cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 112 of 182
CVE-2026-56173P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-56173 [HIGH] CWE-416 CVE-2026-56173: Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50296P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50296 [HIGH] CWE-416 CVE-2026-50296: Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally. Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50397P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50397 [HIGH] CWE-416 CVE-2026-50397: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58629P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58629 [HIGH] CWE-416 CVE-2026-58629: Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42984P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42984 [HIGH] CWE-416 CVE-2026-42984: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34347P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-34347 [HIGH] CWE-416 CVE-2026-34347: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-58725P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-58725 [HIGH] CWE-122 CVE-2025-58725: Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locall Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50166P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-50166 [MEDIUM] CWE-190 CVE-2025-50166: Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized a Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-69374P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69374 [MEDIUM] CWE-770 CVE-2026-69374: Allocation of resources without limits or throttling in Windows SMB Server allows an authorized atta Allocation of resources without limits or throttling in Windows SMB Server allows an authorized attacker to deny service over a network.
nvd
CVE-2026-56186P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-56186 [MEDIUM] CWE-125 CVE-2026-56186: Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-42907P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42907 [MEDIUM] CWE-200 CVE-2026-42907: Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized att Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-32151P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32151 [MEDIUM] CWE-200 CVE-2026-32151: Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized att Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-50432P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50432 [MEDIUM] CWE-416 CVE-2026-50432: Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny ser Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.
nvd
CVE-2026-65794P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-65794 [MEDIUM] CWE-126 CVE-2026-65794: Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-61921P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61921 [MEDIUM] CWE-125 CVE-2026-61921: Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-69350P3MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69350 [MEDIUM] CWE-122 CVE-2026-69350: Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privil Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-29142P3HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19043.17062022-05-10
CVE-2022-29142 [HIGH] CVE-2022-29142: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-30196P3HIGHCVSS 8.2≥ 10.0.19043.0, < 10.0.19044.20062022-09-13
CVE-2022-30196 [HIGH] CVE-2022-30196: Windows Secure Channel Denial of Service Vulnerability Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2025-21181P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21181 [HIGH] CWE-400 CVE-2025-21181: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2022-26831P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.16452022-04-15
CVE-2022-26831 [HIGH] CVE-2022-26831: Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase