cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 135 of 182
CVE-2024-38069P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.46512024-07-09
CVE-2024-38069 [HIGH] CWE-347 CVE-2024-38069: Windows Enroll Engine Security Feature Bypass Vulnerability Windows Enroll Engine Security Feature Bypass Vulnerability
nvd
CVE-2025-21191P4HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-21191 [HIGH] CWE-367 CVE-2025-21191: Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows a Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-24865P3MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-24865 [MEDIUM] CWE-20 CVE-2023-24865: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-24866P3MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-24866 [MEDIUM] CWE-20 CVE-2023-24866: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-35296P3MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-35296 [MEDIUM] CWE-125 CVE-2023-35296: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2025-59289P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.63322025-10-14
CVE-2025-59289 [HIGH] CWE-415 CVE-2025-59289: Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55696P4HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-55696 [HIGH] CWE-367 CVE-2025-55696: Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) all Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-35316P3MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-35316 [MEDIUM] CWE-125 CVE-2023-35316: Remote Procedure Call Runtime Information Disclosure Vulnerability Remote Procedure Call Runtime Information Disclosure Vulnerability
nvd
CVE-2023-36564P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-36564 [MEDIUM] CVE-2023-36564: Windows Search Security Feature Bypass Vulnerability Windows Search Security Feature Bypass Vulnerability
nvd
CVE-2023-35332P4MEDIUMCVSS 6.8≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-35332 [MEDIUM] CWE-326 CVE-2023-35332: Windows Remote Desktop Protocol Security Feature Bypass Windows Remote Desktop Protocol Security Feature Bypass
nvd
CVE-2026-49168P4MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49168 [MEDIUM] CWE-190 CVE-2026-49168: Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to e Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2024-37976P4MEDIUMCVSS 6.7≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-37976 [MEDIUM] CWE-190 CVE-2024-37976: Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
nvd
CVE-2024-37983P4MEDIUMCVSS 6.7≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-37983 [MEDIUM] CWE-822 CVE-2024-37983: Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
nvd
CVE-2025-26681P4MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-26681 [MEDIUM] CWE-416 CVE-2025-26681: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69373P4MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69373 [MEDIUM] CWE-125 CVE-2026-69373: Integer overflow or wraparound in Windows Overlay Filter allows an authorized attacker to elevate pr Integer overflow or wraparound in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-72935P4MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-72935 [MEDIUM] CWE-125 CVE-2026-72935: Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-65795P4MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-65795 [MEDIUM] CWE-197 CVE-2026-65795: Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally. Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21265P4MEDIUMCVSS 6.4≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-21265 [MEDIUM] CWE-1329 CVE-2026-21265: Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificate Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing security fixes related to Windows boot manager or Secure Boot. The ope
nvd
CVE-2026-0390P4MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-0390 [MEDIUM] CWE-807 CVE-2026-0390: Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized atta Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2024-26209P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.42912024-04-09
CVE-2024-26209 [MEDIUM] CWE-908 CVE-2024-26209: Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase