cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13

Vulnerabilities

Page 66 of 182
CVE-2025-60714P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-60714 [HIGH] CWE-122 CVE-2025-60714: Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally. Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-50173P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-50173 [HIGH] CWE-1390 CVE-2025-50173: Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58610P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58610 [HIGH] CWE-122 CVE-2026-58610: Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50362P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50362 [HIGH] CWE-122 CVE-2026-50362: Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker t Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-54993P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-54993 [HIGH] CWE-122 CVE-2026-54993: Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-32183P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32183 [HIGH] CWE-77 CVE-2026-32183: Improper neutralization of special elements used in a command ('command injection') in Windows Snipp Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-69785P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69785 [HIGH] CWE-426 CVE-2026-69785: Untrusted search path in Windows Smart Card allows an authorized attacker to elevate privileges loca Untrusted search path in Windows Smart Card allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50462P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50462 [HIGH] CWE-73 CVE-2026-50462: External control of file name or path in Windows Ancillary Function Driver for WinSock allows an aut External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59201P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-59201 [HIGH] CWE-284 CVE-2025-59201: Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53152P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-53152 [HIGH] CWE-416 CVE-2025-53152: Use after free in Desktop Windows Manager allows an authorized attacker to execute code locally. Use after free in Desktop Windows Manager allows an authorized attacker to execute code locally.
nvd
CVE-2026-68887P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-68887 [HIGH] CWE-125 CVE-2026-68887: Out-of-bounds read in Windows Message Queuing Queue Manager allows an unauthorized attacker to deny Out-of-bounds read in Windows Message Queuing Queue Manager allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-69329P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69329 [HIGH] CWE-125 CVE-2026-69329: Out-of-bounds read in BranchCache allows an unauthorized attacker to deny service over a network. Out-of-bounds read in BranchCache allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-54113P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-54113 [HIGH] CWE-770 CVE-2026-54113: Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attack Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-59132P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-59132 [HIGH] CWE-476 CVE-2026-59132: Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a ne Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50647P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50647 [HIGH] CWE-835 CVE-2026-50647: Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD F Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-32077P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32077 [HIGH] CWE-822 CVE-2026-32077: Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an author Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50377P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50377 [HIGH] CWE-125 CVE-2026-50377: Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20923P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20923 [HIGH] CWE-416 CVE-2026-20923: Use after free in Windows Management Services allows an authorized attacker to elevate privileges lo Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-62571P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.66912025-12-09
CVE-2025-62571 [HIGH] CWE-20 CVE-2025-62571: Improper input validation in Windows Installer allows an authorized attacker to elevate privileges l Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20865P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20865 [HIGH] CWE-416 CVE-2026-20865: Use after free in Windows Management Services allows an authorized attacker to elevate privileges lo Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase