CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-41091HIGH | Microsoft Defender Elevation of Privilege VulnerabilityImproper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. CWE-59May 20, 2026 | CVSS7.8v3.1 | EPSS9.64% | PoCs5 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-45498MEDIUM | Microsoft Defender Denial of Service VulnerabilityMicrosoft Defender Denial of Service Vulnerability CWE-400May 20, 2026 | CVSS4.0v3.1 | EPSS63.1% | PoCs3 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-33825HIGH | Microsoft Defender Elevation of Privilege VulnerabilityInsufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally. CWE-1220Apr 14, 2026 | CVSS7.8v3.1 | EPSS6.75% | PoCs5 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2022-44698MEDIUM | Windows SmartScreen Security Feature Bypass VulnerabilityWindows SmartScreen Security Feature Bypass Vulnerability. | CVSS5.4v3.1 | EPSS76.3% | PoCs0 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2021-1647HIGH | Microsoft Defender Remote Code Execution VulnerabilityMicrosoft Defender Remote Code Execution Vulnerability | CVSS7.8v3.1 | EPSS39.4% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |