cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

2,906 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
2,906
CISA KEV
95
actively exploited
Public exploits
67
Exploited in wild
123
Severity breakdown
CRITICAL79HIGH2093MEDIUM721LOW13

Vulnerabilities

Page 21 of 146
CVE-2022-30163P3HIGHCVSS 8.5≥ 10.0.19043.0, < 10.0.19044.17662022-06-15
CVE-2022-30163 [HIGH] CWE-362 CVE-2022-30163: Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2026-32225P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32225 [HIGH] CWE-693 CVE-2026-32225: Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security f Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2025-53131P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-53131 [HIGH] CWE-122 CVE-2025-53131: Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a n Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-26663P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-26663 [HIGH] CWE-416 CVE-2025-26663: Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attack Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21294P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21294 [HIGH] CWE-591 CVE-2025-21294: Microsoft Digest Authentication Remote Code Execution Vulnerability Microsoft Digest Authentication Remote Code Execution Vulnerability
nvd
CVE-2026-40415P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-40415 [HIGH] CWE-416 CVE-2026-40415: Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network. Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-45635P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-45635 [HIGH] CWE-843 CVE-2026-45635: Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-45599P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-45599 [HIGH] CWE-416 CVE-2026-45599: Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21204P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-21204 [HIGH] CWE-59 CVE-2025-21204: Improper link resolution before file access ('link following') in Windows Update Stack allows an aut Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-24871P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-24871 [HIGH] CWE-190 CVE-2023-24871: Windows Bluetooth Service Remote Code Execution Vulnerability Windows Bluetooth Service Remote Code Execution Vulnerability
nvd
CVE-2026-33829P4MEDIUMCVSS 4.3PoC≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-33829 [MEDIUM] CWE-200 CVE-2026-33829: Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauth Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2022-24541P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.16452022-04-15
CVE-2022-24541 [HIGH] CVE-2022-24541: Windows Server Service Remote Code Execution Vulnerability Windows Server Service Remote Code Execution Vulnerability
nvd
CVE-2022-24508P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.15862022-03-09
CVE-2022-24508 [HIGH] CVE-2022-24508: Win32 File Enumeration Remote Code Execution Vulnerability Win32 File Enumeration Remote Code Execution Vulnerability
nvd
CVE-2022-30153P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19043.17662022-06-15
CVE-2022-30153 [HIGH] CVE-2022-30153: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-30161P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19043.17662022-06-15
CVE-2022-30161 [HIGH] CVE-2022-30161: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29139P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19043.17062022-05-10
CVE-2022-29139 [HIGH] CVE-2022-29139: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2024-26166P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.41702024-03-12
CVE-2024-26166 [HIGH] CWE-122 CVE-2024-26166: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21450P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.41702024-03-12
CVE-2024-21450 [HIGH] CWE-190 CVE-2024-21450: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21440P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.41702024-03-12
CVE-2024-21440 [HIGH] CWE-197 CVE-2024-21440: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2024-26162P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.41702024-03-12
CVE-2024-26162 [HIGH] CWE-681 CVE-2024-26162: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase