Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13
Vulnerabilities
Page 14 of 182
CVE-2026-50694P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50694 [CRITICAL] CWE-416 CVE-2026-50694: Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-57089P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-57089 [CRITICAL] CWE-416 CVE-2026-57089: Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized at
Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-38104P2HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.46512024-07-09
CVE-2024-38104 [HIGH] CWE-822 CVE-2024-38104: Windows Fax Service Remote Code Execution Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2024-38116P2HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.47802024-08-13
CVE-2024-38116 [HIGH] CWE-122 CVE-2024-38116: Windows IP Routing Management Snapin Remote Code Execution Vulnerability
Windows IP Routing Management Snapin Remote Code Execution Vulnerability
nvd
CVE-2024-49080P2HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.52472024-12-12
CVE-2024-49080 [HIGH] CWE-122 CVE-2024-49080: Windows IP Routing Management Snapin Remote Code Execution Vulnerability
Windows IP Routing Management Snapin Remote Code Execution Vulnerability
nvd
CVE-2025-21376P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21376 [HIGH] CWE-122 CVE-2025-21376: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2026-20868P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20868 [HIGH] CWE-122 CVE-2026-20868: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-43452P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.51312024-11-12
CVE-2024-43452 [HIGH] CWE-367 CVE-2024-43452: Windows Registry Elevation of Privilege Vulnerability
Windows Registry Elevation of Privilege Vulnerability
nvd
CVE-2026-62784P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62784 [HIGH] CWE-122 CVE-2026-62784: Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorize
Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.
nvd
CVE-2026-58626P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58626 [HIGH] CWE-416 CVE-2026-58626: Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
nvd
CVE-2026-23669P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-23669 [HIGH] CWE-416 CVE-2026-23669: Use after free in RPC Runtime allows an authorized attacker to execute code over a network.
Use after free in RPC Runtime allows an authorized attacker to execute code over a network.
nvd
CVE-2026-50369P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50369 [HIGH] CWE-362 CVE-2026-50369: Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privilege
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2022-30133P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.18892022-08-09
CVE-2022-30133 [CRITICAL] CVE-2022-30133: Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
nvd
CVE-2022-35744P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.18892023-05-31
CVE-2022-35744 [CRITICAL] CVE-2022-35744: Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
nvd
CVE-2022-35841P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.20062022-09-13
CVE-2022-35841 [HIGH] CVE-2022-35841: Windows Enterprise App Management Service Remote Code Execution Vulnerability
Windows Enterprise App Management Service Remote Code Execution Vulnerability
nvd
CVE-2026-68839P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-68839 [CRITICAL] CWE-20 CVE-2026-68839: Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker
Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-77493P3CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-77493 [CRITICAL] CWE-415 CVE-2026-77493: Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a n
Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69493P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69493 [CRITICAL] CWE-122 CVE-2026-69493: Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code
Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69715P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69715 [CRITICAL] CWE-122 CVE-2026-69715: Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a net
Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-56190P3CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-56190 [CRITICAL] CWE-908 CVE-2026-56190: Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
nvd