Microsoft Windows 10 Version 22H2 vulnerabilities
2,407 known vulnerabilities affecting microsoft/windows_10_version_22h2.
Total CVEs
2,407
CISA KEV
79
actively exploited
Public exploits
52
Exploited in wild
97
Severity breakdown
CRITICAL63HIGH1710MEDIUM623LOW11
Vulnerabilities
Page 104 of 121
CVE-2025-48808P4MEDIUMCVSS 5.5≥ 10.0.19045.0, < 10.0.19045.60932025-07-08
CVE-2025-48808 [MEDIUM] CWE-200 CVE-2025-48808: Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized at
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2026-27931P4MEDIUMCVSS 5.5≥ 10.0.19045.0, < 10.0.19045.71842026-04-14
CVE-2026-27931 [MEDIUM] CWE-125 CVE-2026-27931: Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-50431P4MEDIUMCVSS 5.5≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-50431 [MEDIUM] CWE-200 CVE-2026-50431: Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability
Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability
nvd
CVE-2023-28251P4MEDIUMCVSS 5.5≥ 10.0.19045.0, < 10.0.19045.29652023-05-09
CVE-2023-28251 [MEDIUM] CVE-2023-28251: Windows Driver Revocation List Security Feature Bypass Vulnerability
Windows Driver Revocation List Security Feature Bypass Vulnerability
nvd
CVE-2026-32218P4MEDIUMCVSS 5.5≥ 10.0.19045.0, < 10.0.19045.71842026-04-14
CVE-2026-32218 [MEDIUM] CWE-532 CVE-2026-32218: Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2025-59209P4MEDIUMCVSS 5.5≥ 10.0.19045.0, < 10.0.19045.64562025-10-14
CVE-2025-59209 [MEDIUM] CWE-200 CVE-2025-59209: Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32215P4MEDIUMCVSS 5.5≥ 10.0.19045.0, < 10.0.19045.71842026-04-14
CVE-2026-32215 [MEDIUM] CWE-532 CVE-2026-32215: Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32217P4MEDIUMCVSS 5.5≥ 10.0.19045.0, < 10.0.19045.71842026-04-14
CVE-2026-32217 [MEDIUM] CWE-532 CVE-2026-32217: Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2026-27930P4MEDIUMCVSS 5.5≥ 10.0.19045.0, < 10.0.19045.71842026-04-14
CVE-2026-27930 [MEDIUM] CWE-125 CVE-2026-27930: Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-42915P4MEDIUMCVSS 5.5≥ 10.0.19045.0, < 10.0.19045.74172026-06-09
CVE-2026-42915 [MEDIUM] CWE-131 CVE-2026-42915: Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny servi
Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally.
nvd
CVE-2026-50316P4MEDIUMCVSS 5.5≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-50316 [MEDIUM] CWE-532 CVE-2026-50316: Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2024-21320MEDIUMCVSS 6.5PoC≥ 10.0.19045.0, < 10.0.19045.39302024-01-09
CVE-2024-21320 [MEDIUM] CWE-200 Windows Themes Spoofing Vulnerability
Windows Themes Spoofing Vulnerability
Windows Themes Spoofing Vulnerability
cvelistv5
CVE-2026-34346P4MEDIUMCVSS 5.5≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-34346 [MEDIUM] CWE-319 CVE-2026-34346: Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock all
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.
nvd
CVE-2025-21219P4MEDIUMCVSS 4.3≥ 10.0.19045.0, < 10.0.19045.53712025-01-14
CVE-2025-21219 [MEDIUM] CWE-41 CVE-2025-21219: MapUrlToZone Security Feature Bypass Vulnerability
MapUrlToZone Security Feature Bypass Vulnerability
nvd
CVE-2025-21189P4MEDIUMCVSS 4.3≥ 10.0.19045.0, < 10.0.19045.53712025-01-14
CVE-2025-21189 [MEDIUM] CWE-41 CVE-2025-21189: MapUrlToZone Security Feature Bypass Vulnerability
MapUrlToZone Security Feature Bypass Vulnerability
nvd
CVE-2025-55333P4MEDIUMCVSS 4.6≥ 10.0.19045.0, < 10.0.19045.64562025-10-14
CVE-2025-55333 [MEDIUM] CWE-1023 CVE-2025-55333: Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to b
Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2026-50661P4MEDIUMCVSS 4.6≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-50661 [MEDIUM] CWE-693 CVE-2026-50661: Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a securi
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2026-50310P4MEDIUMCVSS 4.7≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-50310 [MEDIUM] CWE-190 CVE-2026-50310: Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to d
Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.
nvd
CVE-2023-36908P4MEDIUMCVSS 6.5≥ 10.0.19045.0, < 10.0.19045.33242023-08-08
CVE-2023-36908 [MEDIUM] CWE-200 CVE-2023-36908: Windows Hyper-V Information Disclosure Vulnerability
Windows Hyper-V Information Disclosure Vulnerability
nvd
CVE-2025-24992P4MEDIUMCVSS 5.5≥ 10.0.19045.0, < 10.0.19045.56082025-03-11
CVE-2025-24992 [MEDIUM] CWE-126 CVE-2025-24992: Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.
nvd