cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

2,906 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
2,906
CISA KEV
95
actively exploited
Public exploits
67
Exploited in wild
123
Severity breakdown
CRITICAL79HIGH2093MEDIUM721LOW13

Vulnerabilities

Page 10 of 146
CVE-2026-50439P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50439 [CRITICAL] CWE-416 CVE-2026-50439: Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.
nvd
CVE-2021-43217P2CRITICALCVSS 9.8≥ 10.0.0, < 10.0.19044.14152021-12-15
CVE-2021-43217 [CRITICAL] CVE-2021-43217: Windows Encrypting File System (EFS) Remote Code Execution Vulnerability Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
nvd
CVE-2025-21369P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21369 [HIGH] CWE-122 CVE-2025-21369: Microsoft Digest Authentication Remote Code Execution Vulnerability Microsoft Digest Authentication Remote Code Execution Vulnerability
nvd
CVE-2025-21368P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21368 [HIGH] CWE-122 CVE-2025-21368: Microsoft Digest Authentication Remote Code Execution Vulnerability Microsoft Digest Authentication Remote Code Execution Vulnerability
nvd
CVE-2023-36017P2HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19043.36932023-11-14
CVE-2023-36017 [HIGH] CWE-843 CVE-2023-36017: Windows Scripting Engine Memory Corruption Vulnerability Windows Scripting Engine Memory Corruption Vulnerability
nvd
CVE-2025-49744P3HIGHCVSS 7.0PoC≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-49744 [HIGH] CWE-122 CVE-2025-49744: Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56194P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-56194 [HIGH] CWE-122 CVE-2026-56194: Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate p Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-56647P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-56647 [HIGH] CWE-190 CVE-2026-56647: Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2023-36910P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.33242023-08-08
CVE-2023-36910 [CRITICAL] CWE-190 CVE-2023-36910: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2023-35385P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.33242023-08-08
CVE-2023-35385 [CRITICAL] CWE-190 CVE-2023-35385: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2024-38199P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.47802024-08-13
CVE-2024-38199 [CRITICAL] CWE-416 CVE-2024-38199: Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
nvd
CVE-2023-32057P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-32057 [CRITICAL] CWE-20 CVE-2023-32057: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2025-21307P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21307 [CRITICAL] CWE-416 CVE-2025-21307: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
nvd
CVE-2023-36005P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19041.38032023-12-12
CVE-2023-36005 [HIGH] CWE-591 CVE-2023-36005: Windows Telephony Server Elevation of Privilege Vulnerability Windows Telephony Server Elevation of Privilege Vulnerability
nvd
CVE-2026-57092P2CRITICALCVSS 9.9≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-57092 [CRITICAL] CWE-416 CVE-2026-57092: Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a networ Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-57090P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-57090 [CRITICAL] CWE-122 CVE-2026-57090: Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-49172P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49172 [CRITICAL] CWE-122 CVE-2026-49172: Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code ov Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-54995P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-54995 [CRITICAL] CWE-416 CVE-2026-54995: Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to ex Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2023-21746HIGHCVSS 7.8ExploitedPoC≥ 10.0.19043.0, < 10.0.19044.24862023-01-10
CVE-2023-21746 [HIGH] Windows NTLM Elevation of Privilege Vulnerability Windows NTLM Elevation of Privilege Vulnerability Windows NTLM Elevation of Privilege Vulnerability
cvelistv5
CVE-2025-33064P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.59652025-06-10
CVE-2025-33064 [HIGH] CWE-122 CVE-2025-33064: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase