Skip to main content

Vendor/product archive

microsoft / windows_10_1607 CVEs

Beta · best-effort

2,038 CVEs tagged to microsoft / windows_10_160753 Critical, 1,440 High, 537 Medium, 8 Low, 0 Unrated.

CVE-2026-49804

Published Jul 14, 2026

Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack.

CVSS 6.6 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-49803

Published Jul 14, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges…

CVSS 7.0 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-49799

Published Jul 14, 2026

Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-49794

Published Jul 14, 2026

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

CVSS 4.6 · Medium
evidence mentions
5
Buzz score
32.4

CVE-2026-49793

Published Jul 14, 2026

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

CVSS 7.8 · High
evidence mentions
5
Buzz score
32.4

CVE-2026-49792

Published Jul 14, 2026

Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

CVSS 7.8 · High
evidence mentions
5
Buzz score
32.4

CVE-2026-49791

Published Jul 14, 2026

Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVSS 7.1 · High
evidence mentions
5
Buzz score
32.4

CVE-2026-49788

Published Jul 14, 2026

Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.

CVSS 7.5 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-49787

Published Jul 14, 2026

Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

CVSS 7.5 · High
evidence mentions
5
Buzz score
32.4

CVE-2026-49784

Published Jul 14, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges loca…

CVSS 7.0 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-49783

Published Jul 14, 2026

Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVSS 7.8 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-49180

Published Jul 14, 2026

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-49172

Published Jul 14, 2026

Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
29.1
Showing 201-225 of 2,038 CVEsPage 9 of 82