cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13

Vulnerabilities

Page 17 of 182
CVE-2026-69518P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69518 [HIGH] CWE-122 CVE-2026-69518: Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-62795P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62795 [HIGH] CWE-416 CVE-2026-62795: Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attack Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-50500P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50500 [HIGH] CWE-416 CVE-2026-50500: Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a networ Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-25188P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-25188 [HIGH] CWE-122 CVE-2026-25188: Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate p Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network.
nvd
CVE-2023-35630P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19041.38032023-12-12
CVE-2023-35630 [HIGH] CWE-122 CVE-2023-35630: Internet Connection Sharing (ICS) Remote Code Execution Vulnerability Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
nvd
CVE-2024-30078P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.45292024-06-11
CVE-2024-30078 [HIGH] CWE-20 CVE-2024-30078: Windows Wi-Fi Driver Remote Code Execution Vulnerability Windows Wi-Fi Driver Remote Code Execution Vulnerability
nvd
CVE-2023-24949P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.29652023-05-09
CVE-2023-24949 [HIGH] CWE-190 CVE-2023-24949: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2025-26645P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.56082025-03-11
CVE-2025-26645 [HIGH] CWE-23 CVE-2025-26645: Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code ove Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21371P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21371 [HIGH] CWE-122 CVE-2025-21371: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2022-24487P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.16452022-04-15
CVE-2022-24487 [HIGH] CVE-2022-24487: Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
nvd
CVE-2026-24294P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-24294 [HIGH] CWE-287 CVE-2026-24294: Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges lo Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-21407P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21407 [HIGH] CWE-122 CVE-2025-21407: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21406P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21406 [HIGH] CWE-416 CVE-2025-21406: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21190P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21190 [HIGH] CWE-122 CVE-2025-21190: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21201P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21201 [HIGH] CWE-415 CVE-2025-21201: Windows Telephony Server Remote Code Execution Vulnerability Windows Telephony Server Remote Code Execution Vulnerability
nvd
CVE-2025-21200P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21200 [HIGH] CWE-122 CVE-2025-21200: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2026-81955P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-81955 [HIGH] CWE-122 CVE-2026-81955: Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execut Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-73016P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-73016 [HIGH] CWE-122 CVE-2026-73016: Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execut Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69334P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69334 [HIGH] CWE-122 CVE-2026-69334: Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacke Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69601P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69601 [HIGH] CWE-122 CVE-2026-69601: Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase