cbcvebase.

Microsoft Windows 10 21H2 vulnerabilities

1,830 known vulnerabilities affecting microsoft/windows_10_21h2.

Total CVEs
1,830
CISA KEV
87
actively exploited
Public exploits
54
Exploited in wild
97
Severity breakdown
CRITICAL44HIGH1306MEDIUM473LOW7

Vulnerabilities

Page 80 of 92
CVE-2025-59211P4MEDIUMCVSS 5.5fixed in 10.0.19044.64562025-10-14
CVE-2025-59211 [MEDIUM] CWE-200 CVE-2025-59211: Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
nvd
CVE-2026-20829P4MEDIUMCVSS 5.5fixed in 10.0.19044.68092026-01-13
CVE-2026-20829 [MEDIUM] CWE-125 CVE-2026-20829: Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally. Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.
nvd
CVE-2025-59509P4MEDIUMCVSS 5.5fixed in 10.0.19044.65752025-11-11
CVE-2025-59509 [MEDIUM] CWE-201 CVE-2025-59509: Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose information locally.
nvd
CVE-2024-43585P4MEDIUMCVSS 5.5fixed in 10.0.19044.50112024-10-08
CVE-2024-43585 [MEDIUM] CWE-693 CVE-2024-43585: Code Integrity Guard Security Feature Bypass Vulnerability Code Integrity Guard Security Feature Bypass Vulnerability
nvd
CVE-2025-59204P4MEDIUMCVSS 5.5fixed in 10.0.19044.64562025-10-14
CVE-2025-59204 [MEDIUM] CWE-908 CVE-2025-59204: Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclo Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclose information locally.
nvd
CVE-2025-59513P4MEDIUMCVSS 5.5fixed in 10.0.19044.65752025-11-11
CVE-2025-59513 [MEDIUM] CWE-125 CVE-2025-59513: Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to discl Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2025-49684P4MEDIUMCVSS 5.5fixed in 10.0.19044.60932025-07-08
CVE-2025-49684 [MEDIUM] CWE-126 CVE-2025-49684: Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locall Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42972P4MEDIUMCVSS 5.5fixed in 10.0.19044.74172026-06-09
CVE-2026-42972 [MEDIUM] CWE-200 CVE-2026-42972: Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized a Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42968P4MEDIUMCVSS 5.5fixed in 10.0.19044.74172026-06-09
CVE-2026-42968 [MEDIUM] CWE-125 CVE-2026-42968: Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose informatio Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-45594P4MEDIUMCVSS 5.5fixed in 10.0.19044.74172026-06-09
CVE-2026-45594 [MEDIUM] CWE-200 CVE-2026-45594: Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) S Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32212P4MEDIUMCVSS 5.5fixed in 10.0.19044.71842026-04-14
CVE-2026-32212 [MEDIUM] CWE-59 CVE-2026-32212: Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
nvd
CVE-2026-45634P4MEDIUMCVSS 5.5fixed in 10.0.19044.74172026-06-09
CVE-2026-45634 [MEDIUM] CWE-125 CVE-2026-45634: Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information loca Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32214P4MEDIUMCVSS 5.5fixed in 10.0.19044.71842026-04-14
CVE-2026-32214 [MEDIUM] CWE-284 CVE-2026-32214: Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to discl Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
nvd
CVE-2023-28226P4MEDIUMCVSS 5.3fixed in 10.0.19044.28462023-04-11
CVE-2023-28226 [MEDIUM] CWE-347 CVE-2023-28226: Windows Enroll Engine Security Feature Bypass Vulnerability Windows Enroll Engine Security Feature Bypass Vulnerability
nvd
CVE-2023-28266P4MEDIUMCVSS 5.5fixed in 10.0.19044.28462023-04-11
CVE-2023-28266 [MEDIUM] CWE-126 CVE-2023-28266: Windows Common Log File System Driver Information Disclosure Vulnerability Windows Common Log File System Driver Information Disclosure Vulnerability
nvd
CVE-2026-24297P4MEDIUMCVSS 4.8fixed in 10.0.19044.70582026-03-10
CVE-2026-24297 [MEDIUM] CWE-362 CVE-2026-24297: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kerberos allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2023-35377P4MEDIUMCVSS 6.5fixed in 10.0.19044.33242023-08-08
CVE-2023-35377 [MEDIUM] CWE-20 CVE-2023-35377: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2023-35376P4MEDIUMCVSS 6.5fixed in 10.0.19044.33242023-08-08
CVE-2023-35376 [MEDIUM] CWE-20 CVE-2023-35376: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2023-36909P4MEDIUMCVSS 6.5fixed in 10.0.19044.33242023-08-08
CVE-2023-36909 [MEDIUM] CWE-191 CVE-2023-36909: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2023-20569P4MEDIUMCVSS 4.7fixed in 10.0.19044.33242023-08-08
CVE-2023-20569 [MEDIUM] CWE-203 CVE-2023-20569: A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the retur A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
nvd