cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13

Vulnerabilities

Page 11 of 182
CVE-2026-69625P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69625 [HIGH] CWE-122 CVE-2026-69625: Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an authorized Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2023-36910P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.33242023-08-08
CVE-2023-36910 [CRITICAL] CWE-190 CVE-2023-36910: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2023-35385P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.33242023-08-08
CVE-2023-35385 [CRITICAL] CWE-190 CVE-2023-35385: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2024-38199P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.47802024-08-13
CVE-2024-38199 [CRITICAL] CWE-416 CVE-2024-38199: Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
nvd
CVE-2025-21307P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21307 [CRITICAL] CWE-416 CVE-2025-21307: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
nvd
CVE-2026-69824P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69824 [CRITICAL] CWE-122 CVE-2026-69824: Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69496P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69496 [CRITICAL] CWE-122 CVE-2026-69496: Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute c Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69829P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69829 [CRITICAL] CWE-122 CVE-2026-69829: Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a n Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-70296P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-70296 [CRITICAL] CWE-787 CVE-2026-70296: Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code ove Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-49172P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49172 [CRITICAL] CWE-122 CVE-2026-49172: Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code ov Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-54995P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-54995 [CRITICAL] CWE-416 CVE-2026-54995: Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to ex Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2023-21746HIGHCVSS 7.8ExploitedPoC≥ 10.0.19043.0, < 10.0.19044.24862023-01-10
CVE-2023-21746 [HIGH] Windows NTLM Elevation of Privilege Vulnerability Windows NTLM Elevation of Privilege Vulnerability Windows NTLM Elevation of Privilege Vulnerability
cvelistv5
CVE-2025-33064P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.59652025-06-10
CVE-2025-33064 [HIGH] CWE-122 CVE-2025-33064: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
nvd
CVE-2026-69628P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69628 [HIGH] CWE-122 CVE-2026-69628: Heap-based buffer overflow in Windows iSCSI allows an authorized attacker to execute code over a net Heap-based buffer overflow in Windows iSCSI allows an authorized attacker to execute code over a network.
nvd
CVE-2026-72959P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-72959 [HIGH] CWE-122 CVE-2026-72959: Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
nvd
CVE-2026-56647P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-56647 [HIGH] CWE-190 CVE-2026-56647: Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69681P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69681 [HIGH] CWE-122 CVE-2026-69681: Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69512P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69512 [HIGH] CWE-122 CVE-2026-69512: Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privile Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2023-32057P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-32057 [CRITICAL] CWE-20 CVE-2023-32057: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2022-21894MEDIUMCVSS 4.4ExploitedPoC≥ 10.0.19043.0, < 10.0.19044.14662022-01-11
CVE-2022-21894 [MEDIUM] Secure Boot Security Feature Bypass Vulnerability Secure Boot Security Feature Bypass Vulnerability Secure Boot Security Feature Bypass Vulnerability
cvelistv5
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase