cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 158 of 182
CVE-2026-69353P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69353 [MEDIUM] CWE-125 CVE-2026-69353: Out-of-bounds read in Windows Text Shaping allows an authorized attacker to disclose information loc Out-of-bounds read in Windows Text Shaping allows an authorized attacker to disclose information locally.
nvd
CVE-2026-69390P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69390 [MEDIUM] CWE-125 CVE-2026-69390: Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information lo Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.
nvd
CVE-2026-59137P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-59137 [MEDIUM] CWE-908 CVE-2026-59137: Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disc Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-62887P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62887 [MEDIUM] CWE-125 CVE-2026-62887: Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
nvd
CVE-2026-59128P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-59128 [MEDIUM] CWE-125 CVE-2026-59128: Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.
nvd
CVE-2026-62743P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62743 [MEDIUM] CWE-125 CVE-2026-62743: Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
nvd
CVE-2026-62796P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62796 [MEDIUM] CWE-125 CVE-2026-62796: Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
nvd
CVE-2026-65662P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-65662 [MEDIUM] CWE-125 CVE-2026-65662: Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally. Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.
nvd
CVE-2026-62786P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62786 [MEDIUM] CWE-125 CVE-2026-62786: Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
nvd
CVE-2026-62738P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62738 [MEDIUM] CWE-125 CVE-2026-62738: Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose i Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.
nvd
CVE-2026-65784P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-65784 [MEDIUM] CWE-125 CVE-2026-65784: Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
nvd
CVE-2026-62703P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62703 [MEDIUM] CWE-125 CVE-2026-62703: Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50437P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50437 [MEDIUM] CWE-125 CVE-2026-50437: Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42968P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42968 [MEDIUM] CWE-125 CVE-2026-42968: Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose informatio Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-34346P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-34346 [MEDIUM] CWE-319 CVE-2026-34346: Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock all Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.
nvd
CVE-2025-21247P4MEDIUMCVSS 4.3≥ 10.0.19044.0, < 10.0.19044.56082025-03-11
CVE-2025-21247 [MEDIUM] CWE-41 CVE-2025-21247: Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to b Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-21249P4LOWCVSS 3.3≥ 10.0.19044.0, < 10.0.19044.69372026-02-10
CVE-2026-21249 [LOW] CWE-73 CVE-2026-21249: External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spo External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
nvd
CVE-2023-38254P4MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.33242023-08-08
CVE-2023-38254 [MEDIUM] CWE-20 CVE-2023-38254: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21272P4MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21272 [MEDIUM] CWE-908 CVE-2025-21272: Windows COM Server Information Disclosure Vulnerability Windows COM Server Information Disclosure Vulnerability
nvd
CVE-2025-21288P4MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21288 [MEDIUM] CWE-908 CVE-2025-21288: Windows COM Server Information Disclosure Vulnerability Windows COM Server Information Disclosure Vulnerability
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase