Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13
Vulnerabilities
Page 125 of 182
CVE-2026-71350P3MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-71350 [MEDIUM] CWE-122 CVE-2026-71350: Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code
Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.
nvd
CVE-2026-71348P3MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-71348 [MEDIUM] CWE-122 CVE-2026-71348: Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code
Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.
nvd
CVE-2026-68833P3MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-68833 [MEDIUM] CWE-122 CVE-2026-68833: Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a ph
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.
nvd
CVE-2026-69566P3MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69566 [MEDIUM] CWE-122 CVE-2026-69566: Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a ph
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.
nvd
CVE-2026-71349P3MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-71349 [MEDIUM] CWE-122 CVE-2026-71349: Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code
Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.
nvd
CVE-2026-54132P3MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-54132 [MEDIUM] CWE-122 CVE-2026-54132: Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges w
Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2026-50668P3MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50668 [MEDIUM] CWE-122 CVE-2026-50668: Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges wit
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2023-36871P3MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-36871 [MEDIUM] CVE-2023-36871: Azure Active Directory Security Feature Bypass Vulnerability
Azure Active Directory Security Feature Bypass Vulnerability
nvd
CVE-2026-72939P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-72939 [MEDIUM] CWE-476 CVE-2026-72939: Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized at
Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network.
nvd
CVE-2026-61345P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61345 [MEDIUM] CWE-476 CVE-2026-61345: Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
nvd
CVE-2026-59138P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-59138 [MEDIUM] CWE-476 CVE-2026-59138: Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
nvd
CVE-2026-49799P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49799 [MEDIUM] CWE-400 CVE-2026-49799: Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allo
Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.
nvd
CVE-2026-42903P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42903 [MEDIUM] CWE-476 CVE-2026-42903: Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a ne
Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.
nvd
CVE-2026-26155P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-26155 [MEDIUM] CWE-126 CVE-2026-26155: Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
nvd
CVE-2022-21883P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.14662022-01-11
CVE-2022-21883 [HIGH] CVE-2022-21883: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2025-59244P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-59244 [MEDIUM] CWE-73 CVE-2025-59244: External control of file name or path in Windows Core Shell allows an unauthorized attacker to perfo
External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2022-21848P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19043.14662022-01-11
CVE-2022-21848 [HIGH] CVE-2022-21848: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2025-60723P3MEDIUMCVSS 6.3≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-60723 [MEDIUM] CWE-362 CVE-2025-60723: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to deny service over a network.
nvd
CVE-2021-43219P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.19044.14152021-12-15
CVE-2021-43219 [HIGH] CVE-2021-43219: DirectX Graphics Kernel File Denial of Service Vulnerability
DirectX Graphics Kernel File Denial of Service Vulnerability
nvd
CVE-2022-34720P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.20062022-09-13
CVE-2022-34720 [HIGH] CVE-2022-34720: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd