← Back

Windows 11 21h2

windows_11_21h2

Vendor: Microsoft • 1,001 CVEs

CVEs (1,001)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
11Windows 10 1607
Windows 10 1809Windows 10 21h2+8 more
Jan 1, 2025
Nov 14, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Windows Kernel Information Disclosure Vulnerability
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jan 1, 2025
Nov 14, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
Windows Kernel Elevation of Privilege Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Nov 21, 2024
Nov 14, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Nov 21, 2024
Nov 14, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Microsoft Remote Registry Service Remote Code Execution Vulnerability
1Microsoft
11Windows 10 1507
Windows 10 1607Windows 10 1809+8 more
Nov 21, 2024
Nov 14, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Windows HMAC Key Derivation Elevation of Privilege Vulnerability
1Microsoft
4Windows 11 21h2
Windows 11 22h2Windows 11 23h2+1 more
Nov 21, 2024
Nov 14, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Windows Storage Elevation of Privilege Vulnerability
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Nov 21, 2024
Nov 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Windows NTFS Information Disclosure Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Nov 21, 2024
Nov 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
1Microsoft
9Windows 10 1507
Windows 10 1607Windows 10 1809+6 more
Nov 21, 2024
Nov 14, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
Windows Search Service Elevation of Privilege Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Nov 21, 2024
Nov 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows User Interface Application Core Remote Code Execution Vulnerability
1Microsoft
8Windows 10 1809
Windows 10 21h2Windows 10 22h2+5 more
Nov 21, 2024
Nov 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Authentication Elevation of Privilege Vulnerability
1Microsoft
4Windows 11 21h2
Windows 11 22h2Windows 11 23h2+1 more
Nov 21, 2024
Nov 14, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Windows Authentication Denial of Service Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Oct 28, 2025
Nov 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
1Microsoft
9Windows 10 1809
Windows 10 21h2Windows 10 22h2+6 more
Oct 28, 2025
Nov 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows DWM Core Library Elevation of Privilege Vulnerability
1Microsoft
11Windows 10 1507
Windows 10 1607Windows 10 1809+8 more
Nov 21, 2024
Nov 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Oct 28, 2025
Nov 14, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Windows SmartScreen Security Feature Bypass Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Nov 21, 2024
Nov 14, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Windows Scripting Engine Memory Corruption Vulnerability
4Fedoraproject
HaxxMicrosoft+1 more
13Active Iq Unified Manager
FedoraLibcurl+10 more
May 12, 2026
Oct 18, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl...Show more
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255 bytes. If the host name is detected to be longer, curl switches to local name resolving and instead passes on the resolved address only. Due to this bug, the local variable that means "let the host resolve the name" could get the wrong value during a slow SOCKS5 handshake, and contrary to the intention, copy the too long host name to the target buffer instead of copying just the resolved address there. The target buffer being a heap based buffer, and the host name coming from the URL that curl has been told to operate with.Show less
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Nov 21, 2024
Oct 10, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Nov 21, 2024
Oct 10, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability