cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 155 of 182
CVE-2025-60708P4MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-60708 [MEDIUM] CWE-822 CVE-2025-60708: Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service lo Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.
nvd
CVE-2022-41086P4MEDIUMCVSS 6.4≥ 10.0.19043.0, < 10.0.19044.22512022-11-09
CVE-2022-41086 [MEDIUM] CWE-362 CVE-2022-41086: Windows Group Policy Elevation of Privilege Vulnerability Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2022-24503P4MEDIUMCVSS 5.3≥ 10.0.19043.0, < 10.0.19044.15862022-03-09
CVE-2022-24503 [MEDIUM] CVE-2022-24503: Remote Desktop Protocol Client Information Disclosure Vulnerability Remote Desktop Protocol Client Information Disclosure Vulnerability
nvd
CVE-2023-21693P4MEDIUMCVSS 5.7≥ 10.0.19043.0, < 10.0.19044.26042023-02-14
CVE-2023-21693 [MEDIUM] CWE-125 CVE-2023-21693: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2024-20692P4MEDIUMCVSS 5.7≥ 10.0.19043.0, < 10.0.19044.39302024-01-09
CVE-2024-20692 [MEDIUM] CWE-326 CVE-2024-20692: Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
nvd
CVE-2024-43547P4MEDIUMCVSS 5.9≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43547 [MEDIUM] CWE-325 CVE-2024-43547: Windows Kerberos Information Disclosure Vulnerability Windows Kerberos Information Disclosure Vulnerability
nvd
CVE-2025-21269P4MEDIUMCVSS 4.3≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21269 [MEDIUM] CWE-41 CVE-2025-21269: Windows HTML Platforms Security Feature Bypass Vulnerability Windows HTML Platforms Security Feature Bypass Vulnerability
nvd
CVE-2025-55338P4MEDIUMCVSS 4.6≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-55338 [MEDIUM] CWE-1310 CVE-2025-55338: Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a s Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2023-35336P4MEDIUMCVSS 5.4≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-35336 [MEDIUM] CWE-20 CVE-2023-35336: Windows MSHTML Platform Security Feature Bypass Vulnerability Windows MSHTML Platform Security Feature Bypass Vulnerability
nvd
CVE-2025-29837P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29837 [MEDIUM] CWE-59 CVE-2025-29837: Improper link resolution before file access ('link following') in Windows Installer allows an author Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally.
nvd
CVE-2023-36889P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.33242023-08-08
CVE-2023-36889 [MEDIUM] CWE-284 CVE-2023-36889: Windows Group Policy Security Feature Bypass Vulnerability Windows Group Policy Security Feature Bypass Vulnerability
nvd
CVE-2025-59211P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-59211 [MEDIUM] CWE-200 CVE-2025-59211: Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
nvd
CVE-2025-55336P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-55336 [MEDIUM] CWE-200 CVE-2025-55336: Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2026-21222P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.69372026-02-10
CVE-2026-21222 [MEDIUM] CWE-532 CVE-2026-21222: Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2025-59509P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-59509 [MEDIUM] CWE-201 CVE-2025-59509: Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose information locally.
nvd
CVE-2026-57083P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-57083 [MEDIUM] CWE-908 CVE-2026-57083: Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-27930P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-27930 [MEDIUM] CWE-125 CVE-2026-27930: Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-27931P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-27931 [MEDIUM] CWE-125 CVE-2026-27931: Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
nvd
CVE-2025-62209P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.64562025-11-11
CVE-2025-62209 [MEDIUM] CWE-532 CVE-2025-62209: Insertion of sensitive information into log file in Windows License Manager allows an authorized att Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
nvd
CVE-2025-62208P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.64562025-11-11
CVE-2025-62208 [MEDIUM] CWE-532 CVE-2025-62208: Insertion of sensitive information into log file in Windows License Manager allows an authorized att Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase