Microsoft Windows 10 Version 21H2 vulnerabilities
2,906 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
2,906
CISA KEV
95
actively exploited
Public exploits
67
Exploited in wild
124
Severity breakdown
CRITICAL79HIGH2093MEDIUM721LOW13
Vulnerabilities
Page 121 of 146
CVE-2025-21263P4MEDIUMCVSS 6.6≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21263 [MEDIUM] CWE-125 CVE-2025-21263: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21327P4MEDIUMCVSS 6.6≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21327 [MEDIUM] CWE-125 CVE-2025-21327: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21265P4MEDIUMCVSS 6.6≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21265 [MEDIUM] CWE-125 CVE-2025-21265: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21261P4MEDIUMCVSS 6.6≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21261 [MEDIUM] CWE-125 CVE-2025-21261: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21341P4MEDIUMCVSS 6.6≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21341 [MEDIUM] CWE-125 CVE-2025-21341: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2023-24944P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.29652023-05-09
CVE-2023-24944 [MEDIUM] CWE-843 CVE-2023-24944: Windows Bluetooth Driver Information Disclosure Vulnerability
Windows Bluetooth Driver Information Disclosure Vulnerability
nvd
CVE-2025-62463P4MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.66912025-12-09
CVE-2025-62463 [MEDIUM] CWE-476 CVE-2025-62463: Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.
Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.
nvd
CVE-2022-41086P4MEDIUMCVSS 6.4≥ 10.0.19043.0, < 10.0.19044.22512022-11-09
CVE-2022-41086 [MEDIUM] CWE-362 CVE-2022-41086: Windows Group Policy Elevation of Privilege Vulnerability
Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2022-24503P4MEDIUMCVSS 5.3≥ 10.0.19043.0, < 10.0.19044.15862022-03-09
CVE-2022-24503 [MEDIUM] CVE-2022-24503: Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability
nvd
CVE-2023-21693P4MEDIUMCVSS 5.7≥ 10.0.19043.0, < 10.0.19044.26042023-02-14
CVE-2023-21693 [MEDIUM] CWE-125 CVE-2023-21693: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2024-20692P4MEDIUMCVSS 5.7≥ 10.0.19043.0, < 10.0.19044.39302024-01-09
CVE-2024-20692 [MEDIUM] CWE-326 CVE-2024-20692: Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
nvd
CVE-2024-43547P4MEDIUMCVSS 5.9≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43547 [MEDIUM] CWE-325 CVE-2024-43547: Windows Kerberos Information Disclosure Vulnerability
Windows Kerberos Information Disclosure Vulnerability
nvd
CVE-2025-21269P4MEDIUMCVSS 4.3≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21269 [MEDIUM] CWE-41 CVE-2025-21269: Windows HTML Platforms Security Feature Bypass Vulnerability
Windows HTML Platforms Security Feature Bypass Vulnerability
nvd
CVE-2025-53136P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-53136 [MEDIUM] CWE-200 CVE-2025-53136: Exposure of sensitive information to an unauthorized actor in Windows NT OS Kernel allows an authori
Exposure of sensitive information to an unauthorized actor in Windows NT OS Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2025-53799P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-53799 [MEDIUM] CWE-908 CVE-2025-53799: Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclo
Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.
nvd
CVE-2023-36889P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.33242023-08-08
CVE-2023-36889 [MEDIUM] CWE-284 CVE-2023-36889: Windows Group Policy Security Feature Bypass Vulnerability
Windows Group Policy Security Feature Bypass Vulnerability
nvd
CVE-2025-53804P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-53804 [MEDIUM] CWE-200 CVE-2025-53804: Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized at
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2025-59211P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-59211 [MEDIUM] CWE-200 CVE-2025-59211: Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
nvd
CVE-2026-21222P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.69372026-02-10
CVE-2026-21222 [MEDIUM] CWE-532 CVE-2026-21222: Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2025-29837P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29837 [MEDIUM] CWE-59 CVE-2025-29837: Improper link resolution before file access ('link following') in Windows Installer allows an author
Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally.
nvd