cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 132 of 182
CVE-2025-29960P4MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29960 [MEDIUM] CWE-125 CVE-2025-29960: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-29959P4MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29959 [MEDIUM] CWE-908 CVE-2025-29959: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthor Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-29958P4MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29958 [MEDIUM] CWE-908 CVE-2025-29958: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthor Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-29961P4MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29961 [MEDIUM] CWE-125 CVE-2025-29961: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-29836P4MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29836 [MEDIUM] CWE-125 CVE-2025-29836: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-29830P4MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29830 [MEDIUM] CWE-908 CVE-2025-29830: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthor Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-29832P4MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29832 [MEDIUM] CWE-125 CVE-2025-29832: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-29835P4MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29835 [MEDIUM] CWE-125 CVE-2025-29835: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2023-29352P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.30862023-06-14
CVE-2023-29352 [MEDIUM] CVE-2023-29352: Windows Remote Desktop Security Feature Bypass Vulnerability Windows Remote Desktop Security Feature Bypass Vulnerability
nvd
CVE-2023-35308P3MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-35308 [MEDIUM] CWE-73 CVE-2023-35308: Windows MSHTML Platform Security Feature Bypass Vulnerability Windows MSHTML Platform Security Feature Bypass Vulnerability
nvd
CVE-2025-58729P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-58729 [MEDIUM] CWE-1287 CVE-2025-58729: Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an auth Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
nvd
CVE-2026-68898P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-68898 [MEDIUM] CWE-125 CVE-2026-68898: Out-of-bounds read in Windows iSCSI allows an unauthorized attacker to deny service over a network. Out-of-bounds read in Windows iSCSI allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-49804P3MEDIUMCVSS 6.6≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49804 [MEDIUM] CWE-122 CVE-2026-49804: Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate pr Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2026-69267P4MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69267 [MEDIUM] CWE-1220 CVE-2026-69267: Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allow Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally.
nvd
CVE-2026-49174P3MEDIUMCVSS 6.1≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49174 [MEDIUM] CWE-306 CVE-2026-49174: Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
nvd
CVE-2026-69317P4MEDIUMCVSS 5.7≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69317 [MEDIUM] CWE-125 CVE-2026-69317: Out-of-bounds read in Remote Desktop Client allows an authorized attacker to disclose information ov Out-of-bounds read in Remote Desktop Client allows an authorized attacker to disclose information over a network.
nvd
CVE-2023-21677P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.24862023-01-10
CVE-2023-21677 [HIGH] CWE-822 CVE-2023-21677: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2023-21683P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.24862023-01-10
CVE-2023-21683 [HIGH] CWE-476 CVE-2023-21683: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2023-21527P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.24862023-01-10
CVE-2023-21527 [HIGH] CWE-191 CVE-2023-21527: Windows iSCSI Service Denial of Service Vulnerability Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2023-32011P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.30862023-06-14
CVE-2023-32011 [HIGH] CWE-125 CVE-2023-32011: Windows iSCSI Discovery Service Denial of Service Vulnerability Windows iSCSI Discovery Service Denial of Service Vulnerability
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase