cbcvebase.

Microsoft Windows 10 Version 22H2 vulnerabilities

2,407 known vulnerabilities affecting microsoft/windows_10_version_22h2.

Total CVEs
2,407
CISA KEV
79
actively exploited
Public exploits
52
Exploited in wild
96
Severity breakdown
CRITICAL63HIGH1710MEDIUM623LOW11

Vulnerabilities

Page 9 of 121
CVE-2023-21746HIGHCVSS 7.8ExploitedPoC≥ 10.0.19045.0, < 10.0.19045.24862023-01-10
CVE-2023-21746 [HIGH] Windows NTLM Elevation of Privilege Vulnerability Windows NTLM Elevation of Privilege Vulnerability Windows NTLM Elevation of Privilege Vulnerability
cvelistv5
CVE-2025-33064P2HIGHCVSS 8.8≥ 10.0.19045.0, < 10.0.19045.59652025-06-10
CVE-2025-33064 [HIGH] CWE-122 CVE-2025-33064: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
nvd
CVE-2026-50666P2HIGHCVSS 8.8≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-50666 [HIGH] CWE-416 CVE-2026-50666: Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-50360P2HIGHCVSS 8.8≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-50360 [HIGH] CWE-303 CVE-2026-50360: Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized atta Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2023-32015P2CRITICALCVSS 9.8≥ 10.0.19045.0, < 10.0.19045.30862023-06-14
CVE-2023-32015 [CRITICAL] CWE-20 CVE-2023-32015: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-28250P2CRITICALCVSS 9.8≥ 10.0.19045.0, < 10.0.19045.28462023-04-11
CVE-2023-28250 [CRITICAL] CWE-191 CVE-2023-28250: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-29363P2CRITICALCVSS 9.8≥ 10.0.19045.0, < 10.0.19045.30862023-06-14
CVE-2023-29363 [CRITICAL] CWE-122 CVE-2023-29363: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-32014P2CRITICALCVSS 9.8≥ 10.0.19045.0, < 10.0.19045.30862023-06-14
CVE-2023-32014 [CRITICAL] CWE-191 CVE-2023-32014: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-35365P2CRITICALCVSS 9.8≥ 10.0.19045.0, < 10.0.19045.32082023-07-11
CVE-2023-35365 [CRITICAL] CWE-20 CVE-2023-35365: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2023-35366P2CRITICALCVSS 9.8≥ 10.0.19045.0, < 10.0.19045.32082023-07-11
CVE-2023-35366 [CRITICAL] CWE-20 CVE-2023-35366: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2023-35367P2CRITICALCVSS 9.8≥ 10.0.19045.0, < 10.0.19045.32082023-07-11
CVE-2023-35367 [CRITICAL] CWE-20 CVE-2023-35367: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2023-36911P2CRITICALCVSS 9.8≥ 10.0.19045.0, < 10.0.19045.33242023-08-08
CVE-2023-36911 [CRITICAL] CWE-190 CVE-2023-36911: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2025-26670P2HIGHCVSS 8.1≥ 10.0.19045.0, < 10.0.19045.57372025-04-08
CVE-2025-26670 [HIGH] CWE-416 CVE-2025-26670: Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attack Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
nvd
CVE-2022-44666P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.23642022-12-13
CVE-2022-44666 [HIGH] CVE-2022-44666: Windows Contacts Remote Code Execution Vulnerability Windows Contacts Remote Code Execution Vulnerability
nvd
CVE-2026-25177P2HIGHCVSS 8.8≥ 10.0.19045.0, < 10.0.19045.70582026-03-10
CVE-2026-25177 [HIGH] CWE-641 CVE-2026-25177: Improper restriction of names for files and other resources in Active Directory Domain Services allo Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-58626P2HIGHCVSS 8.8≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-58626 [HIGH] CWE-416 CVE-2026-58626: Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
nvd
CVE-2026-50502P2HIGHCVSS 8.8≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-50502 [HIGH] CWE-1220 CVE-2026-50502: Insufficient granularity of access control in Windows Event Logging Service allows an authorized att Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.
nvd
CVE-2023-21752P3HIGHCVSS 7.1PoC≥ 10.0.19045.0, < 10.0.19045.24862023-01-10
CVE-2023-21752 [HIGH] CWE-284 CVE-2023-21752: Windows Backup Service Elevation of Privilege Vulnerability Windows Backup Service Elevation of Privilege Vulnerability
nvd
CVE-2023-21803P2CRITICALCVSS 9.8≥ 10.0.19045.0, < 10.0.19045.26042023-02-14
CVE-2023-21803 [CRITICAL] CWE-190 CVE-2023-21803: Windows iSCSI Discovery Service Remote Code Execution Vulnerability Windows iSCSI Discovery Service Remote Code Execution Vulnerability
nvd
CVE-2023-36606P3HIGHCVSS 7.5≥ 10.0.19045.0, < 10.0.19045.35702023-10-10
CVE-2023-36606 [HIGH] CWE-400 CVE-2023-36606: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
Microsoft Windows 10 Version 22H2 vulnerabilities | cvebase