Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13
Vulnerabilities
Page 138 of 182
CVE-2025-59195P4HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-59195 [HIGH] CWE-362 CVE-2025-59195: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to deny service locally.
nvd
CVE-2025-49678P4HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-49678 [HIGH] CWE-362 CVE-2025-49678: Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally
Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-24883P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.28462023-04-11
CVE-2023-24883 [MEDIUM] CWE-126 CVE-2023-24883: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-24906P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-24906 [MEDIUM] CWE-190 CVE-2023-24906: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-24857P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-24857 [MEDIUM] CWE-126 CVE-2023-24857: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-24863P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-24863 [MEDIUM] CWE-190 CVE-2023-24863: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-24870P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-24870 [MEDIUM] CWE-126 CVE-2023-24870: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2024-43525P4MEDIUMCVSS 6.8≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43525 [MEDIUM] CWE-20 CVE-2024-43525: Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
nvd
CVE-2024-43526P4MEDIUMCVSS 6.8≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43526 [MEDIUM] CWE-20 CVE-2024-43526: Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
nvd
CVE-2024-43523P4MEDIUMCVSS 6.8≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43523 [MEDIUM] CWE-20 CVE-2024-43523: Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
nvd
CVE-2024-43524P4MEDIUMCVSS 6.8≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43524 [MEDIUM] CWE-118 CVE-2024-43524: Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
nvd
CVE-2024-43543P4MEDIUMCVSS 6.8≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43543 [MEDIUM] CWE-601 CVE-2024-43543: Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
nvd
CVE-2024-43536P4MEDIUMCVSS 6.8≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43536 [MEDIUM] CWE-601 CVE-2024-43536: Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
nvd
CVE-2026-57097P4MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-57097 [MEDIUM] CWE-426 CVE-2026-57097: Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature
Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2026-77892P4MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-77892 [MEDIUM] CWE-693 CVE-2026-77892: No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges
No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2026-50298P4MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50298 [MEDIUM] CWE-190 CVE-2026-50298: Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate p
Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2024-21431P4MEDIUMCVSS 6.7≥ 10.0.19043.0, < 10.0.19044.41702024-03-12
CVE-2024-21431 [MEDIUM] CWE-732 CVE-2024-21431: Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
nvd
CVE-2025-48807P4MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.63322025-08-12
CVE-2025-48807 [MEDIUM] CWE-923 CVE-2025-48807: Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an aut
Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally.
nvd
CVE-2025-54104P4MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-54104 [MEDIUM] CWE-843 CVE-2025-54104: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55226P4MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-55226 [MEDIUM] CWE-362 CVE-2025-55226: Concurrent execution using shared resource with improper synchronization ('race condition') in Graph
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to execute code locally.
nvd