cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13

Vulnerabilities

Page 59 of 182
CVE-2026-48573P3HIGHCVSS 7.9≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-48573 [HIGH] CWE-1329 CVE-2026-48573: No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feat No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-48576P3HIGHCVSS 7.9≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-48576 [HIGH] CWE-1329 CVE-2026-48576: No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feat No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2025-21299P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21299 [HIGH] CWE-922 CVE-2025-21299: Windows Kerberos Security Feature Bypass Vulnerability Windows Kerberos Security Feature Bypass Vulnerability
nvd
CVE-2024-29995P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.47802024-08-13
CVE-2024-29995 [HIGH] CWE-208 CVE-2024-29995: Windows Kerberos Elevation of Privilege Vulnerability Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2022-41039P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.22512022-11-09
CVE-2022-41039 [HIGH] CWE-362 CVE-2022-41039: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2022-44676P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.23642022-12-13
CVE-2022-44676 [HIGH] CWE-362 CVE-2022-44676: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2023-21548P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.24862023-01-10
CVE-2023-21548 [HIGH] CWE-591 CVE-2023-21548: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2023-21535P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.24862023-01-10
CVE-2023-21535 [HIGH] CWE-591 CVE-2023-21535: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2022-41088P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.22512022-11-09
CVE-2022-41088 [HIGH] CWE-362 CVE-2022-41088: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-23405P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-23405 [HIGH] CWE-190 CVE-2023-23405: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2023-24908P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-24908 [HIGH] CWE-190 CVE-2023-24908: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2023-24869P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-24869 [HIGH] CWE-190 CVE-2023-24869: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2026-69906P3HIGHCVSS 8.2≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69906 [HIGH] CWE-122 CVE-2026-69906: Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate pr Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-72962P3HIGHCVSS 8.2≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-72962 [HIGH] CWE-122 CVE-2026-72962: Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate priv Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-38051P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.21302022-10-11
CVE-2022-38051 [HIGH] CVE-2022-38051: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2026-69365P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69365 [HIGH] CWE-125 CVE-2026-69365: Out-of-bounds read in Microsoft Local Security Authority Server (lsasrv) allows an authorized attack Out-of-bounds read in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2024-21307P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.39302024-01-09
CVE-2024-21307 [HIGH] CWE-416 CVE-2024-21307: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2023-28274P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.28462023-04-11
CVE-2023-28274 [HIGH] CWE-20 CVE-2023-28274: Windows Win32k Elevation of Privilege Vulnerability Windows Win32k Elevation of Privilege Vulnerability
nvd
CVE-2022-32230P3HIGHCVSS 7.5≥ 19042.1706, < 19042.1706≥ 19043.1706, < 19043.1706+1 more2022-06-14
CVE-2022-32230 [HIGH] CWE-476 CVE-2022-32230: Microsoft Windows SMBv3 suffers from a null pointer dereference in versions of Windows prior to the Microsoft Windows SMBv3 suffers from a null pointer dereference in versions of Windows prior to the April, 2022 patch set. By sending a malformed FileNormalizedNameInformation SMBv3 request over a named pipe, an attacker can cause a Blue Screen of Death (BSOD) crash of the Windows kernel. For most systems, this attack requires authentication, except in
nvd
CVE-2025-32713P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.59652025-06-10
CVE-2025-32713 [HIGH] CWE-122 CVE-2025-32713: Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase