cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 142 of 182
CVE-2026-69874P4MEDIUMCVSS 6.4≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69874 [MEDIUM] CWE-822 CVE-2026-69874: Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges lo Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-21924P4MEDIUMCVSS 5.3≥ 10.0.19043.0, < 10.0.19044.14662022-01-11
CVE-2022-21924 [MEDIUM] CVE-2022-21924: Workstation Service Remote Protocol Security Feature Bypass Vulnerability Workstation Service Remote Protocol Security Feature Bypass Vulnerability
nvd
CVE-2026-40380P4MEDIUMCVSS 6.2≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-40380 [MEDIUM] CWE-122 CVE-2026-40380: Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execu Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack.
nvd
CVE-2025-48823P4MEDIUMCVSS 5.9≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-48823 [MEDIUM] CWE-310 CVE-2025-48823: Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose i Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-69552P4MEDIUMCVSS 5.7≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69552 [MEDIUM] CWE-209 CVE-2026-69552: Generation of error message containing sensitive information in Windows Print Spooler Components all Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a network.
nvd
CVE-2024-30034P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.44122024-05-14
CVE-2024-30034 [MEDIUM] CWE-843 CVE-2024-30034: Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability
nvd
CVE-2025-29956P4MEDIUMCVSS 5.4≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29956 [MEDIUM] CWE-126 CVE-2025-29956: Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-25185P4MEDIUMCVSS 5.3≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-25185 [MEDIUM] CWE-200 CVE-2026-25185: Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows a Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-61368P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61368 [MEDIUM] CWE-122 CVE-2026-61368: Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.
nvd
CVE-2026-20927P4MEDIUMCVSS 5.3≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20927 [MEDIUM] CWE-362 CVE-2026-20927: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service over a network.
nvd
CVE-2026-73004P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-73004 [MEDIUM] CWE-306 CVE-2026-73004: Missing authentication for critical function in Windows Autopilot allows an authorized attacker to p Missing authentication for critical function in Windows Autopilot allows an authorized attacker to perform tampering locally.
nvd
CVE-2026-72964P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-72964 [MEDIUM] CWE-306 CVE-2026-72964: Missing authentication for critical function in Windows Internet Connection Sharing (ICS) allows an Missing authentication for critical function in Windows Internet Connection Sharing (ICS) allows an authorized attacker to perform tampering locally.
nvd
CVE-2026-69321P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69321 [MEDIUM] CWE-306 CVE-2026-69321: Missing authentication for critical function in Windows Power Dependency Coordinator allows an autho Missing authentication for critical function in Windows Power Dependency Coordinator allows an authorized attacker to perform tampering locally.
nvd
CVE-2026-69674P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69674 [MEDIUM] CWE-306 CVE-2026-69674: Missing authentication for critical function in Windows Modern Device Management (MDM) allows an aut Missing authentication for critical function in Windows Modern Device Management (MDM) allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-83991P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-83991 [MEDIUM] CWE-306 CVE-2026-83991: Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an aut Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.
nvd
CVE-2022-29112P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19043.17062022-05-10
CVE-2022-29112 [MEDIUM] CVE-2022-29112: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2023-21750P4HIGHCVSS 7.1≥ 10.0.19043.0, < 10.0.19044.24862023-01-10
CVE-2023-21750 [HIGH] CWE-284 CVE-2023-21750: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-28222P4HIGHCVSS 7.1≥ 10.0.19043.0, < 10.0.19044.28462023-04-11
CVE-2023-28222 [HIGH] CWE-59 CVE-2023-28222: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-34690P4HIGHCVSS 7.1≥ 10.0.19043.0, < 10.0.19044.18892022-08-09
CVE-2022-34690 [HIGH] CVE-2022-34690: Windows Fax Service Elevation of Privilege Vulnerability Windows Fax Service Elevation of Privilege Vulnerability
nvd
CVE-2023-28267P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.28462023-04-11
CVE-2023-28267 [MEDIUM] CWE-126 CVE-2023-28267: Remote Desktop Protocol Client Information Disclosure Vulnerability Remote Desktop Protocol Client Information Disclosure Vulnerability
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase