cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 160 of 182
CVE-2026-50431P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50431 [MEDIUM] CWE-200 CVE-2026-50431: Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability
nvd
CVE-2026-32215P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32215 [MEDIUM] CWE-532 CVE-2026-32215: Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32217P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32217 [MEDIUM] CWE-532 CVE-2026-32217: Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2025-60706P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-60706 [MEDIUM] CWE-125 CVE-2025-60706: Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally. Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.
nvd
CVE-2025-59209P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-59209 [MEDIUM] CWE-200 CVE-2025-59209: Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
nvd
CVE-2023-28251P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.29652023-05-09
CVE-2023-28251 [MEDIUM] CVE-2023-28251: Windows Driver Revocation List Security Feature Bypass Vulnerability Windows Driver Revocation List Security Feature Bypass Vulnerability
nvd
CVE-2024-21362P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.40462024-02-13
CVE-2024-21362 [MEDIUM] CWE-367 CVE-2024-21362: Windows Kernel Security Feature Bypass Vulnerability Windows Kernel Security Feature Bypass Vulnerability
nvd
CVE-2026-42915P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42915 [MEDIUM] CWE-131 CVE-2026-42915: Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny servi Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally.
nvd
CVE-2026-61928P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61928 [MEDIUM] CWE-312 CVE-2026-61928: Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.
nvd
CVE-2024-21320MEDIUMCVSS 6.5PoC≥ 10.0.19043.0, < 10.0.19044.39302024-01-09
CVE-2024-21320 [MEDIUM] CWE-200 Windows Themes Spoofing Vulnerability Windows Themes Spoofing Vulnerability Windows Themes Spoofing Vulnerability
cvelistv5
CVE-2025-21219P4MEDIUMCVSS 4.3≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21219 [MEDIUM] CWE-41 CVE-2025-21219: MapUrlToZone Security Feature Bypass Vulnerability MapUrlToZone Security Feature Bypass Vulnerability
nvd
CVE-2025-21189P4MEDIUMCVSS 4.3≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21189 [MEDIUM] CWE-41 CVE-2025-21189: MapUrlToZone Security Feature Bypass Vulnerability MapUrlToZone Security Feature Bypass Vulnerability
nvd
CVE-2026-20834P4MEDIUMCVSS 4.6≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20834 [MEDIUM] CWE-36 CVE-2026-20834: Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.
nvd
CVE-2022-34728P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.20062022-09-13
CVE-2022-34728 [MEDIUM] CVE-2022-34728: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2026-69316P4MEDIUMCVSS 4.7≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69316 [MEDIUM] CWE-126 CVE-2026-69316: Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information loc Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50310P4MEDIUMCVSS 4.7≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50310 [MEDIUM] CWE-190 CVE-2026-50310: Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to d Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.
nvd
CVE-2026-73019P4MEDIUMCVSS 4.3≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-73019 [MEDIUM] CWE-41 CVE-2026-73019: Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to by Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2022-26935P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19043.17062022-05-10
CVE-2022-26935 [MEDIUM] CVE-2022-26935: Windows WLAN AutoConfig Service Information Disclosure Vulnerability Windows WLAN AutoConfig Service Information Disclosure Vulnerability
nvd
CVE-2023-36908P4MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.33242023-08-08
CVE-2023-36908 [MEDIUM] CWE-200 CVE-2023-36908: Windows Hyper-V Information Disclosure Vulnerability Windows Hyper-V Information Disclosure Vulnerability
nvd
CVE-2022-37965P4MEDIUMCVSS 5.9≥ 10.0.19043.0, < 10.0.19044.21302022-10-11
CVE-2022-37965 [MEDIUM] CVE-2022-37965: Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase