CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
13,708 results Clear all
CVE-2026-21243 7.5 HIGH EPSS 0.00
Windows LDAP - DoS
Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
CWE-476 Feb 10, 2026
CVE-2026-21242 7.0 HIGH EPSS 0.00
Windows Subsystem for Linux - Privilege Escalation
Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
CWE-416 Feb 10, 2026
CVE-2026-21241 7.0 HIGH EPSS 0.00
Windows Ancillary Function Driver for WinSock - Privilege Escalation
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CWE-416 Feb 10, 2026
CVE-2026-21240 7.8 HIGH EPSS 0.00
Windows HTTP.sys - Privilege Escalation
Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
CWE-367 Feb 10, 2026
CVE-2026-21239 7.8 HIGH EPSS 0.00
Windows Kernel < - Privilege Escalation
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CWE-122 Feb 10, 2026
CVE-2026-21238 7.8 HIGH EPSS 0.00
Windows Ancillary Function Driver - Privilege Escalation
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CWE-284 Feb 10, 2026
CVE-2026-21237 7.0 HIGH EPSS 0.00
Windows Subsystem for Linux - Privilege Escalation
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
CWE-416 Feb 10, 2026
CVE-2026-21236 7.8 HIGH EPSS 0.00
Windows Ancillary Function Driver - Buffer Overflow
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CWE-122 Feb 10, 2026
CVE-2026-21235 7.3 HIGH EPSS 0.00
Microsoft Graphics Component - Privilege Escalation
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CWE-416 Feb 10, 2026
CVE-2026-21234 7.0 HIGH EPSS 0.00
Windows Connected Devices Platform Service - Privilege Escalation
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
CWE-362 Feb 10, 2026
CVE-2026-21232 7.8 HIGH EPSS 0.00
Windows HTTP.sys - Privilege Escalation
Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
CWE-822 Feb 10, 2026
CVE-2026-21231 7.8 HIGH EPSS 0.00
Windows Kernel - Privilege Escalation
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
CWE-362 Feb 10, 2026
CVE-2026-21229 8.0 HIGH EPSS 0.00
Power BI - Code Injection
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
CWE-20 Feb 10, 2026
CVE-2026-21228 8.1 HIGH EPSS 0.00
Azure Local - RCE
Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network.
CWE-295 Feb 10, 2026
CVE-2026-21222 5.5 MEDIUM EPSS 0.00
Windows Kernel - Info Disclosure
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
CWE-532 Feb 10, 2026
CVE-2026-21218 7.5 HIGH EPSS 0.00
.NET - Info Disclosure
Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.
CWE-166 Feb 10, 2026
CVE-2026-20846 7.5 HIGH EPSS 0.00
Windows GDI+ - DoS
Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.
CWE-126 Feb 10, 2026
CVE-2026-20841 7.8 HIGH 13 PoCs Analysis EPSS 0.00
Windows Notepad App - Command Injection
Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.
CWE-77 Feb 10, 2026
CVE-2026-24302 8.6 HIGH EPSS 0.00
Azure Arc - Privilege Escalation
Azure Arc Elevation of Privilege Vulnerability
CWE-284 Feb 05, 2026
CVE-2026-24300 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Azure Front Door - Privilege Escalation
Azure Front Door Elevation of Privilege Vulnerability
CWE-284 Feb 05, 2026