cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

2,906 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
2,906
CISA KEV
95
actively exploited
Public exploits
67
Exploited in wild
124
Severity breakdown
CRITICAL79HIGH2093MEDIUM721LOW13

Vulnerabilities

Page 72 of 146
CVE-2026-27921P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-27921 [HIGH] CWE-362 CVE-2026-27921: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-41108P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-41108 [HIGH] CWE-122 CVE-2026-41108: Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privile Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-45653P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-45653 [HIGH] CWE-122 CVE-2026-45653: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-26635P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-26635 [MEDIUM] CWE-1390 CVE-2025-26635: Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.
nvd
CVE-2022-29105P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19043.17062022-05-10
CVE-2022-29105 [HIGH] CVE-2022-29105: Microsoft Windows Media Foundation Remote Code Execution Vulnerability Microsoft Windows Media Foundation Remote Code Execution Vulnerability
nvd
CVE-2021-43232P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.19044.14152021-12-15
CVE-2021-43232 [HIGH] CVE-2021-43232: Windows Event Tracing Remote Code Execution Vulnerability Windows Event Tracing Remote Code Execution Vulnerability
nvd
CVE-2022-26917P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19043.16452022-04-15
CVE-2022-26917 [HIGH] CVE-2022-26917: Windows Fax Compose Form Remote Code Execution Vulnerability Windows Fax Compose Form Remote Code Execution Vulnerability
nvd
CVE-2022-26918P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19043.16452022-04-15
CVE-2022-26918 [HIGH] CVE-2022-26918: Windows Fax Compose Form Remote Code Execution Vulnerability Windows Fax Compose Form Remote Code Execution Vulnerability
nvd
CVE-2022-26916P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19043.16452022-04-15
CVE-2022-26916 [HIGH] CVE-2022-26916: Windows Fax Compose Form Remote Code Execution Vulnerability Windows Fax Compose Form Remote Code Execution Vulnerability
nvd
CVE-2022-35743P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.18892023-05-31
CVE-2022-35743 [HIGH] CWE-94 CVE-2022-35743: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
nvd
CVE-2023-36596P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-36596 [HIGH] CWE-822 CVE-2023-36596: Remote Procedure Call Information Disclosure Vulnerability Remote Procedure Call Information Disclosure Vulnerability
nvd
CVE-2022-30200P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.20062022-09-13
CVE-2022-30200 [HIGH] CVE-2022-30200: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-21895P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19043.14662022-01-11
CVE-2022-21895 [HIGH] CWE-59 CVE-2022-21895: Windows User Profile Service Elevation of Privilege Vulnerability Windows User Profile Service Elevation of Privilege Vulnerability
nvd
CVE-2022-21995P3HIGHCVSS 7.9≥ 10.0.19043.0, < 10.0.19044.15262022-02-09
CVE-2022-21995 [HIGH] CVE-2022-21995: Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2023-36710P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-36710 [HIGH] CWE-197 CVE-2023-36710: Windows Media Foundation Core Remote Code Execution Vulnerability Windows Media Foundation Core Remote Code Execution Vulnerability
nvd
CVE-2022-21897P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.14662022-01-11
CVE-2022-21897 [HIGH] CVE-2022-21897: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-22049P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.18262022-07-12
CVE-2022-22049 [HIGH] CWE-787 CVE-2022-22049: Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
nvd
CVE-2023-36438P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-36438 [HIGH] CVE-2023-36438: Windows TCP/IP Information Disclosure Vulnerability Windows TCP/IP Information Disclosure Vulnerability
nvd
CVE-2022-21916P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19043.14662022-01-11
CVE-2022-21916 [HIGH] CVE-2022-21916: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-21879P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.14662022-01-11
CVE-2022-21879 [HIGH] CVE-2022-21879: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd