cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13

Vulnerabilities

Page 33 of 182
CVE-2022-34730P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.20062022-09-13
CVE-2022-34730 [HIGH] CVE-2022-34730: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2022-34726P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.20062022-09-13
CVE-2022-34726 [HIGH] CVE-2022-34726: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2024-38054P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.46512024-07-09
CVE-2024-38054 [HIGH] CWE-122 CVE-2024-38054: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-38180P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.47802024-08-13
CVE-2024-38180 [HIGH] CWE-693 CVE-2024-38180: Windows SmartScreen Security Feature Bypass Vulnerability Windows SmartScreen Security Feature Bypass Vulnerability
nvd
CVE-2024-21369P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.40462024-02-13
CVE-2024-21369 [HIGH] CWE-122 CVE-2024-21369: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21350P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.40462024-02-13
CVE-2024-21350 [HIGH] CWE-190 CVE-2024-21350: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2023-29362P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.30862023-06-14
CVE-2023-29362 [HIGH] CWE-122 CVE-2023-29362: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2025-29967P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29967 [HIGH] CWE-122 CVE-2025-29967: Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to exec Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-50509P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50509 [HIGH] CWE-502 CVE-2026-50509: Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20843P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20843 [HIGH] CWE-284 CVE-2026-20843: Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized att Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21238P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.69372026-02-10
CVE-2026-21238 [HIGH] CWE-284 CVE-2026-21238: Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attack Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-30141P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19043.17662022-06-15
CVE-2022-30141 [HIGH] CVE-2022-30141: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2026-26178P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-26178 [HIGH] CWE-190 CVE-2026-26178: Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized att Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2022-26919P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19043.16452022-04-15
CVE-2022-26919 [HIGH] CVE-2022-26919: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2026-69784P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69784 [HIGH] CWE-416 CVE-2026-69784: Use after free in Windows Hello allows an authorized attacker to elevate privileges locally. Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21231P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.69372026-02-10
CVE-2026-21231 [HIGH] CWE-362 CVE-2026-21231: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24035P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.56082025-03-11
CVE-2025-24035 [HIGH] CWE-591 CVE-2025-24035: Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unau Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21295P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21295 [HIGH] CWE-416 CVE-2025-21295: SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
nvd
CVE-2022-22025P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.18262022-07-12
CVE-2022-22025 [HIGH] CVE-2022-22025: Windows Internet Information Services Cachuri Module Denial of Service Vulnerability Windows Internet Information Services Cachuri Module Denial of Service Vulnerability
nvd
CVE-2026-69638P3HIGHCVSS 8.4≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69638 [HIGH] CWE-122 CVE-2026-69638: Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase