CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
13,708 results Clear all
CVE-2026-21535 8.2 HIGH EPSS 0.00
Microsoft Teams - Info Disclosure
Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.
CWE-284 Feb 19, 2026
CVE-2026-26030 9.9 CRITICAL 2 PoCs Analysis EPSS 0.00
Microsoft Semantic Kernel <1.39.4 - RCE
Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. The problem has been fixed in version `python-1.39.4`. Users should upgrade this version or higher. As a workaround, avoid using `InMemoryVectorStore` for production scenarios.
CWE-94 Feb 19, 2026
CVE-2026-26119 8.8 HIGH EPSS 0.00
Windows Admin Center - Privilege Escalation
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
CWE-287 Feb 17, 2026
CVE-2026-0102 3.1 LOW EPSS 0.00
Web Browser - Info Disclosure
Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This could result in disclosure of stored autofill data such as addresses, email, or phone number metadata.
CWE-359 Feb 17, 2026
CVE-2026-23655 6.5 MEDIUM EPSS 0.00
Azure Compute Gallery - Info Disclosure
Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
CWE-312 Feb 10, 2026
CVE-2026-21537 8.8 HIGH EPSS 0.00
Microsoft Defender For Endpoint - Code Injection
Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network.
CWE-94 Feb 10, 2026
CVE-2026-21533 7.8 HIGH KEV 6 PoCs Analysis EPSS 0.03
Microsoft Windows 10 1607 - Improper Privilege Management
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
CWE-269 Feb 10, 2026
CVE-2026-21531 9.8 CRITICAL 2 PoCs Analysis EPSS 0.00
Microsoft Azure Conversation Authorin... - Insecure Deserialization
Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.
CWE-502 Feb 10, 2026
CVE-2026-21529 5.7 MEDIUM EPSS 0.00
Microsoft Azure Hdinsight < 5.1 - XSS
Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network.
CWE-79 Feb 10, 2026
CVE-2026-21528 6.5 MEDIUM EPSS 0.00
Microsoft Azure Iot Explorer < 0.15.13 - Exposure to Wrong Actor
Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
CWE-1327 Feb 10, 2026
CVE-2026-21527 6.5 MEDIUM EPSS 0.00
Microsoft Exchange Server - Info Disclosure
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CWE-451 Feb 10, 2026
CVE-2026-21525 6.2 MEDIUM KEV EPSS 0.03
Microsoft Windows 10 1607 < 10.0.14393.8868 - NULL Pointer Dereference
Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.
CWE-476 Feb 10, 2026
CVE-2026-21523 8.0 HIGH EPSS 0.00
Microsoft Visual Studio Code < 1.109.2 - TOCTOU Race Condition
Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network.
CWE-367 Feb 10, 2026
CVE-2026-21522 6.7 MEDIUM EPSS 0.00
Microsoft Confcom < 1.2.8 - Command Injection
Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
CWE-77 Feb 10, 2026
CVE-2026-21519 7.8 HIGH KEV EPSS 0.03
Microsoft Windows 10 1607 < 10.0.14393.8868 - Type Confusion
Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CWE-843 Feb 10, 2026
CVE-2026-21518 8.8 HIGH EPSS 0.00
Microsoft Visual Studio Code < 1.109.2 - Command Injection
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CWE-77 Feb 10, 2026
CVE-2026-21517 4.7 MEDIUM EPSS 0.00
Windows App for Mac - Privilege Escalation
Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally.
CWE-59 Feb 10, 2026
CVE-2026-21516 8.8 HIGH EPSS 0.00
Microsoft Github Copilot < 1.5.63-243 - Command Injection
Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network.
CWE-77 Feb 10, 2026
CVE-2026-21514 7.8 HIGH KEV EPSS 0.05
Microsoft Office Word - Info Disclosure
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
CWE-807 Feb 10, 2026
CVE-2026-21513 8.8 HIGH KEV EPSS 0.05
MSHTML Framework - Auth Bypass
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
CWE-693 Feb 10, 2026