cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 71 of 182
CVE-2026-70579P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-70579 [HIGH] CWE-125 CVE-2026-70579: Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose informati Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-50463P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50463 [HIGH] CWE-125 CVE-2026-50463: Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-45639P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-45639 [HIGH] CWE-125 CVE-2026-45639: Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a net Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-42908P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42908 [HIGH] CWE-125 CVE-2026-42908: Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a net Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-50457P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50457 [HIGH] CWE-362 CVE-2026-50457: Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54125P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-54125 [HIGH] CWE-362 CVE-2026-54125: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50427P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50427 [HIGH] CWE-362 CVE-2026-50427: Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges local Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50689P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50689 [HIGH] CWE-362 CVE-2026-50689: Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges local Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32153P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32153 [HIGH] CWE-362 CVE-2026-32153: Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges local Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32089P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32089 [HIGH] CWE-362 CVE-2026-32089: Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges lo Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-64661P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.66912025-12-09
CVE-2025-64661 [HIGH] CWE-362 CVE-2025-64661: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58526P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58526 [HIGH] CWE-362 CVE-2026-58526: Use after free in Windows Storage allows an authorized attacker to elevate privileges locally. Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26167P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-26167 [HIGH] CWE-362 CVE-2026-26167: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69799P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69799 [HIGH] CWE-362 CVE-2026-69799: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58628P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58628 [HIGH] CWE-362 CVE-2026-58628: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42991P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42991 [HIGH] CWE-362 CVE-2026-42991: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42978P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42978 [HIGH] CWE-362 CVE-2026-42978: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42979P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42979 [HIGH] CWE-362 CVE-2026-42979: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42977P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42977 [HIGH] CWE-362 CVE-2026-42977: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32164P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32164 [HIGH] CWE-362 CVE-2026-32164: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase