cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 83 of 182
CVE-2025-53150P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-53150 [HIGH] CWE-362 CVE-2025-53150: Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-48000P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-48000 [HIGH] CWE-362 CVE-2025-48000: Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevat Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54913P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-54913 [HIGH] CWE-362 CVE-2025-54913: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapControlSettings allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59192P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-59192 [HIGH] CWE-126 CVE-2025-59192: Buffer over-read in Storport.sys Driver allows an authorized attacker to elevate privileges locally. Buffer over-read in Storport.sys Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-58714P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-58714 [HIGH] CWE-284 CVE-2025-58714: Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attack Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50673P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50673 [HIGH] CWE-367 CVE-2026-50673: Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges local Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-38119P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.48942024-09-10
CVE-2024-38119 [HIGH] CWE-416 CVE-2024-38119: Windows Network Address Translation (NAT) Remote Code Execution Vulnerability Windows Network Address Translation (NAT) Remote Code Execution Vulnerability
nvd
CVE-2023-24932MEDIUMCVSS 6.7Exploited≥ 10.0.19044.0, < 10.0.19044.60932023-05-09
CVE-2023-24932 [MEDIUM] Secure Boot Security Feature Bypass Vulnerability Secure Boot Security Feature Bypass Vulnerability Secure Boot Security Feature Bypass Vulnerability
cvelistv5
CVE-2025-50161P3HIGHCVSS 7.3≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-50161 [HIGH] CWE-122 CVE-2025-50161: Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privile Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21247P3HIGHCVSS 7.3≥ 10.0.19044.0, < 10.0.19044.69372026-02-10
CVE-2026-21247 [HIGH] CWE-20 CVE-2026-21247: Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally. Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.
nvd
CVE-2025-62565P3HIGHCVSS 7.3≥ 10.0.19044.0, < 10.0.19044.66912025-12-09
CVE-2025-62565 [HIGH] CWE-416 CVE-2025-62565: Use after free in Windows Shell allows an authorized attacker to elevate privileges locally. Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-68846P3HIGHCVSS 7.1≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-68846 [HIGH] CWE-416 CVE-2026-68846: Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network. Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69336P3HIGHCVSS 7.1≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69336 [HIGH] CWE-122 CVE-2026-69336: Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privil Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-68889P3HIGHCVSS 7.1≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-68889 [HIGH] CWE-122 CVE-2026-68889: Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privil Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69366P3HIGHCVSS 7.1≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69366 [HIGH] CWE-416 CVE-2026-69366: Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network. Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69272P3HIGHCVSS 7.1≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69272 [HIGH] CWE-122 CVE-2026-69272: Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privil Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69313P3HIGHCVSS 7.1≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69313 [HIGH] CWE-122 CVE-2026-69313: Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privil Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2022-38016P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.21302022-10-11
CVE-2022-38016 [HIGH] CVE-2022-38016: Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
nvd
CVE-2023-32009P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.30862023-06-14
CVE-2023-32009 [HIGH] CWE-284 CVE-2023-32009: Windows Collaborative Translation Framework Elevation of Privilege Vulnerability Windows Collaborative Translation Framework Elevation of Privilege Vulnerability
nvd
CVE-2022-21878P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.14662022-01-11
CVE-2022-21878 [HIGH] CVE-2022-21878: Windows Geolocation Service Remote Code Execution Vulnerability Windows Geolocation Service Remote Code Execution Vulnerability
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase