cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13

Vulnerabilities

Page 50 of 182
CVE-2025-60705P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-60705 [HIGH] CWE-284 CVE-2025-60705: Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker t Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-21556P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.24862023-01-10
CVE-2023-21556 [HIGH] CWE-191 CVE-2023-21556: Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
nvd
CVE-2022-44683P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.23642022-12-13
CVE-2022-44683 [HIGH] CWE-416 CVE-2022-44683: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-35297P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-35297 [HIGH] CWE-843 CVE-2023-35297: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2026-54128P3HIGHCVSS 8.4≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-54128 [HIGH] CWE-416 CVE-2026-54128: Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally. Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.
nvd
CVE-2023-28283P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.29652023-05-09
CVE-2023-28283 [HIGH] CWE-591 CVE-2023-28283: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2026-81354P3HIGHCVSS 8.2≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-81354 [HIGH] CWE-122 CVE-2026-81354: Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges loca Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-30211P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.18262022-07-12
CVE-2022-30211 [HIGH] CVE-2022-30211: Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
nvd
CVE-2026-69332P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69332 [HIGH] CWE-125 CVE-2026-69332: Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a networ Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69505P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69505 [HIGH] CWE-125 CVE-2026-69505: Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a networ Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69458P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69458 [HIGH] CWE-125 CVE-2026-69458: Out-of-bounds read in Windows BitLocker allows an authorized attacker to elevate privileges over a n Out-of-bounds read in Windows BitLocker allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-50365P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50365 [HIGH] CWE-287 CVE-2026-50365: Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges ove Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.
nvd
CVE-2026-57087P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-57087 [HIGH] CWE-122 CVE-2026-57087: Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
nvd
CVE-2022-30194P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.18892022-08-09
CVE-2022-30194 [HIGH] CWE-94 CVE-2022-30194: Windows WebBrowser Control Remote Code Execution Vulnerability Windows WebBrowser Control Remote Code Execution Vulnerability
nvd
CVE-2023-38184P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.33242023-08-08
CVE-2023-38184 [HIGH] CWE-416 CVE-2023-38184: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2026-20837P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20837 [HIGH] CWE-122 CVE-2026-20837: Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
nvd
CVE-2024-26170P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.41702024-03-12
CVE-2024-26170 [HIGH] CWE-20 CVE-2024-26170: Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability
nvd
CVE-2024-49089P3HIGHCVSS 7.2≥ 10.0.19043.0, < 10.0.19044.52472024-12-12
CVE-2024-49089 [HIGH] CWE-122 CVE-2024-49089: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2025-62470P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.66912025-12-09
CVE-2025-62470 [HIGH] CWE-122 CVE-2025-62470: Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20940P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20940 [HIGH] CWE-822 CVE-2026-20940: Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker t Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase