cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

2,906 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
2,906
CISA KEV
95
actively exploited
Public exploits
67
Exploited in wild
124
Severity breakdown
CRITICAL79HIGH2093MEDIUM721LOW13

Vulnerabilities

Page 103 of 146
CVE-2025-29835P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29835 [MEDIUM] CWE-125 CVE-2025-29835: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-55226P3MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-55226 [MEDIUM] CWE-362 CVE-2025-55226: Concurrent execution using shared resource with improper synchronization ('race condition') in Graph Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to execute code locally.
nvd
CVE-2026-27925P4MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-27925 [MEDIUM] CWE-416 CVE-2026-27925: Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network.
nvd
CVE-2023-21677P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.24862023-01-10
CVE-2023-21677 [HIGH] CWE-822 CVE-2023-21677: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2023-21683P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.24862023-01-10
CVE-2023-21683 [HIGH] CWE-476 CVE-2023-21683: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2023-21527P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.24862023-01-10
CVE-2023-21527 [HIGH] CWE-191 CVE-2023-21527: Windows iSCSI Service Denial of Service Vulnerability Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2023-35330P4HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-35330 [HIGH] CWE-126 CVE-2023-35330: Windows Extended Negotiation Denial of Service Vulnerability Windows Extended Negotiation Denial of Service Vulnerability
nvd
CVE-2023-21811P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.26042023-02-14
CVE-2023-21811 [HIGH] CWE-126 CVE-2023-21811: Windows iSCSI Service Denial of Service Vulnerability Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2023-21700P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.26042023-02-14
CVE-2023-21700 [HIGH] CWE-476 CVE-2023-21700: Windows iSCSI Discovery Service Denial of Service Vulnerability Windows iSCSI Discovery Service Denial of Service Vulnerability
nvd
CVE-2023-21702P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.26042023-02-14
CVE-2023-21702 [HIGH] CWE-125 CVE-2023-21702: Windows iSCSI Service Denial of Service Vulnerability Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2022-38042P3HIGHCVSS 7.1≥ 10.0.19043.0, < 10.0.19044.21302022-10-11
CVE-2022-38042 [HIGH] CVE-2022-38042: Active Directory Domain Services Elevation of Privilege Vulnerability Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2022-26936P3MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19043.17062022-05-10
CVE-2022-26936 [MEDIUM] CVE-2022-26936: Windows Server Service Information Disclosure Vulnerability Windows Server Service Information Disclosure Vulnerability
nvd
CVE-2023-36427P3HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19043.36932023-11-14
CVE-2023-36427 [HIGH] CVE-2023-36427: Windows Hyper-V Elevation of Privilege Vulnerability Windows Hyper-V Elevation of Privilege Vulnerability
nvd
CVE-2022-30189P3MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19043.17662022-06-15
CVE-2022-30189 [MEDIUM] CVE-2022-30189: Windows Autopilot Device Management and Enrollment Client Spoofing Vulnerability Windows Autopilot Device Management and Enrollment Client Spoofing Vulnerability
nvd
CVE-2022-22015P3MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19043.17062022-05-10
CVE-2022-22015 [MEDIUM] CVE-2022-22015: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
nvd
CVE-2024-20659P4HIGHCVSS 7.1≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-20659 [HIGH] CWE-20 CVE-2024-20659: Windows Hyper-V Security Feature Bypass Vulnerability Windows Hyper-V Security Feature Bypass Vulnerability
nvd
CVE-2024-49082P4MEDIUMCVSS 6.8≥ 10.0.19043.0, < 10.0.19044.52472024-12-12
CVE-2024-49082 [MEDIUM] CWE-22 CVE-2024-49082: Windows File Explorer Information Disclosure Vulnerability Windows File Explorer Information Disclosure Vulnerability
nvd
CVE-2024-21314P3MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.39302024-01-09
CVE-2024-21314 [MEDIUM] CWE-125 CVE-2024-21314: Microsoft Message Queuing Information Disclosure Vulnerability Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2024-20660P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.39302024-01-09
CVE-2024-20660 [MEDIUM] CWE-125 CVE-2024-20660: Microsoft Message Queuing Information Disclosure Vulnerability Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2024-20680P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.39302024-01-09
CVE-2024-20680 [MEDIUM] CWE-822 CVE-2024-20680: Windows Message Queuing Client (MSMQC) Information Disclosure Windows Message Queuing Client (MSMQC) Information Disclosure
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase