Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13
Vulnerabilities
Page 157 of 182
CVE-2026-42971P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42971 [MEDIUM] CWE-200 CVE-2026-42971: Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an a
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42970P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42970 [MEDIUM] CWE-200 CVE-2026-42970: Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an a
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42906P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42906 [MEDIUM] CWE-200 CVE-2026-42906: Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized att
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32079P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32079 [MEDIUM] CWE-200 CVE-2026-32079: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32084P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32084 [MEDIUM] CWE-200 CVE-2026-32084: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32085P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32085 [MEDIUM] CWE-200 CVE-2026-32085: Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows a
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32081P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32081 [MEDIUM] CWE-200 CVE-2026-32081: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2025-59513P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-59513 [MEDIUM] CWE-125 CVE-2025-59513: Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to discl
Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2025-49684P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-49684 [MEDIUM] CWE-126 CVE-2025-49684: Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locall
Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2025-21340P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21340 [MEDIUM] CWE-284 CVE-2025-21340: Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability
Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability
nvd
CVE-2026-24282P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-24282 [MEDIUM] CWE-125 CVE-2026-24282: Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose informa
Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-78454P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-78454 [MEDIUM] CWE-125 CVE-2026-78454: Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information lo
Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69609P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69609 [MEDIUM] CWE-125 CVE-2026-69609: Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69504P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69504 [MEDIUM] CWE-125 CVE-2026-69504: Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69808P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69808 [MEDIUM] CWE-125 CVE-2026-69808: Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69343P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69343 [MEDIUM] CWE-125 CVE-2026-69343: Out-of-bounds read in Windows Overlay Filter allows an authorized attacker to disclose information l
Out-of-bounds read in Windows Overlay Filter allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69286P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69286 [MEDIUM] CWE-20 CVE-2026-69286: Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69303P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69303 [MEDIUM] CWE-125 CVE-2026-69303: Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose informa
Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69741P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69741 [MEDIUM] CWE-125 CVE-2026-69741: Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information lo
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.
nvd
CVE-2026-70145P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-70145 [MEDIUM] CWE-125 CVE-2026-70145: Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose i
Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
nvd