Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13
Vulnerabilities
Page 149 of 182
CVE-2026-25186P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-25186 [MEDIUM] CWE-200 CVE-2026-25186: Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (
Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to disclose information locally.
nvd
CVE-2025-47160P4MEDIUMCVSS 5.4≥ 10.0.19044.0, < 10.0.19044.59652025-06-10
CVE-2025-47160 [MEDIUM] CWE-693 CVE-2025-47160: Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security f
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-20839P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20839 [MEDIUM] CWE-284 CVE-2026-20839: Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker t
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69315P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69315 [MEDIUM] CWE-497 CVE-2026-69315: Exposure of sensitive system information to an unauthorized control sphere in Windows License Manage
Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69862P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69862 [MEDIUM] CWE-125 CVE-2026-69862: Out-of-bounds read in Windows Wireless Wide Area Network Service allows an authorized attacker to di
Out-of-bounds read in Windows Wireless Wide Area Network Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-73008P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-73008 [MEDIUM] CWE-359 CVE-2026-73008: Exposure of private personal information to an unauthorized actor in Windows Biometric Service allow
Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-49180P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49180 [MEDIUM] CWE-59 CVE-2026-49180: Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll)
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
nvd
CVE-2026-49177P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49177 [MEDIUM] CWE-125 CVE-2026-49177: Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69794P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69794 [MEDIUM] CWE-126 CVE-2026-69794: Buffer over-read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose i
Buffer over-read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69288P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69288 [MEDIUM] CWE-908 CVE-2026-69288: Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
nvd
CVE-2026-61347P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61347 [MEDIUM] CWE-126 CVE-2026-61347: Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose informat
Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-62746P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62746 [MEDIUM] CWE-126 CVE-2026-62746: Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.
Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.
nvd
CVE-2026-62793P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62793 [MEDIUM] CWE-126 CVE-2026-62793: Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50383P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50383 [MEDIUM] CWE-126 CVE-2026-50383: Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose infor
Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50381P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50381 [MEDIUM] CWE-843 CVE-2026-50381: Access of resource using incompatible type ('type confusion') in Composite Image File System Driver
Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50341P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50341 [MEDIUM] CWE-126 CVE-2026-50341: Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
nvd
CVE-2026-58614P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58614 [MEDIUM] CWE-125 CVE-2026-58614: Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature loca
Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-50475P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50475 [MEDIUM] CWE-126 CVE-2026-50475: Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.
Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2026-68830P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-68830 [MEDIUM] CWE-59 CVE-2026-68830: Improper link resolution before file access ('link following') in Windows Universal Plug and Play (U
Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69403P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69403 [MEDIUM] CWE-862 CVE-2026-69403: Missing authorization in Windows SMB Server allows an authorized attacker to disclose information lo
Missing authorization in Windows SMB Server allows an authorized attacker to disclose information locally.
nvd