Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13
Vulnerabilities
Page 152 of 182
CVE-2026-68881P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-68881 [MEDIUM] CWE-125 CVE-2026-68881: Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information l
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69367P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69367 [MEDIUM] CWE-125 CVE-2026-69367: Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information l
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69308P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69308 [MEDIUM] CWE-125 CVE-2026-69308: Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information l
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69770P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69770 [MEDIUM] CWE-908 CVE-2026-69770: Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose inf
Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally.
nvd
CVE-2026-72945P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-72945 [MEDIUM] CWE-908 CVE-2026-72945: Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose in
Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69616P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69616 [MEDIUM] CWE-125 CVE-2026-69616: Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to disclose info
Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to disclose information locally.
nvd
CVE-2026-71341P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-71341 [MEDIUM] CWE-125 CVE-2026-71341: Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose
Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69345P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69345 [MEDIUM] CWE-125 CVE-2026-69345: Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information l
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69344P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69344 [MEDIUM] CWE-125 CVE-2026-69344: Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose inf
Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
nvd
CVE-2026-77492P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-77492 [MEDIUM] CWE-125 CVE-2026-77492: Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information loca
Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69457P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69457 [MEDIUM] CWE-125 CVE-2026-69457: Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclose information local
Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2026-68895P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-68895 [MEDIUM] CWE-197 CVE-2026-68895: Numeric truncation error in Internet Storage Name Service allows an authorized attacker to disclose
Numeric truncation error in Internet Storage Name Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69568P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69568 [MEDIUM] CWE-125 CVE-2026-69568: Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to disclose in
Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69376P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69376 [MEDIUM] CWE-125 CVE-2026-69376: Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information l
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
nvd
CVE-2026-72937P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-72937 [MEDIUM] CWE-125 CVE-2026-72937: Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information loca
Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69618P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69618 [MEDIUM] CWE-125 CVE-2026-69618: Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information local
Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information locally.
nvd
CVE-2026-59136P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-59136 [MEDIUM] CWE-908 CVE-2026-59136: Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose
Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
nvd
CVE-2026-62740P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62740 [MEDIUM] CWE-908 CVE-2026-62740: Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose
Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.
nvd
CVE-2026-62730P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62730 [MEDIUM] CWE-126 CVE-2026-62730: Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose infor
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-62709P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62709 [MEDIUM] CWE-908 CVE-2026-62709: Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
nvd