cbcvebase.

Microsoft Windows 10 Version 22H2 vulnerabilities

2,407 known vulnerabilities affecting microsoft/windows_10_version_22h2.

Total CVEs
2,407
CISA KEV
79
actively exploited
Public exploits
52
Exploited in wild
96
Severity breakdown
CRITICAL63HIGH1710MEDIUM623LOW11

Vulnerabilities

Page 26 of 121
CVE-2024-49132P3HIGHCVSS 8.1≥ 10.0.19045.0, < 10.0.19045.52472024-12-12
CVE-2024-49132 [HIGH] CWE-416 CVE-2024-49132: Windows Remote Desktop Services Remote Code Execution Vulnerability Windows Remote Desktop Services Remote Code Execution Vulnerability
nvd
CVE-2026-50476P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-50476 [HIGH] CWE-416 CVE-2026-50476: Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally. Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-23416P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.27282023-03-14
CVE-2023-23416 [HIGH] CWE-20 CVE-2023-23416: Windows Cryptographic Services Remote Code Execution Vulnerability Windows Cryptographic Services Remote Code Execution Vulnerability
nvd
CVE-2024-38052P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.46512024-07-09
CVE-2024-38052 [HIGH] CWE-20 CVE-2024-38052: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-36400P3HIGHCVSS 8.8≥ 10.0.19045.0, < 10.0.19045.36932023-11-14
CVE-2023-36400 [HIGH] CWE-122 CVE-2023-36400: Windows HMAC Key Derivation Elevation of Privilege Vulnerability Windows HMAC Key Derivation Elevation of Privilege Vulnerability
nvd
CVE-2026-26128P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.70582026-03-10
CVE-2026-26128 [HIGH] CWE-287 CVE-2026-26128: Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges lo Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20864P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.68092026-01-13
CVE-2026-20864 [HIGH] CWE-122 CVE-2026-20864: Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attac Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54992P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-54992 [HIGH] CWE-122 CVE-2026-54992: Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-21239P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.69372026-02-10
CVE-2026-21239 [HIGH] CWE-122 CVE-2026-21239: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-21539P3HIGHCVSS 7.5≥ 10.0.19045.0, < 10.0.19045.24862023-01-10
CVE-2023-21539 [HIGH] CWE-125 CVE-2023-21539: Windows Authentication Remote Code Execution Vulnerability Windows Authentication Remote Code Execution Vulnerability
nvd
CVE-2026-57091P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-57091 [HIGH] CWE-121 CVE-2026-57091: Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50489P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-50489 [HIGH] CWE-122 CVE-2026-50489: Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges loc Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58547P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-58547 [HIGH] CWE-122 CVE-2026-58547: Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to el Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50332P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-50332 [HIGH] CWE-122 CVE-2026-50332: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50680P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-50680 [HIGH] CWE-122 CVE-2026-50680: Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges lo Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50477P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-50477 [HIGH] CWE-122 CVE-2026-50477: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56650P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-56650 [HIGH] CWE-122 CVE-2026-56650: Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate p Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50484P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-50484 [HIGH] CWE-122 CVE-2026-50484: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58538P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-58538 [HIGH] CWE-122 CVE-2026-58538: Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate pri Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50363P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-50363 [HIGH] CWE-122 CVE-2026-50363: Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate pr Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows 10 Version 22H2 vulnerabilities | cvebase