cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13

Vulnerabilities

Page 45 of 182
CVE-2024-20698P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.39302024-01-09
CVE-2024-20698 [HIGH] CWE-190 CVE-2024-20698: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-35794P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.18892022-08-09
CVE-2022-35794 [HIGH] CVE-2022-35794: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2022-35767P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.18892022-08-09
CVE-2022-35767 [HIGH] CWE-94 CVE-2022-35767: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2022-35766P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.18892022-08-09
CVE-2022-35766 [HIGH] CWE-94 CVE-2022-35766: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2025-59517P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.66912025-12-09
CVE-2025-59517 [HIGH] CWE-284 CVE-2025-59517: Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privi Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-41081P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.21302022-10-11
CVE-2022-41081 [HIGH] CVE-2022-41081: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2025-54100P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.66912025-12-09
CVE-2025-54100 [HIGH] CWE-77 CVE-2025-54100: Improper neutralization of special elements used in a command ('command injection') in Windows Power Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute code locally.
nvd
CVE-2023-41773P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-41773 [HIGH] CWE-416 CVE-2023-41773: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41774P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-41774 [HIGH] CWE-416 CVE-2023-41774: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41767P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-41767 [HIGH] CWE-416 CVE-2023-41767: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-38166P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-38166 [HIGH] CWE-416 CVE-2023-38166: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41768P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-41768 [HIGH] CWE-416 CVE-2023-41768: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41771P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-41771 [HIGH] CWE-416 CVE-2023-41771: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41765P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-41765 [HIGH] CWE-416 CVE-2023-41765: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41769P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-41769 [HIGH] CWE-416 CVE-2023-41769: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41770P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-41770 [HIGH] CWE-416 CVE-2023-41770: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2026-70563P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-70563 [HIGH] CWE-59 CVE-2026-70563: Improper link resolution before file access ('link following') in Windows Shell allows an unauthoriz Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2022-30139P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19043.17662022-06-15
CVE-2022-30139 [HIGH] CVE-2022-30139: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2026-69807P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69807 [HIGH] CWE-22 CVE-2026-69807: Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-40400P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-40400 [HIGH] CWE-23 CVE-2026-40400: Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a n Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase