cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 125 of 182
CVE-2026-71350P3MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-71350 [MEDIUM] CWE-122 CVE-2026-71350: Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.
nvd
CVE-2026-71348P3MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-71348 [MEDIUM] CWE-122 CVE-2026-71348: Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.
nvd
CVE-2026-68833P3MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-68833 [MEDIUM] CWE-122 CVE-2026-68833: Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a ph Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.
nvd
CVE-2026-69566P3MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69566 [MEDIUM] CWE-122 CVE-2026-69566: Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a ph Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.
nvd
CVE-2026-71349P3MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-71349 [MEDIUM] CWE-122 CVE-2026-71349: Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.
nvd
CVE-2026-54132P3MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-54132 [MEDIUM] CWE-122 CVE-2026-54132: Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges w Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2026-50668P3MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50668 [MEDIUM] CWE-122 CVE-2026-50668: Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges wit Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2023-36871P3MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-36871 [MEDIUM] CVE-2023-36871: Azure Active Directory Security Feature Bypass Vulnerability Azure Active Directory Security Feature Bypass Vulnerability
nvd
CVE-2026-72939P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-72939 [MEDIUM] CWE-476 CVE-2026-72939: Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized at Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network.
nvd
CVE-2026-61345P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61345 [MEDIUM] CWE-476 CVE-2026-61345: Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
nvd
CVE-2026-59138P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-59138 [MEDIUM] CWE-476 CVE-2026-59138: Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
nvd
CVE-2026-49799P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49799 [MEDIUM] CWE-400 CVE-2026-49799: Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allo Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.
nvd
CVE-2026-42903P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42903 [MEDIUM] CWE-476 CVE-2026-42903: Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a ne Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.
nvd
CVE-2026-26155P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-26155 [MEDIUM] CWE-126 CVE-2026-26155: Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
nvd
CVE-2022-21883P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.14662022-01-11
CVE-2022-21883 [HIGH] CVE-2022-21883: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2025-59244P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-59244 [MEDIUM] CWE-73 CVE-2025-59244: External control of file name or path in Windows Core Shell allows an unauthorized attacker to perfo External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2022-21848P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19043.14662022-01-11
CVE-2022-21848 [HIGH] CVE-2022-21848: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2025-60723P3MEDIUMCVSS 6.3≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-60723 [MEDIUM] CWE-362 CVE-2025-60723: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to deny service over a network.
nvd
CVE-2021-43219P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.19044.14152021-12-15
CVE-2021-43219 [HIGH] CVE-2021-43219: DirectX Graphics Kernel File Denial of Service Vulnerability DirectX Graphics Kernel File Denial of Service Vulnerability
nvd
CVE-2022-34720P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.20062022-09-13
CVE-2022-34720 [HIGH] CVE-2022-34720: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase