cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13

Vulnerabilities

Page 60 of 182
CVE-2024-30015P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.44122024-05-14
CVE-2024-30015 [HIGH] CWE-197 CVE-2024-30015: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-30029P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.44122024-05-14
CVE-2024-30029 [HIGH] CWE-197 CVE-2024-30029: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-30014P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.44122024-05-14
CVE-2024-30014 [HIGH] CWE-197 CVE-2024-30014: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2026-25181P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-25181 [HIGH] CWE-125 CVE-2026-25181: Out-of-bounds read in Windows GDI+ allows an unauthorized attacker to disclose information over a ne Out-of-bounds read in Windows GDI+ allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-26666P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-26666 [HIGH] CWE-122 CVE-2025-26666: Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
nvd
CVE-2025-26674P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-26674 [HIGH] CWE-122 CVE-2025-26674: Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
nvd
CVE-2024-38028P3HIGHCVSS 7.2≥ 10.0.19043.0, < 10.0.19044.46512024-07-09
CVE-2024-38028 [HIGH] CWE-125 CVE-2024-38028: Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
nvd
CVE-2024-38025P3HIGHCVSS 7.2≥ 10.0.19043.0, < 10.0.19044.46512024-07-09
CVE-2024-38025 [HIGH] CWE-122 CVE-2024-38025: Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
nvd
CVE-2025-24048P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.56082025-03-11
CVE-2025-24048 [HIGH] CWE-122 CVE-2025-24048: Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privile Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24050P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.56082025-03-11
CVE-2025-24050 [HIGH] CWE-122 CVE-2025-24050: Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privile Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-24474P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.16452022-04-15
CVE-2022-24474 [HIGH] CVE-2022-24474: Windows Win32k Elevation of Privilege Vulnerability Windows Win32k Elevation of Privilege Vulnerability
nvd
CVE-2024-30098P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.64562024-07-09
CVE-2024-30098 [HIGH] CWE-327 CVE-2024-30098: Windows Cryptographic Services Security Feature Bypass Vulnerability Windows Cryptographic Services Security Feature Bypass Vulnerability
nvd
CVE-2026-54984P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-54984 [HIGH] CWE-122 CVE-2026-54984: Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute c Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50347P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50347 [HIGH] CWE-122 CVE-2026-50347: Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code local Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.
nvd
CVE-2023-36401P3HIGHCVSS 7.2≥ 10.0.19043.0, < 10.0.19043.36932023-11-14
CVE-2023-36401 [HIGH] CWE-190 CVE-2023-36401: Microsoft Remote Registry Service Remote Code Execution Vulnerability Microsoft Remote Registry Service Remote Code Execution Vulnerability
nvd
CVE-2026-69428P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69428 [HIGH] CWE-125 CVE-2026-69428: Out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized at Out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-49788P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49788 [HIGH] CWE-770 CVE-2026-49788: Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to de Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-44806P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-44806 [HIGH] CWE-401 CVE-2026-44806: Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unaut Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-49160P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-49160 [HIGH] CWE-400 CVE-2026-49160: Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a n Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-35424P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-35424 [HIGH] CWE-401 CVE-2026-35424: Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol a Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase