cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13

Vulnerabilities

Page 12 of 182
CVE-2023-32015P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.30862023-06-14
CVE-2023-32015 [CRITICAL] CWE-20 CVE-2023-32015: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-29363P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.30862023-06-14
CVE-2023-29363 [CRITICAL] CWE-122 CVE-2023-29363: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-32014P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.30862023-06-14
CVE-2023-32014 [CRITICAL] CWE-191 CVE-2023-32014: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-35365P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-35365 [CRITICAL] CWE-20 CVE-2023-35365: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2023-21803P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.26042023-02-14
CVE-2023-21803 [CRITICAL] CWE-190 CVE-2023-21803: Windows iSCSI Discovery Service Remote Code Execution Vulnerability Windows iSCSI Discovery Service Remote Code Execution Vulnerability
nvd
CVE-2023-36911P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.33242023-08-08
CVE-2023-36911 [CRITICAL] CWE-190 CVE-2023-36911: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2023-36005P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19041.38032023-12-12
CVE-2023-36005 [HIGH] CWE-591 CVE-2023-36005: Windows Telephony Server Elevation of Privilege Vulnerability Windows Telephony Server Elevation of Privilege Vulnerability
nvd
CVE-2026-57092P2CRITICALCVSS 9.9≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-57092 [CRITICAL] CWE-416 CVE-2026-57092: Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a networ Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69769P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69769 [CRITICAL] CWE-122 CVE-2026-69769: Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69525P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69525 [CRITICAL] CWE-416 CVE-2026-69525: Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code ov Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69579P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69579 [CRITICAL] CWE-416 CVE-2026-69579: Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a net Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69431P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69431 [CRITICAL] CWE-122 CVE-2026-69431: Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a n Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69768P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69768 [CRITICAL] CWE-122 CVE-2026-69768: Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a n Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69463P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69463 [CRITICAL] CWE-122 CVE-2026-69463: Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a ne Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-57090P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-57090 [CRITICAL] CWE-122 CVE-2026-57090: Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-26670P2HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-26670 [HIGH] CWE-416 CVE-2025-26670: Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attack Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
nvd
CVE-2022-44666P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.23642022-12-13
CVE-2022-44666 [HIGH] CVE-2022-44666: Windows Contacts Remote Code Execution Vulnerability Windows Contacts Remote Code Execution Vulnerability
nvd
CVE-2026-25177P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-25177 [HIGH] CWE-641 CVE-2026-25177: Improper restriction of names for files and other resources in Active Directory Domain Services allo Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2023-28220P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.28462023-04-11
CVE-2023-28220 [HIGH] CWE-591 CVE-2023-28220: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-28219P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.28462023-04-11
CVE-2023-28219 [HIGH] CWE-591 CVE-2023-28219: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase