Windows 10

Vendor:

First CVE: Jul 20, 2015 · Active for 11 years

4,057
Total CVEs
More Total CVEs than 100% of tracked products
450.8
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.3%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Windows 10 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 20, 2015
11 years ago
Most Recent CVE
Oct 10, 2023
1,018 days ago

CVE Severity & Scoring

Windows 104,057 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local2,142 (52.8%)
Network1,740 (42.9%)
Unknown56 (1.4%)
Physical34 (0.8%)
Adjacent Network85 (2.1%)
Attack Complexity
Low3,096 (76.3%)
High905 (22.3%)
Unknown56 (1.4%)
User Interaction
None2,380 (58.7%)
Unknown56 (1.4%)
Required1,621 (40.0%)
Privileges Required
Low1,955 (48.2%)
High126 (3.1%)
None1,920 (47.3%)
Unknown56 (1.4%)

Top CVEs

Signals from CVEs in this product scope (4057 CVEs).

4,057 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.
Jul 14, 20207.898YESYES
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, W
Jul 20, 20158.897YESYES
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media pla
Feb 6, 20187.896YESYES
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
Jan 18, 20197.895YESYES
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows
Jan 24, 20188.888NOYES
HTTP Protocol Stack Remote Code Execution Vulnerability
Jan 11, 20229.887NOYES
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption
Jan 8, 20197.582NOYES
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Apr 15, 20229.880NONO
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Internet
Feb 10, 20167.880NOYES
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gol
Dec 9, 20157.280NOYES

Exploit Exposure

Signals from CVEs in this product scope (4057 CVEs).

CISA KEV
12 CVEs
0.3% of CVEs· 96th percentile
Metasploit
16 CVEs
0.4% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
384 CVEs
9.5% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (4057 CVEs).

Media Mentions

Signals from CVEs in this product scope (4057 CVEs).

Top CNAs Publishing CVEs For Windows 10

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
22h2677.34.3%01
21h25127.44.6%02
21h17177.44.0%01
20h21,0297.53.9%03
20049137.53.1%03
19091,4307.53.4%06
19031,0567.44.4%040
18092,1057.44.4%061
180726.24.0%00
18031,4477.45.2%067
17091,2417.25.6%097
17037126.77.8%0122
16072,2647.25.2%0152
15114716.611.1%0132