cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

2,906 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
2,906
CISA KEV
95
actively exploited
Public exploits
67
Exploited in wild
124
Severity breakdown
CRITICAL79HIGH2093MEDIUM721LOW13

Vulnerabilities

Page 128 of 146
CVE-2024-26255P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.42912024-04-09
CVE-2024-26255 [MEDIUM] CWE-126 CVE-2024-26255: Windows Remote Access Connection Manager Information Disclosure Vulnerability Windows Remote Access Connection Manager Information Disclosure Vulnerability
nvd
CVE-2024-30039P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.44122024-05-14
CVE-2024-30039 [MEDIUM] CWE-126 CVE-2024-30039: Windows Remote Access Connection Manager Information Disclosure Vulnerability Windows Remote Access Connection Manager Information Disclosure Vulnerability
nvd
CVE-2024-38155P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.47802024-08-13
CVE-2024-38155 [MEDIUM] CWE-125 CVE-2024-38155: Security Center Broker Information Disclosure Vulnerability Security Center Broker Information Disclosure Vulnerability
nvd
CVE-2024-38203P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.51312024-11-12
CVE-2024-38203 [MEDIUM] CWE-693 CVE-2024-38203: Windows Package Library Manager Information Disclosure Vulnerability Windows Package Library Manager Information Disclosure Vulnerability
nvd
CVE-2024-28900P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.44122024-04-09
CVE-2024-28900 [MEDIUM] CWE-126 CVE-2024-28900: Windows Remote Access Connection Manager Information Disclosure Vulnerability Windows Remote Access Connection Manager Information Disclosure Vulnerability
nvd
CVE-2024-28901P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.42912024-04-09
CVE-2024-28901 [MEDIUM] CWE-126 CVE-2024-28901: Windows Remote Access Connection Manager Information Disclosure Vulnerability Windows Remote Access Connection Manager Information Disclosure Vulnerability
nvd
CVE-2024-38118P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.47802024-08-13
CVE-2024-38118 [MEDIUM] CWE-908 CVE-2024-38118: Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
nvd
CVE-2024-38122P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.47802024-08-13
CVE-2024-38122 [MEDIUM] CWE-908 CVE-2024-38122: Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
nvd
CVE-2023-36724P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-36724 [MEDIUM] CWE-287 CVE-2023-36724: Windows Power Management Service Information Disclosure Vulnerability Windows Power Management Service Information Disclosure Vulnerability
nvd
CVE-2025-59190P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-59190 [MEDIUM] CWE-20 CVE-2025-59190: Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to d Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.
nvd
CVE-2023-23394P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-23394 [MEDIUM] CWE-822 CVE-2023-23394: Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
nvd
CVE-2023-23409P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-23409 [MEDIUM] CWE-20 CVE-2023-23409: Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
nvd
CVE-2026-25168P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-25168 [MEDIUM] CWE-476 CVE-2026-25168: Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny ser Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.
nvd
CVE-2026-34339P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-34339 [MEDIUM] CWE-476 CVE-2026-34339: Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorize Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally.
nvd
CVE-2025-26644P4MEDIUMCVSS 5.1≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-26644 [MEDIUM] CWE-1039 CVE-2025-26644: Automated recognition mechanism with inadequate detection or handling of adversarial input perturbat Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.
nvd
CVE-2024-21305P4MEDIUMCVSS 4.4≥ 10.0.19043.0, < 10.0.19044.39302024-01-09
CVE-2024-21305 [MEDIUM] CWE-732 CVE-2024-21305: Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
nvd
CVE-2025-21328P4MEDIUMCVSS 4.3≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21328 [MEDIUM] CWE-41 CVE-2025-21328: MapUrlToZone Security Feature Bypass Vulnerability MapUrlToZone Security Feature Bypass Vulnerability
nvd
CVE-2025-21329P4MEDIUMCVSS 4.3≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21329 [MEDIUM] CWE-41 CVE-2025-21329: MapUrlToZone Security Feature Bypass Vulnerability MapUrlToZone Security Feature Bypass Vulnerability
nvd
CVE-2025-55332P4MEDIUMCVSS 4.6≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-55332 [MEDIUM] CWE-841 CVE-2025-55332: Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2026-26175P4MEDIUMCVSS 4.6≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-26175 [MEDIUM] CWE-908 CVE-2026-26175: Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a se Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase