cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 72 of 182
CVE-2026-26172P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-26172 [HIGH] CWE-362 CVE-2026-26172: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-27911P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-27911 [HIGH] CWE-362 CVE-2026-27911: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32160P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32160 [HIGH] CWE-362 CVE-2026-32160: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32158P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32158 [HIGH] CWE-362 CVE-2026-32158: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32163P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32163 [HIGH] CWE-362 CVE-2026-32163: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32159P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32159 [HIGH] CWE-362 CVE-2026-32159: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20930P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-20930 [HIGH] CWE-362 CVE-2026-20930: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58539P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58539 [HIGH] CWE-125 CVE-2026-58539: Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a net Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-57979P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-57979 [HIGH] CWE-125 CVE-2026-57979: Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a net Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2023-28238P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.28462023-04-11
CVE-2023-28238 [HIGH] CWE-591 CVE-2023-28238: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2025-55326P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-55326 [HIGH] CWE-416 CVE-2025-55326: Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to exe Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-27484P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-27484 [HIGH] CWE-591 CVE-2025-27484: Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-20844P3HIGHCVSS 7.4≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20844 [HIGH] CWE-362 CVE-2026-20844: Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges loc Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-32156P3HIGHCVSS 7.4≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32156 [HIGH] CWE-416 CVE-2026-32156: Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-69340P3HIGHCVSS 7.1≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69340 [HIGH] CWE-122 CVE-2026-69340: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2022-22000P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.15262022-02-09
CVE-2022-22000 [HIGH] CVE-2022-22000: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-35761P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.18892022-08-09
CVE-2022-35761 [HIGH] CWE-269 CVE-2022-35761: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-30035P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.44122024-05-14
CVE-2024-30035 [HIGH] CWE-416 CVE-2024-30035: Windows DWM Core Library Elevation of Privilege Vulnerability Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2022-22026P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.18262022-07-12
CVE-2022-22026 [HIGH] CWE-787 CVE-2022-22026: Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
nvd
CVE-2026-35422P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-35422 [MEDIUM] CWE-288 CVE-2026-35422: Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized atta Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase