Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13
Vulnerabilities
Page 158 of 182
CVE-2026-69353P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69353 [MEDIUM] CWE-125 CVE-2026-69353: Out-of-bounds read in Windows Text Shaping allows an authorized attacker to disclose information loc
Out-of-bounds read in Windows Text Shaping allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69390P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69390 [MEDIUM] CWE-125 CVE-2026-69390: Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information lo
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.
nvd
CVE-2026-59137P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-59137 [MEDIUM] CWE-908 CVE-2026-59137: Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disc
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-62887P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62887 [MEDIUM] CWE-125 CVE-2026-62887: Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
nvd
CVE-2026-59128P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-59128 [MEDIUM] CWE-125 CVE-2026-59128: Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose
Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.
nvd
CVE-2026-62743P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62743 [MEDIUM] CWE-125 CVE-2026-62743: Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
nvd
CVE-2026-62796P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62796 [MEDIUM] CWE-125 CVE-2026-62796: Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
nvd
CVE-2026-65662P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-65662 [MEDIUM] CWE-125 CVE-2026-65662: Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.
nvd
CVE-2026-62786P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62786 [MEDIUM] CWE-125 CVE-2026-62786: Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
nvd
CVE-2026-62738P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62738 [MEDIUM] CWE-125 CVE-2026-62738: Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose i
Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.
nvd
CVE-2026-65784P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-65784 [MEDIUM] CWE-125 CVE-2026-65784: Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
nvd
CVE-2026-62703P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62703 [MEDIUM] CWE-125 CVE-2026-62703: Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50437P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50437 [MEDIUM] CWE-125 CVE-2026-50437: Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42968P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42968 [MEDIUM] CWE-125 CVE-2026-42968: Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose informatio
Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-34346P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-34346 [MEDIUM] CWE-319 CVE-2026-34346: Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock all
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.
nvd
CVE-2025-21247P4MEDIUMCVSS 4.3≥ 10.0.19044.0, < 10.0.19044.56082025-03-11
CVE-2025-21247 [MEDIUM] CWE-41 CVE-2025-21247: Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to b
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-21249P4LOWCVSS 3.3≥ 10.0.19044.0, < 10.0.19044.69372026-02-10
CVE-2026-21249 [LOW] CWE-73 CVE-2026-21249: External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spo
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
nvd
CVE-2023-38254P4MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.33242023-08-08
CVE-2023-38254 [MEDIUM] CWE-20 CVE-2023-38254: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21272P4MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21272 [MEDIUM] CWE-908 CVE-2025-21272: Windows COM Server Information Disclosure Vulnerability
Windows COM Server Information Disclosure Vulnerability
nvd
CVE-2025-21288P4MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21288 [MEDIUM] CWE-908 CVE-2025-21288: Windows COM Server Information Disclosure Vulnerability
Windows COM Server Information Disclosure Vulnerability
nvd