cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

2,906 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
2,906
CISA KEV
95
actively exploited
Public exploits
67
Exploited in wild
124
Severity breakdown
CRITICAL79HIGH2093MEDIUM721LOW13

Vulnerabilities

Page 105 of 146
CVE-2023-24865P3MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-24865 [MEDIUM] CWE-20 CVE-2023-24865: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-24866P3MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-24866 [MEDIUM] CWE-20 CVE-2023-24866: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-35296P3MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-35296 [MEDIUM] CWE-125 CVE-2023-35296: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2024-38161P4MEDIUMCVSS 6.8≥ 10.0.19043.0, < 10.0.19044.46512024-08-13
CVE-2024-38161 [MEDIUM] CWE-122 CVE-2024-38161: Windows Mobile Broadband Driver Remote Code Execution Vulnerability Windows Mobile Broadband Driver Remote Code Execution Vulnerability
nvd
CVE-2026-26152P4HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-26152 [HIGH] CWE-922 CVE-2026-26152: Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized att Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59195P4HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-59195 [HIGH] CWE-362 CVE-2025-59195: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to deny service locally.
nvd
CVE-2025-27468P4HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-27468 [HIGH] CWE-269 CVE-2025-27468: Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-41097P3MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.22512022-11-09
CVE-2022-41097 [MEDIUM] CVE-2022-41097: Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability
nvd
CVE-2023-35316P3MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-35316 [MEDIUM] CWE-125 CVE-2023-35316: Remote Procedure Call Runtime Information Disclosure Vulnerability Remote Procedure Call Runtime Information Disclosure Vulnerability
nvd
CVE-2023-36564P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-36564 [MEDIUM] CVE-2023-36564: Windows Search Security Feature Bypass Vulnerability Windows Search Security Feature Bypass Vulnerability
nvd
CVE-2023-35332P4MEDIUMCVSS 6.8≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-35332 [MEDIUM] CWE-326 CVE-2023-35332: Windows Remote Desktop Protocol Security Feature Bypass Windows Remote Desktop Protocol Security Feature Bypass
nvd
CVE-2025-29958P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29958 [MEDIUM] CWE-908 CVE-2025-29958: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthor Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-29961P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29961 [MEDIUM] CWE-125 CVE-2025-29961: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2024-37976P4MEDIUMCVSS 6.7≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-37976 [MEDIUM] CWE-190 CVE-2024-37976: Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
nvd
CVE-2024-37983P4MEDIUMCVSS 6.7≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-37983 [MEDIUM] CWE-822 CVE-2024-37983: Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
nvd
CVE-2025-29836P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29836 [MEDIUM] CWE-125 CVE-2025-29836: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-49168P4MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49168 [MEDIUM] CWE-190 CVE-2026-49168: Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to e Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2025-29830P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29830 [MEDIUM] CWE-908 CVE-2025-29830: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthor Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-26681P4MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-26681 [MEDIUM] CWE-416 CVE-2025-26681: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54104P3MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-54104 [MEDIUM] CWE-843 CVE-2025-54104: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd