Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13
Vulnerabilities
Page 112 of 182
CVE-2026-56173P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-56173 [HIGH] CWE-416 CVE-2026-56173: Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.
Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50296P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50296 [HIGH] CWE-416 CVE-2026-50296: Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50397P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50397 [HIGH] CWE-416 CVE-2026-50397: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58629P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58629 [HIGH] CWE-416 CVE-2026-58629: Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42984P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42984 [HIGH] CWE-416 CVE-2026-42984: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34347P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-34347 [HIGH] CWE-416 CVE-2026-34347: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-58725P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-58725 [HIGH] CWE-122 CVE-2025-58725: Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locall
Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50166P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-50166 [MEDIUM] CWE-190 CVE-2025-50166: Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized a
Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-69374P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69374 [MEDIUM] CWE-770 CVE-2026-69374: Allocation of resources without limits or throttling in Windows SMB Server allows an authorized atta
Allocation of resources without limits or throttling in Windows SMB Server allows an authorized attacker to deny service over a network.
nvd
CVE-2026-56186P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-56186 [MEDIUM] CWE-125 CVE-2026-56186: Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a
Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-42907P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42907 [MEDIUM] CWE-200 CVE-2026-42907: Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized att
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-32151P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32151 [MEDIUM] CWE-200 CVE-2026-32151: Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized att
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-50432P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50432 [MEDIUM] CWE-416 CVE-2026-50432: Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny ser
Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.
nvd
CVE-2026-65794P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-65794 [MEDIUM] CWE-126 CVE-2026-65794: Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over
Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-61921P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61921 [MEDIUM] CWE-125 CVE-2026-61921: Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-69350P3MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69350 [MEDIUM] CWE-122 CVE-2026-69350: Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privil
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-29142P3HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19043.17062022-05-10
CVE-2022-29142 [HIGH] CVE-2022-29142: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-30196P3HIGHCVSS 8.2≥ 10.0.19043.0, < 10.0.19044.20062022-09-13
CVE-2022-30196 [HIGH] CVE-2022-30196: Windows Secure Channel Denial of Service Vulnerability
Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2025-21181P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21181 [HIGH] CWE-400 CVE-2025-21181: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2022-26831P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.16452022-04-15
CVE-2022-26831 [HIGH] CVE-2022-26831: Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
nvd