Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13
Vulnerabilities
Page 150 of 182
CVE-2026-59135P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-59135 [MEDIUM] CWE-1390 CVE-2026-59135: Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose
Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32214P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32214 [MEDIUM] CWE-284 CVE-2026-32214: Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to discl
Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
nvd
CVE-2026-20806P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-20806 [MEDIUM] CWE-843 CVE-2026-20806: Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized at
Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69453P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69453 [MEDIUM] CWE-862 CVE-2026-69453: Missing authorization in Microsoft Windows Search Component allows an authorized attacker to perform
Missing authorization in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.
nvd
CVE-2026-61936P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61936 [MEDIUM] CWE-862 CVE-2026-61936: Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a
Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-50495P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50495 [MEDIUM] CWE-284 CVE-2026-50495: Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
nvd
CVE-2026-50303P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50303 [MEDIUM] CWE-1240 CVE-2026-50303: Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authoriz
Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2025-55229P4MEDIUMCVSS 5.3≥ 10.0.19044.0, < 10.0.19044.58542025-08-21
CVE-2025-55229 [MEDIUM] CWE-347 CVE-2025-55229: Improper verification of cryptographic signature in Windows Certificates allows an unauthorized atta
Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-69474P4MEDIUMCVSS 4.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69474 [MEDIUM] CWE-126 CVE-2026-69474: Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over
Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network.
nvd
CVE-2023-28235P4MEDIUMCVSS 6.8≥ 10.0.19043.0, < 10.0.19044.28462023-04-11
CVE-2023-28235 [MEDIUM] CVE-2023-28235: Windows Lock Screen Security Feature Bypass Vulnerability
Windows Lock Screen Security Feature Bypass Vulnerability
nvd
CVE-2023-28270P4MEDIUMCVSS 6.8≥ 10.0.19043.0, < 10.0.19044.28462023-04-11
CVE-2023-28270 [MEDIUM] CWE-863 CVE-2023-28270: Windows Lock Screen Security Feature Bypass Vulnerability
Windows Lock Screen Security Feature Bypass Vulnerability
nvd
CVE-2025-47999P4MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-47999 [MEDIUM] CWE-820 CVE-2025-47999: Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adj
Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
nvd
CVE-2022-21928P4MEDIUMCVSS 6.4≥ 10.0.19043.0, < 10.0.19043.14662022-01-11
CVE-2022-21928 [MEDIUM] CVE-2022-21928: Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
nvd
CVE-2025-21202P4MEDIUMCVSS 6.1≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21202 [MEDIUM] CWE-284 CVE-2025-21202: Windows Recovery Environment Agent Elevation of Privilege Vulnerability
Windows Recovery Environment Agent Elevation of Privilege Vulnerability
nvd
CVE-2025-29974P4MEDIUMCVSS 5.7≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29974 [MEDIUM] CWE-125 CVE-2025-29974: Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose
Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an adjacent network.
nvd
CVE-2025-32722P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.59652025-06-10
CVE-2025-32722 [MEDIUM] CWE-284 CVE-2025-32722: Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose inf
Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2025-54101P4MEDIUMCVSS 4.8≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-54101 [MEDIUM] CWE-416 CVE-2025-54101: Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network.
Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network.
nvd
CVE-2026-20932P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20932 [MEDIUM] CWE-200 CVE-2026-20932: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-20823P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20823 [MEDIUM] CWE-200 CVE-2026-20823: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-20862P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20862 [MEDIUM] CWE-200 CVE-2026-20862: Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an
Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally.
nvd