Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13
Vulnerabilities
Page 45 of 182
CVE-2024-20698P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.39302024-01-09
CVE-2024-20698 [HIGH] CWE-190 CVE-2024-20698: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-35794P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.18892022-08-09
CVE-2022-35794 [HIGH] CVE-2022-35794: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2022-35767P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.18892022-08-09
CVE-2022-35767 [HIGH] CWE-94 CVE-2022-35767: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2022-35766P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.18892022-08-09
CVE-2022-35766 [HIGH] CWE-94 CVE-2022-35766: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2025-59517P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.66912025-12-09
CVE-2025-59517 [HIGH] CWE-284 CVE-2025-59517: Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privi
Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-41081P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.21302022-10-11
CVE-2022-41081 [HIGH] CVE-2022-41081: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2025-54100P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.66912025-12-09
CVE-2025-54100 [HIGH] CWE-77 CVE-2025-54100: Improper neutralization of special elements used in a command ('command injection') in Windows Power
Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute code locally.
nvd
CVE-2023-41773P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-41773 [HIGH] CWE-416 CVE-2023-41773: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41774P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-41774 [HIGH] CWE-416 CVE-2023-41774: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41767P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-41767 [HIGH] CWE-416 CVE-2023-41767: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-38166P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-38166 [HIGH] CWE-416 CVE-2023-38166: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41768P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-41768 [HIGH] CWE-416 CVE-2023-41768: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41771P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-41771 [HIGH] CWE-416 CVE-2023-41771: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41765P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-41765 [HIGH] CWE-416 CVE-2023-41765: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41769P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-41769 [HIGH] CWE-416 CVE-2023-41769: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41770P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-41770 [HIGH] CWE-416 CVE-2023-41770: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2026-70563P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-70563 [HIGH] CWE-59 CVE-2026-70563: Improper link resolution before file access ('link following') in Windows Shell allows an unauthoriz
Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2022-30139P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19043.17662022-06-15
CVE-2022-30139 [HIGH] CVE-2022-30139: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2026-69807P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69807 [HIGH] CWE-22 CVE-2026-69807: Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell
Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-40400P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-40400 [HIGH] CWE-23 CVE-2026-40400: Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a n
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
nvd