cvss 5.3epss 0.01
Windows iSCSI Service Denial of Service Vulnerability
- risk 0.35cvss 5.3epss 0.01
Windows TCP/IP Information Disclosure Vulnerability
- risk 0.35cvss 5.3epss 0.02
PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can…
- risk 0.35cvss 5.4epss 0.02
Windows HTML Platforms Security Feature Bypass Vulnerability
- risk 0.35cvss 5.3epss 0.01
Windows Enroll Engine Security Feature Bypass Vulnerability
- risk 0.35cvss 5.3epss 0.01
Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability
- risk 0.35cvss 5.3epss 0.01
Windows Point-to-Point Protocol (PPP) Information Disclosure Vulnerability
- risk 0.35cvss 5.3epss 0.02
Remote Procedure Call Runtime Denial of Service Vulnerability
- risk 0.35cvss 5.3epss 0.02
Microsoft File Server Shadow Copy Agent Service (RVSS) Elevation of Privilege Vulnerability
- risk 0.35cvss 5.4epss 0.02
Remote Desktop Protocol Client Information Disclosure Vulnerability
- risk 0.35cvss 5.3epss 0.03
Workstation Service Remote Protocol Security Feature Bypass Vulnerability
- risk 0.35cvss 5.3epss 0.03
Local Security Authority (Domain Policy) Remote Protocol Security Feature Bypass
- risk 0.35cvss 5.3epss 0.03
Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnerability
- risk 0.35cvss 5.3epss 0.01
Windows Secure Kernel Mode Security Feature Bypass Vulnerability
Page 199 of 214