Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13
Vulnerabilities
Page 60 of 182
CVE-2024-30015P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.44122024-05-14
CVE-2024-30015 [HIGH] CWE-197 CVE-2024-30015: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-30029P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.44122024-05-14
CVE-2024-30029 [HIGH] CWE-197 CVE-2024-30029: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-30014P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.44122024-05-14
CVE-2024-30014 [HIGH] CWE-197 CVE-2024-30014: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2026-25181P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-25181 [HIGH] CWE-125 CVE-2026-25181: Out-of-bounds read in Windows GDI+ allows an unauthorized attacker to disclose information over a ne
Out-of-bounds read in Windows GDI+ allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-26666P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-26666 [HIGH] CWE-122 CVE-2025-26666: Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
nvd
CVE-2025-26674P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-26674 [HIGH] CWE-122 CVE-2025-26674: Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
nvd
CVE-2024-38028P3HIGHCVSS 7.2≥ 10.0.19043.0, < 10.0.19044.46512024-07-09
CVE-2024-38028 [HIGH] CWE-125 CVE-2024-38028: Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
nvd
CVE-2024-38025P3HIGHCVSS 7.2≥ 10.0.19043.0, < 10.0.19044.46512024-07-09
CVE-2024-38025 [HIGH] CWE-122 CVE-2024-38025: Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
nvd
CVE-2025-24048P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.56082025-03-11
CVE-2025-24048 [HIGH] CWE-122 CVE-2025-24048: Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privile
Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24050P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.56082025-03-11
CVE-2025-24050 [HIGH] CWE-122 CVE-2025-24050: Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privile
Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-24474P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.16452022-04-15
CVE-2022-24474 [HIGH] CVE-2022-24474: Windows Win32k Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
nvd
CVE-2024-30098P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.64562024-07-09
CVE-2024-30098 [HIGH] CWE-327 CVE-2024-30098: Windows Cryptographic Services Security Feature Bypass Vulnerability
Windows Cryptographic Services Security Feature Bypass Vulnerability
nvd
CVE-2026-54984P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-54984 [HIGH] CWE-122 CVE-2026-54984: Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute c
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50347P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50347 [HIGH] CWE-122 CVE-2026-50347: Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code local
Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.
nvd
CVE-2023-36401P3HIGHCVSS 7.2≥ 10.0.19043.0, < 10.0.19043.36932023-11-14
CVE-2023-36401 [HIGH] CWE-190 CVE-2023-36401: Microsoft Remote Registry Service Remote Code Execution Vulnerability
Microsoft Remote Registry Service Remote Code Execution Vulnerability
nvd
CVE-2026-69428P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69428 [HIGH] CWE-125 CVE-2026-69428: Out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized at
Out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-49788P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49788 [HIGH] CWE-770 CVE-2026-49788: Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to de
Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-44806P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-44806 [HIGH] CWE-401 CVE-2026-44806: Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unaut
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-49160P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-49160 [HIGH] CWE-400 CVE-2026-49160: Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a n
Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-35424P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-35424 [HIGH] CWE-401 CVE-2026-35424: Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol a
Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.
nvd