cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 150 of 182
CVE-2026-59135P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-59135 [MEDIUM] CWE-1390 CVE-2026-59135: Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32214P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32214 [MEDIUM] CWE-284 CVE-2026-32214: Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to discl Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
nvd
CVE-2026-20806P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-20806 [MEDIUM] CWE-843 CVE-2026-20806: Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized at Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69453P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69453 [MEDIUM] CWE-862 CVE-2026-69453: Missing authorization in Microsoft Windows Search Component allows an authorized attacker to perform Missing authorization in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.
nvd
CVE-2026-61936P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61936 [MEDIUM] CWE-862 CVE-2026-61936: Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-50495P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50495 [MEDIUM] CWE-284 CVE-2026-50495: Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
nvd
CVE-2026-50303P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50303 [MEDIUM] CWE-1240 CVE-2026-50303: Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authoriz Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2025-55229P4MEDIUMCVSS 5.3≥ 10.0.19044.0, < 10.0.19044.58542025-08-21
CVE-2025-55229 [MEDIUM] CWE-347 CVE-2025-55229: Improper verification of cryptographic signature in Windows Certificates allows an unauthorized atta Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-69474P4MEDIUMCVSS 4.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69474 [MEDIUM] CWE-126 CVE-2026-69474: Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network.
nvd
CVE-2023-28235P4MEDIUMCVSS 6.8≥ 10.0.19043.0, < 10.0.19044.28462023-04-11
CVE-2023-28235 [MEDIUM] CVE-2023-28235: Windows Lock Screen Security Feature Bypass Vulnerability Windows Lock Screen Security Feature Bypass Vulnerability
nvd
CVE-2023-28270P4MEDIUMCVSS 6.8≥ 10.0.19043.0, < 10.0.19044.28462023-04-11
CVE-2023-28270 [MEDIUM] CWE-863 CVE-2023-28270: Windows Lock Screen Security Feature Bypass Vulnerability Windows Lock Screen Security Feature Bypass Vulnerability
nvd
CVE-2025-47999P4MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-47999 [MEDIUM] CWE-820 CVE-2025-47999: Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adj Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
nvd
CVE-2022-21928P4MEDIUMCVSS 6.4≥ 10.0.19043.0, < 10.0.19043.14662022-01-11
CVE-2022-21928 [MEDIUM] CVE-2022-21928: Windows Resilient File System (ReFS) Remote Code Execution Vulnerability Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
nvd
CVE-2025-21202P4MEDIUMCVSS 6.1≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21202 [MEDIUM] CWE-284 CVE-2025-21202: Windows Recovery Environment Agent Elevation of Privilege Vulnerability Windows Recovery Environment Agent Elevation of Privilege Vulnerability
nvd
CVE-2025-29974P4MEDIUMCVSS 5.7≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29974 [MEDIUM] CWE-125 CVE-2025-29974: Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an adjacent network.
nvd
CVE-2025-32722P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.59652025-06-10
CVE-2025-32722 [MEDIUM] CWE-284 CVE-2025-32722: Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose inf Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2025-54101P4MEDIUMCVSS 4.8≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-54101 [MEDIUM] CWE-416 CVE-2025-54101: Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network. Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network.
nvd
CVE-2026-20932P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20932 [MEDIUM] CWE-200 CVE-2026-20932: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-20823P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20823 [MEDIUM] CWE-200 CVE-2026-20823: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-20862P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20862 [MEDIUM] CWE-200 CVE-2026-20862: Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase