CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,847 CVEs tracked 53,242 with exploits 4,725 exploited in wild 1,540 CISA KEV 3,918 Nuclei templates 37,802 vendors 42,493 researchers
2,165 results Clear all
CVE-2025-15349 7.5 HIGH EPSS 0.00
Anritsu ShockLine - RCE
Anritsu ShockLine SCPI Race Condition Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Anritsu ShockLine. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SCPI component. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27315.
CWE-362 Jan 23, 2026
CVE-2025-66803 4.8 MEDIUM EPSS 0.00
Hotwired Turbo <8.0.x - Info Disclosure
Race condition in the turbo-frame element handler in Hotwired Turbo before 8.0.x causes logout operations to fail when delayed frame responses reapply session cookies after logout. This can be exploited by remote attackers via selective network delays (e.g. delaying requests based on sequence or timing) or by physically proximate attackers when the race condition occurs naturally on shared computers.
CWE-362 Jan 20, 2026
CVE-2026-23735 EPSS 0.00
GraphQL Modules <3.1.1 - Info Disclosure
GraphQL Modules is a toolset of libraries and guidelines dedicated to create reusable, maintainable, testable and extendable modules out of your GraphQL server. From 2.2.1 to before 2.4.1 and 3.1.1, when 2 or more parallel requests are made which trigger the same service, the context of the requests is mixed up in the service when the context is injected via @ExecutionContext(). ExecutionContext is often used to pass authentication tokens from incoming requests to services loading data from backend APIs. This vulnerability is fixed in 2.4.1 and 3.1.1.
CWE-362 Jan 16, 2026
CVE-2026-22856 8.1 HIGH EPSS 0.00
Freerdp < 3.20.1 - Race Condition
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the serial channel IRP thread tracking allows a heap use‑after‑free when one thread removes an entry from serial->IrpThreads while another reads it. This vulnerability is fixed in 3.20.1.
CWE-362 Jan 14, 2026
CVE-2026-22851 5.9 MEDIUM EPSS 0.00
Freerdp < 3.20.1 - Race Condition
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race condition between the RDPGFX dynamic virtual channel thread and the SDL render thread leads to a heap use-after-free. Specifically, an escaped pointer to sdl->primary (SDL_Surface) is accessed after it has been freed during RDPGFX ResetGraphics handling. This vulnerability is fixed in 3.20.1.
CWE-362 Jan 14, 2026
CVE-2025-68969 6.8 MEDIUM EPSS 0.00
Thermal Management Module - Info Disclosure
Multi-thread race condition vulnerability in the thermal management module. Impact: Successful exploitation of this vulnerability may affect availability.
CWE-362 Jan 14, 2026
CVE-2025-68962 5.1 MEDIUM EPSS 0.00
Camera Framework Module - Memory Corruption
Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.
CWE-362 Jan 14, 2026
CVE-2025-68961 5.1 MEDIUM EPSS 0.00
Camera Framework Module - DoS
Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.
CWE-362 Jan 14, 2026
CVE-2025-68960 8.4 HIGH EPSS 0.00
Video Framework Module - Memory Corruption
Multi-thread race condition vulnerability in the video framework module. Impact: Successful exploitation of this vulnerability may affect availability.
CWE-362 Jan 14, 2026
CVE-2025-68958 8.0 HIGH EPSS 0.00
Card Framework Module - Memory Corruption
Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.
CWE-362 Jan 14, 2026
CVE-2025-68957 8.4 HIGH EPSS 0.00
Card Framework Module - Memory Corruption
Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.
CWE-362 Jan 14, 2026
CVE-2025-68956 8.0 HIGH EPSS 0.00
Card Framework Module - Memory Corruption
Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.
CWE-362 Jan 14, 2026
CVE-2025-68955 8.0 HIGH EPSS 0.00
Card Framework Module - DoS
Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.
CWE-362 Jan 14, 2026
CVE-2026-21221 7.0 HIGH EPSS 0.00
Capability Access Management Service - Privilege Escalation
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
CWE-362 Jan 13, 2026
CVE-2026-20934 7.5 HIGH EPSS 0.00
Windows SMB Server - Privilege Escalation
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
CWE-362 Jan 13, 2026
CVE-2026-20927 5.3 MEDIUM EPSS 0.00
Windows SMB Server - DoS
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service over a network.
CWE-362 Jan 13, 2026
CVE-2026-20926 7.5 HIGH EPSS 0.00
Windows SMB Server - Privilege Escalation
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
CWE-362 Jan 13, 2026
CVE-2026-20924 7.8 HIGH EPSS 0.00
Windows Management Services - Privilege Escalation
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
CWE-362 Jan 13, 2026
CVE-2026-20921 7.5 HIGH EPSS 0.00
Windows SMB Server - Privilege Escalation
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
CWE-362 Jan 13, 2026
CVE-2026-20919 7.5 HIGH EPSS 0.00
Windows SMB Server - Privilege Escalation
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
CWE-362 Jan 13, 2026