cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 145 of 182
CVE-2026-68843P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-68843 [MEDIUM] CWE-416 CVE-2026-68843: Use after free in Microsoft Office Word allows an authorized attacker to disclose information locall Use after free in Microsoft Office Word allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42914P4MEDIUMCVSS 5.3≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42914 [MEDIUM] CWE-125 CVE-2026-42914: Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network. Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.
cvelistv5nvd
CVE-2026-69554P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69554 [MEDIUM] CWE-306 CVE-2026-69554: Missing authentication for critical function in Microsoft Windows Search Component allows an authori Missing authentication for critical function in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.
nvd
CVE-2026-45595P4MEDIUMCVSS 5.4≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-45595 [MEDIUM] CWE-693 CVE-2026-45595: Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to by Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2022-26934P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19043.17062022-05-10
CVE-2022-26934 [MEDIUM] CVE-2022-26934: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2022-35837P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.20062022-09-13
CVE-2022-35837 [MEDIUM] CVE-2022-35837: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2022-30208P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.18262022-07-12
CVE-2022-30208 [MEDIUM] CVE-2022-30208: Windows Security Account Manager (SAM) Denial of Service Vulnerability Windows Security Account Manager (SAM) Denial of Service Vulnerability
nvd
CVE-2022-38006P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.20062022-09-13
CVE-2022-38006 [MEDIUM] CVE-2022-38006: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2022-21997P4HIGHCVSS 7.1≥ 10.0.19043.0, < 10.0.19044.15262022-02-09
CVE-2022-21997 [HIGH] CWE-59 CVE-2022-21997: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-30226P4HIGHCVSS 7.1≥ 10.0.19043.0, < 10.0.19044.18262022-07-12
CVE-2022-30226 [HIGH] CVE-2022-30226: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-22022P4HIGHCVSS 7.1≥ 10.0.19043.0, < 10.0.19044.18262022-07-12
CVE-2022-22022 [HIGH] CVE-2022-22022: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2023-21760P4HIGHCVSS 7.1≥ 10.0.19043.0, < 10.0.19044.24862023-01-10
CVE-2023-21760 [HIGH] CWE-59 CVE-2023-21760: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2023-35347P4HIGHCVSS 7.1≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-35347 [HIGH] CWE-59 CVE-2023-35347: Microsoft Install Service Elevation of Privilege Vulnerability Microsoft Install Service Elevation of Privilege Vulnerability
nvd
CVE-2022-37977P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.21302022-10-11
CVE-2022-37977 [MEDIUM] CVE-2022-37977: Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
nvd
CVE-2025-50158P4HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-50158 [HIGH] CWE-367 CVE-2025-50158: Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to disclose information locally.
nvd
CVE-2023-21560P4MEDIUMCVSS 6.6≥ 10.0.19043.0, < 10.0.19044.24862023-01-10
CVE-2023-21560 [MEDIUM] CWE-122 CVE-2023-21560: Windows Boot Manager Security Feature Bypass Vulnerability Windows Boot Manager Security Feature Bypass Vulnerability
nvd
CVE-2023-28269P4MEDIUMCVSS 6.8≥ 10.0.19043.0, < 10.0.19044.28462023-04-11
CVE-2023-28269 [MEDIUM] CWE-122 CVE-2023-28269: Windows Boot Manager Security Feature Bypass Vulnerability Windows Boot Manager Security Feature Bypass Vulnerability
nvd
CVE-2024-38013P4MEDIUMCVSS 6.7≥ 10.0.19043.0, < 10.0.19044.46512024-07-09
CVE-2024-38013 [MEDIUM] CWE-59 CVE-2024-38013: Microsoft Windows Server Backup Elevation of Privilege Vulnerability Microsoft Windows Server Backup Elevation of Privilege Vulnerability
nvd
CVE-2026-45608P4MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-45608 [MEDIUM] CWE-125 CVE-2026-45608: Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information lo Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.
nvd
CVE-2024-49101P4MEDIUMCVSS 6.6≥ 10.0.19043.0, < 10.0.19044.52472024-12-12
CVE-2024-49101 [MEDIUM] CWE-125 CVE-2024-49101: Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase