Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13
Vulnerabilities
Page 72 of 182
CVE-2026-26172P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-26172 [HIGH] CWE-362 CVE-2026-26172: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-27911P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-27911 [HIGH] CWE-362 CVE-2026-27911: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32160P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32160 [HIGH] CWE-362 CVE-2026-32160: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32158P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32158 [HIGH] CWE-362 CVE-2026-32158: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32163P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32163 [HIGH] CWE-362 CVE-2026-32163: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32159P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32159 [HIGH] CWE-362 CVE-2026-32159: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20930P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-20930 [HIGH] CWE-362 CVE-2026-20930: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58539P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58539 [HIGH] CWE-125 CVE-2026-58539: Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a net
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-57979P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-57979 [HIGH] CWE-125 CVE-2026-57979: Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a net
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2023-28238P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.28462023-04-11
CVE-2023-28238 [HIGH] CWE-591 CVE-2023-28238: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2025-55326P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-55326 [HIGH] CWE-416 CVE-2025-55326: Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to exe
Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-27484P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-27484 [HIGH] CWE-591 CVE-2025-27484: Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device
Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-20844P3HIGHCVSS 7.4≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20844 [HIGH] CWE-362 CVE-2026-20844: Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges loc
Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-32156P3HIGHCVSS 7.4≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32156 [HIGH] CWE-416 CVE-2026-32156: Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-69340P3HIGHCVSS 7.1≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69340 [HIGH] CWE-122 CVE-2026-69340: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2022-22000P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.15262022-02-09
CVE-2022-22000 [HIGH] CVE-2022-22000: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-35761P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.18892022-08-09
CVE-2022-35761 [HIGH] CWE-269 CVE-2022-35761: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-30035P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.44122024-05-14
CVE-2024-30035 [HIGH] CWE-416 CVE-2024-30035: Windows DWM Core Library Elevation of Privilege Vulnerability
Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2022-22026P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.18262022-07-12
CVE-2022-22026 [HIGH] CWE-787 CVE-2022-22026: Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
nvd
CVE-2026-35422P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-35422 [MEDIUM] CWE-288 CVE-2026-35422: Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized atta
Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network.
nvd