Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13
Vulnerabilities
Page 160 of 182
CVE-2026-50431P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50431 [MEDIUM] CWE-200 CVE-2026-50431: Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability
Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability
nvd
CVE-2026-32215P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32215 [MEDIUM] CWE-532 CVE-2026-32215: Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32217P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32217 [MEDIUM] CWE-532 CVE-2026-32217: Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2025-60706P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-60706 [MEDIUM] CWE-125 CVE-2025-60706: Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.
nvd
CVE-2025-59209P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-59209 [MEDIUM] CWE-200 CVE-2025-59209: Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
nvd
CVE-2023-28251P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.29652023-05-09
CVE-2023-28251 [MEDIUM] CVE-2023-28251: Windows Driver Revocation List Security Feature Bypass Vulnerability
Windows Driver Revocation List Security Feature Bypass Vulnerability
nvd
CVE-2024-21362P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.40462024-02-13
CVE-2024-21362 [MEDIUM] CWE-367 CVE-2024-21362: Windows Kernel Security Feature Bypass Vulnerability
Windows Kernel Security Feature Bypass Vulnerability
nvd
CVE-2026-42915P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42915 [MEDIUM] CWE-131 CVE-2026-42915: Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny servi
Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally.
nvd
CVE-2026-61928P4MEDIUMCVSS 5.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61928 [MEDIUM] CWE-312 CVE-2026-61928: Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.
nvd
CVE-2024-21320MEDIUMCVSS 6.5PoC≥ 10.0.19043.0, < 10.0.19044.39302024-01-09
CVE-2024-21320 [MEDIUM] CWE-200 Windows Themes Spoofing Vulnerability
Windows Themes Spoofing Vulnerability
Windows Themes Spoofing Vulnerability
cvelistv5
CVE-2025-21219P4MEDIUMCVSS 4.3≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21219 [MEDIUM] CWE-41 CVE-2025-21219: MapUrlToZone Security Feature Bypass Vulnerability
MapUrlToZone Security Feature Bypass Vulnerability
nvd
CVE-2025-21189P4MEDIUMCVSS 4.3≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21189 [MEDIUM] CWE-41 CVE-2025-21189: MapUrlToZone Security Feature Bypass Vulnerability
MapUrlToZone Security Feature Bypass Vulnerability
nvd
CVE-2026-20834P4MEDIUMCVSS 4.6≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20834 [MEDIUM] CWE-36 CVE-2026-20834: Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a
Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.
nvd
CVE-2022-34728P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.20062022-09-13
CVE-2022-34728 [MEDIUM] CVE-2022-34728: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2026-69316P4MEDIUMCVSS 4.7≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69316 [MEDIUM] CWE-126 CVE-2026-69316: Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information loc
Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50310P4MEDIUMCVSS 4.7≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50310 [MEDIUM] CWE-190 CVE-2026-50310: Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to d
Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.
nvd
CVE-2026-73019P4MEDIUMCVSS 4.3≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-73019 [MEDIUM] CWE-41 CVE-2026-73019: Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to by
Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2022-26935P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19043.17062022-05-10
CVE-2022-26935 [MEDIUM] CVE-2022-26935: Windows WLAN AutoConfig Service Information Disclosure Vulnerability
Windows WLAN AutoConfig Service Information Disclosure Vulnerability
nvd
CVE-2023-36908P4MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.33242023-08-08
CVE-2023-36908 [MEDIUM] CWE-200 CVE-2023-36908: Windows Hyper-V Information Disclosure Vulnerability
Windows Hyper-V Information Disclosure Vulnerability
nvd
CVE-2022-37965P4MEDIUMCVSS 5.9≥ 10.0.19043.0, < 10.0.19044.21302022-10-11
CVE-2022-37965 [MEDIUM] CVE-2022-37965: Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
nvd