cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 99 of 182
CVE-2026-21253P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.69372026-02-10
CVE-2026-21253 [HIGH] CWE-416 CVE-2026-21253: Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally. Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69492P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69492 [HIGH] CWE-122 CVE-2026-69492: Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to e Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-41108P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-41108 [HIGH] CWE-122 CVE-2026-41108: Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privile Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69563P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69563 [HIGH] CWE-122 CVE-2026-69563: Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized a Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20847P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20847 [MEDIUM] CWE-200 CVE-2026-20847: Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized att Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2026-57982P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-57982 [MEDIUM] CWE-908 CVE-2026-57982: Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information o Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-50302P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50302 [MEDIUM] CWE-295 CVE-2026-50302: Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2022-37985P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.21302022-10-11
CVE-2022-37985 [MEDIUM] CVE-2022-37985: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2023-35383P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.33242023-08-08
CVE-2023-35383 [HIGH] CWE-190 CVE-2023-35383: Microsoft Message Queuing Information Disclosure Vulnerability Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2022-21901P3HIGHCVSS 8.0≥ 10.0.19043.0, < 10.0.19044.14662022-01-11
CVE-2022-21901 [HIGH] CVE-2022-21901: Windows Hyper-V Elevation of Privilege Vulnerability Windows Hyper-V Elevation of Privilege Vulnerability
nvd
CVE-2022-30166P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19043.17662022-06-15
CVE-2022-30166 [HIGH] CVE-2022-30166: Local Security Authority Subsystem Service Elevation of Privilege Vulnerability Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
nvd
CVE-2023-36567P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-36567 [HIGH] CWE-908 CVE-2023-36567: Windows Deployment Services Information Disclosure Vulnerability Windows Deployment Services Information Disclosure Vulnerability
nvd
CVE-2023-36906P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.33242023-08-08
CVE-2023-36906 [HIGH] CWE-170 CVE-2023-36906: Windows Cryptographic Services Information Disclosure Vulnerability Windows Cryptographic Services Information Disclosure Vulnerability
nvd
CVE-2022-38004P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.20062022-09-13
CVE-2022-38004 [HIGH] CVE-2022-38004: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2022-41121P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.23642022-12-13
CVE-2022-41121 [HIGH] CVE-2022-41121: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2022-34719P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.20062022-09-13
CVE-2022-34719 [HIGH] CVE-2022-34719: Windows Distributed File System (DFS) Elevation of Privilege Vulnerability Windows Distributed File System (DFS) Elevation of Privilege Vulnerability
nvd
CVE-2023-36907P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.33242023-08-08
CVE-2023-36907 [HIGH] CWE-170 CVE-2023-36907: Windows Cryptographic Services Information Disclosure Vulnerability Windows Cryptographic Services Information Disclosure Vulnerability
nvd
CVE-2022-24479P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.16452022-04-15
CVE-2022-24479 [HIGH] CVE-2022-24479: Connected User Experiences and Telemetry Elevation of Privilege Vulnerability Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
nvd
CVE-2021-43247P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.19044.14152021-12-15
CVE-2021-43247 [HIGH] CWE-787 CVE-2021-43247: Windows TCP/IP Driver Elevation of Privilege Vulnerability Windows TCP/IP Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-24550P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.16452022-04-15
CVE-2022-24550 [HIGH] CVE-2022-24550: Windows Telephony Server Elevation of Privilege Vulnerability Windows Telephony Server Elevation of Privilege Vulnerability
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase