cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 167 of 182
CVE-2026-45606P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-45606 [MEDIUM] CWE-125 CVE-2026-45606: Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.
nvd
CVE-2025-55332P4MEDIUMCVSS 4.6≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-55332 [MEDIUM] CWE-841 CVE-2025-55332: Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2026-69483P4MEDIUMCVSS 4.7≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69483 [MEDIUM] CWE-125 CVE-2026-69483: Out-of-bounds read in Windows Image Acquisition allows an authorized attacker to disclose informatio Out-of-bounds read in Windows Image Acquisition allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69895P4MEDIUMCVSS 4.7≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69895 [MEDIUM] CWE-125 CVE-2026-69895: Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information lo Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.
nvd
CVE-2025-58717P4MEDIUMCVSS 4.3≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-58717 [MEDIUM] CWE-125 CVE-2025-58717: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-55700P4MEDIUMCVSS 4.3≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-55700 [MEDIUM] CWE-125 CVE-2025-55700: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-20962P4MEDIUMCVSS 4.4≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20962 [MEDIUM] CWE-908 CVE-2026-20962: Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized a Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally.
nvd
CVE-2026-27906P4MEDIUMCVSS 4.4≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-27906 [MEDIUM] CWE-20 CVE-2026-27906: Improper input validation in Windows Hello allows an authorized attacker to bypass a security featur Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-69713P4MEDIUMCVSS 4.4≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69713 [MEDIUM] CWE-1395 CVE-2026-69713: Dependency on vulnerable third-party component in Windows Secure Boot allows an authorized attacker Dependency on vulnerable third-party component in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2024-43555P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43555 [MEDIUM] CWE-125 CVE-2024-43555: Windows Mobile Broadband Driver Denial of Service Vulnerability Windows Mobile Broadband Driver Denial of Service Vulnerability
nvd
CVE-2024-43561P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43561 [MEDIUM] CWE-20 CVE-2024-43561: Windows Mobile Broadband Driver Denial of Service Vulnerability Windows Mobile Broadband Driver Denial of Service Vulnerability
nvd
CVE-2024-43558P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43558 [MEDIUM] CWE-20 CVE-2024-43558: Windows Mobile Broadband Driver Denial of Service Vulnerability Windows Mobile Broadband Driver Denial of Service Vulnerability
nvd
CVE-2024-43557P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43557 [MEDIUM] CWE-20 CVE-2024-43557: Windows Mobile Broadband Driver Denial of Service Vulnerability Windows Mobile Broadband Driver Denial of Service Vulnerability
nvd
CVE-2024-43559P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43559 [MEDIUM] CWE-476 CVE-2024-43559: Windows Mobile Broadband Driver Denial of Service Vulnerability Windows Mobile Broadband Driver Denial of Service Vulnerability
nvd
CVE-2024-43538P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43538 [MEDIUM] CWE-20 CVE-2024-43538: Windows Mobile Broadband Driver Denial of Service Vulnerability Windows Mobile Broadband Driver Denial of Service Vulnerability
nvd
CVE-2024-43542P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43542 [MEDIUM] CWE-20 CVE-2024-43542: Windows Mobile Broadband Driver Denial of Service Vulnerability Windows Mobile Broadband Driver Denial of Service Vulnerability
nvd
CVE-2024-43537P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43537 [MEDIUM] CWE-125 CVE-2024-43537: Windows Mobile Broadband Driver Denial of Service Vulnerability Windows Mobile Broadband Driver Denial of Service Vulnerability
nvd
CVE-2024-43540P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43540 [MEDIUM] CWE-20 CVE-2024-43540: Windows Mobile Broadband Driver Denial of Service Vulnerability Windows Mobile Broadband Driver Denial of Service Vulnerability
nvd
CVE-2023-36717P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-36717 [MEDIUM] CVE-2023-36717: Windows Virtual Trusted Platform Module Denial of Service Vulnerability Windows Virtual Trusted Platform Module Denial of Service Vulnerability
nvd
CVE-2025-21347P4MEDIUMCVSS 6.0≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21347 [MEDIUM] CWE-59 CVE-2025-21347: Windows Deployment Services Denial of Service Vulnerability Windows Deployment Services Denial of Service Vulnerability
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase