cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 146 of 182
CVE-2024-49109P4MEDIUMCVSS 6.6≥ 10.0.19043.0, < 10.0.19044.52472024-12-12
CVE-2024-49109 [MEDIUM] CWE-125 CVE-2024-49109: Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
nvd
CVE-2024-49081P4MEDIUMCVSS 6.6≥ 10.0.19043.0, < 10.0.19044.52472024-12-12
CVE-2024-49081 [MEDIUM] CWE-122 CVE-2024-49081: Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
nvd
CVE-2024-49094P4MEDIUMCVSS 6.6≥ 10.0.19043.0, < 10.0.19044.52472024-12-12
CVE-2024-49094 [MEDIUM] CWE-122 CVE-2024-49094: Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
nvd
CVE-2024-49111P4MEDIUMCVSS 6.6≥ 10.0.19043.0, < 10.0.19044.52472024-12-12
CVE-2024-49111 [MEDIUM] CWE-125 CVE-2024-49111: Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
nvd
CVE-2022-35754P4MEDIUMCVSS 6.7≥ 10.0.19043.0, < 10.0.19044.18892023-05-31
CVE-2022-35754 [MEDIUM] CVE-2022-35754: Unified Write Filter Elevation of Privilege Vulnerability Unified Write Filter Elevation of Privilege Vulnerability
nvd
CVE-2024-21316P4MEDIUMCVSS 6.1≥ 10.0.19043.0, < 10.0.19044.39302024-01-09
CVE-2024-21316 [MEDIUM] CWE-20 CVE-2024-21316: Windows Server Key Distribution Service Security Feature Bypass Windows Server Key Distribution Service Security Feature Bypass
nvd
CVE-2024-21430P4MEDIUMCVSS 6.4≥ 10.0.19043.0, < 10.0.19044.41702024-03-12
CVE-2024-21430 [MEDIUM] CWE-125 CVE-2024-21430: Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability
nvd
CVE-2024-21339P4MEDIUMCVSS 6.4≥ 10.0.19043.0, < 10.0.19044.40462024-02-13
CVE-2024-21339 [MEDIUM] CWE-416 CVE-2024-21339: Windows USB Generic Parent Driver Remote Code Execution Vulnerability Windows USB Generic Parent Driver Remote Code Execution Vulnerability
nvd
CVE-2025-21242P4MEDIUMCVSS 5.9≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21242 [MEDIUM] CWE-200 CVE-2025-21242: Windows Kerberos Information Disclosure Vulnerability Windows Kerberos Information Disclosure Vulnerability
nvd
CVE-2022-34709P4MEDIUMCVSS 6.0≥ 10.0.19043.0, < 10.0.19044.18892022-08-09
CVE-2022-34709 [MEDIUM] CWE-843 CVE-2022-34709: Windows Defender Credential Guard Security Feature Bypass Vulnerability Windows Defender Credential Guard Security Feature Bypass Vulnerability
nvd
CVE-2026-49807P4MEDIUMCVSS 6.2≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49807 [MEDIUM] CWE-200 CVE-2026-49807: Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-50294P4MEDIUMCVSS 6.2≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50294 [MEDIUM] CWE-497 CVE-2026-50294: Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2025-27735P4MEDIUMCVSS 6.0≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-27735 [MEDIUM] CWE-345 CVE-2025-27735: Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclav Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-50485P4MEDIUMCVSS 5.7≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50485 [MEDIUM] CWE-126 CVE-2026-50485: Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent n Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
nvd
CVE-2026-72980P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-72980 [MEDIUM] CWE-427 CVE-2026-72980: Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-68831P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-68831 [MEDIUM] CWE-552 CVE-2026-68831: Files or directories accessible to external parties in Windows Defender Firewall Service allows an a Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69351P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69351 [MEDIUM] CWE-359 CVE-2026-69351: Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.
nvd
CVE-2026-68851P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-68851 [MEDIUM] CWE-126 CVE-2026-68851: Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
nvd
CVE-2026-58545P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58545 [MEDIUM] CWE-284 CVE-2026-58545: Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-72966P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-72966 [MEDIUM] CWE-862 CVE-2026-72966: Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to p Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase