cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 151 of 182
CVE-2026-59130P4MEDIUMCVSS 5.6≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-59130 [MEDIUM] CWE-1303 CVE-2026-59130: No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
nvd
CVE-2026-20829P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20829 [MEDIUM] CWE-125 CVE-2026-20829: Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally. Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.
nvd
CVE-2026-59131P4MEDIUMCVSS 5.6≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-59131 [MEDIUM] CWE-1303 CVE-2026-59131: No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
nvd
CVE-2026-57084P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-57084 [MEDIUM] CWE-908 CVE-2026-57084: Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose i Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.
nvd
CVE-2025-55325P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-55325 [MEDIUM] CWE-126 CVE-2025-55325: Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose in Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2026-20939P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20939 [MEDIUM] CWE-200 CVE-2026-20939: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-20937P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20937 [MEDIUM] CWE-200 CVE-2026-20937: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2024-43585P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43585 [MEDIUM] CWE-693 CVE-2024-43585: Code Integrity Guard Security Feature Bypass Vulnerability Code Integrity Guard Security Feature Bypass Vulnerability
nvd
CVE-2026-68852P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-68852 [MEDIUM] CWE-200 CVE-2026-68852: Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose informa Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69406P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69406 [MEDIUM] CWE-497 CVE-2026-69406: Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50681P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50681 [MEDIUM] CWE-200 CVE-2026-50681: Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50352P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50352 [MEDIUM] CWE-200 CVE-2026-50352: Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.
nvd
CVE-2026-34328P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-34328 [MEDIUM] CWE-200 CVE-2026-34328: Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an author Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50350P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50350 [MEDIUM] CWE-200 CVE-2026-50350: Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driv Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2026-45594P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-45594 [MEDIUM] CWE-200 CVE-2026-45594: Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) S Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.
nvd
CVE-2026-77491P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-77491 [MEDIUM] CWE-125 CVE-2026-77491: Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-69318P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69318 [MEDIUM] CWE-125 CVE-2026-69318: Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose informatio Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69627P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69627 [MEDIUM] CWE-125 CVE-2026-69627: Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authorized attacker to disc Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69527P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69527 [MEDIUM] CWE-125 CVE-2026-69527: Out-of-bounds read in Windows USB Mass Storage Class Driver allows an authorized attacker to disclos Out-of-bounds read in Windows USB Mass Storage Class Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2026-70290P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-70290 [MEDIUM] CWE-908 CVE-2026-70290: Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to dis Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase