CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
179 results Clear all
CVE-2021-26410 EPSS 0.00
ASP - Info Disclosure
Improper syscall input validation in ASP (AMD Secure Processor) may force the kernel into reading syscall parameter values from its own memory space allowing an attacker to infer the contents of the kernel memory leading to potential information disclosure.
CWE-822 Feb 10, 2026
CVE-2026-21250 7.8 HIGH EPSS 0.00
Windows HTTP.sys - Privilege Escalation
Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
CWE-822 Feb 10, 2026
CVE-2026-21232 7.8 HIGH EPSS 0.00
Windows HTTP.sys - Privilege Escalation
Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
CWE-822 Feb 10, 2026
CVE-2025-59959 5.5 MEDIUM EPSS 0.00
Juniper Junos < 22.4 - Denial of Service
An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial-of-Service (DoS). When the command 'show route < ( receive-protocol | advertising-protocol ) bgp > detail' is executed, and at least one of the routes in the intended output has specific attributes, this will cause an rpd crash and restart. 'show route ... extensive' is not affected. This issue affects: Junos OS:  * all versions before 22.4R3-S8, * 23.2 versions before 23.2R2-S5, * 23.4 versions before 23.4R2-S5, * 24.2 versions before 24.2R2-S2, * 24.4 versions before 24.4R2; Junos OS Evolved: * all versions before 22.4R3-S8-EVO,  * 23.2 versions before 23.2R2-S5-EVO, * 23.4 versions before 23.4R2-S6-EVO, * 24.2 versions before 24.2R2-S2-EVO, * 24.4 versions before 24.4R2-EVO.
CWE-822 Jan 15, 2026
CVE-2026-20956 7.8 HIGH EPSS 0.00
Microsoft Office Excel - Code Injection
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CWE-822 Jan 13, 2026
CVE-2026-20955 7.8 HIGH EPSS 0.00
Microsoft Office Excel - Code Injection
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CWE-822 Jan 13, 2026
CVE-2026-20948 7.8 HIGH EPSS 0.00
Microsoft Office Word - RCE
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CWE-822 Jan 13, 2026
CVE-2026-20940 7.8 HIGH EPSS 0.00
Windows Cloud Files Mini Filter Driver - Buffer Overflow
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CWE-822 Jan 13, 2026
CVE-2026-20938 7.8 HIGH EPSS 0.00
Windows VBS Enclave - Privilege Escalation
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
CWE-822 Jan 13, 2026
CVE-2026-20935 6.2 MEDIUM EPSS 0.00
Windows VBS Enclave - Info Disclosure
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally.
CWE-822 Jan 13, 2026
CVE-2026-20857 7.8 HIGH EPSS 0.00
Windows Cloud Files Mini Filter Driver - Privilege Escalation
Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CWE-822 Jan 13, 2026
CVE-2026-20819 5.5 MEDIUM EPSS 0.00
Windows VBS Enclave - Info Disclosure
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.
CWE-822 Jan 13, 2026
CVE-2026-20811 7.8 HIGH EPSS 0.00
Windows Win32K - ICOMP - Privilege Escalation
Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
CWE-843 Jan 13, 2026
CVE-2025-47380 7.8 HIGH EPSS 0.00
Unknown Product <Version> - Memory Corruption
Memory corruption while preprocessing IOCTLs in sensors.
CWE-822 Jan 07, 2026
CVE-2025-47343 7.8 HIGH EPSS 0.00
Product <Version - Memory Corruption
Memory corruption while processing a video session to set video parameters.
CWE-822 Jan 07, 2026
CVE-2025-52516 6.2 MEDIUM EPSS 0.00
Samsung Exynos 1330 Firmware - Denial of Service
An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. An invalid kernel address dereference in the issimian device driver leads to a denial of service.
CWE-822 Jan 05, 2026
CVE-2025-47387 7.8 HIGH EPSS 0.00
Driver <version> - Memory Corruption
Memory Corruption when processing IOCTLs for JPEG data without verification.
CWE-822 Dec 18, 2025
CVE-2025-47325 6.5 MEDIUM EPSS 0.00
Qualcomm Csr8811 Firmware - Information Disclosure
Information disclosure while processing system calls with invalid parameters.
CWE-822 Dec 18, 2025
CVE-2025-62561 7.8 HIGH EPSS 0.00
Microsoft Office Excel - RCE
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CWE-822 Dec 09, 2025
CVE-2025-62560 7.8 HIGH EPSS 0.00
Microsoft 365 Apps < 16.0.10417.20075 - Buffer Over-read
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CWE-822 Dec 09, 2025