cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13

Vulnerabilities

Page 32 of 182
CVE-2026-68894P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-68894 [HIGH] CWE-122 CVE-2026-68894: Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privi Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-68876P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-68876 [HIGH] CWE-122 CVE-2026-68876: Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized a Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69271P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69271 [HIGH] CWE-122 CVE-2026-69271: Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privil Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-50452P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50452 [HIGH] CWE-362 CVE-2026-50452: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2026-50348P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50348 [HIGH] CWE-362 CVE-2026-50348: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2024-26218P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.42912024-04-09
CVE-2024-26218 [HIGH] CWE-367 CVE-2024-26218: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2026-69455P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69455 [HIGH] CWE-122 CVE-2026-69455: Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62783P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62783 [HIGH] CWE-122 CVE-2026-62783: Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62758P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62758 [HIGH] CWE-122 CVE-2026-62758: Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62755P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62755 [HIGH] CWE-121 CVE-2026-62755: Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileg Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62813P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-62813 [HIGH] CWE-416 CVE-2026-62813: Use after free in Active Directory Domain Services allows an authorized attacker to execute code ove Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.
nvd
CVE-2026-69757P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69757 [HIGH] CWE-416 CVE-2026-69757: Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges over a network. Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69761P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69761 [HIGH] CWE-416 CVE-2026-69761: Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges over a network. Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-58531P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58531 [HIGH] CWE-362 CVE-2026-58531: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2022-24492P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.16452022-04-15
CVE-2022-24492 [HIGH] CVE-2022-24492: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2024-21310P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.39302024-01-09
CVE-2024-21310 [HIGH] CWE-197 CVE-2024-21310: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2026-20817P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20817 [HIGH] CWE-280 CVE-2026-20817: Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an aut Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-34734P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.20062022-09-13
CVE-2022-34734 [HIGH] CVE-2022-34734: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2022-34727P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.20062022-09-13
CVE-2022-34727 [HIGH] CVE-2022-34727: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2022-34732P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.20062022-09-13
CVE-2022-34732 [HIGH] CVE-2022-34732: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase