Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13
Vulnerabilities
Page 10 of 182
CVE-2026-69590P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69590 [CRITICAL] CWE-122 CVE-2026-69590: Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
nvd
CVE-2026-72950P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-72950 [CRITICAL] CWE-122 CVE-2026-72950: Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
nvd
CVE-2022-21849P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19043.14662022-01-11
CVE-2022-21849 [CRITICAL] CVE-2022-21849: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2026-69714P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69714 [HIGH] CWE-121 CVE-2026-69714: Stack-based buffer overflow in Windows Device Association Service allows an authorized attacker to e
Stack-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2022-22012P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19043.17062022-05-10
CVE-2022-22012 [CRITICAL] CVE-2022-22012: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29130P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19043.17062022-05-10
CVE-2022-29130 [CRITICAL] CVE-2022-29130: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2023-35349P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-35349 [CRITICAL] CWE-20 CVE-2023-35349: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2024-21416P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.48942024-09-10
CVE-2024-21416 [CRITICAL] CWE-122 CVE-2024-21416: Windows TCP/IP Remote Code Execution Vulnerability
Windows TCP/IP Remote Code Execution Vulnerability
nvd
CVE-2026-69819P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69819 [CRITICAL] CWE-787 CVE-2026-69819: Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network.
Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-50439P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50439 [CRITICAL] CWE-416 CVE-2026-50439: Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute
Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.
nvd
CVE-2021-43217P2CRITICALCVSS 9.8≥ 10.0.0, < 10.0.19044.14152021-12-15
CVE-2021-43217 [CRITICAL] CVE-2021-43217: Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
nvd
CVE-2025-21369P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21369 [HIGH] CWE-122 CVE-2025-21369: Microsoft Digest Authentication Remote Code Execution Vulnerability
Microsoft Digest Authentication Remote Code Execution Vulnerability
nvd
CVE-2025-21368P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21368 [HIGH] CWE-122 CVE-2025-21368: Microsoft Digest Authentication Remote Code Execution Vulnerability
Microsoft Digest Authentication Remote Code Execution Vulnerability
nvd
CVE-2023-36017P2HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19043.36932023-11-14
CVE-2023-36017 [HIGH] CWE-843 CVE-2023-36017: Windows Scripting Engine Memory Corruption Vulnerability
Windows Scripting Engine Memory Corruption Vulnerability
nvd
CVE-2025-49744P3HIGHCVSS 7.0PoC≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-49744 [HIGH] CWE-122 CVE-2025-49744: Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-73012P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-73012 [HIGH] CWE-122 CVE-2026-73012: Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate p
Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-71352P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-71352 [HIGH] CWE-191 CVE-2026-71352: Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows an authori
Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows an authorized attacker to execute code over a network.
nvd
CVE-2026-56194P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-56194 [HIGH] CWE-122 CVE-2026-56194: Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate p
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-50666P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50666 [HIGH] CWE-416 CVE-2026-50666: Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-50360P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50360 [HIGH] CWE-303 CVE-2026-50360: Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized atta
Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd