Vulnerabilities
381,276
with PoCs
37,250
CISA KEV
1,665
Ransomware
606
with Nuclei
4,342

Showing 25 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
Vulnerability search results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Windows Management Instrumentation Information Disclosure Vulnerability

Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.

CWE-125Aug 11, 2026
CVSS5.5v3.1EPSS0.397%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability

Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.

CWE-122CWE-190Aug 11, 2026
CVSS8.1v3.1EPSS0.454%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.

CWE-362CWE-416Aug 11, 2026
CVSS8.1v3.1EPSS0.36%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows iSCSI Target Service Denial of Service Vulnerability

Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.

CWE-122Aug 11, 2026
CVSS5.9v3.1EPSS0.645%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows DNS Elevation of Privilege Vulnerability

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

CWE-197Aug 11, 2026
CVSS6.7v3.1EPSS0.256%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows DNS Elevation of Privilege Vulnerability

Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.

CWE-122CWE-190Aug 11, 2026
CVSS6.7v3.1EPSS0.256%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows DNS Elevation of Privilege Vulnerability

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

CWE-122CWE-197Aug 11, 2026
CVSS6.7v3.1EPSS0.256%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows SMB Client Information Disclosure Vulnerability

Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

CWE-126Aug 11, 2026
CVSS6.5v3.1EPSS0.666%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows DNS Elevation of Privilege Vulnerability

No cwe for this issue in Windows DNS allows an authorized attacker to elevate privileges locally.

Aug 11, 2026
CVSS6.7v3.1EPSS0.256%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows iSCSI Target Service Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.

CWE-122Aug 11, 2026
CVSS9.8v3.1EPSS0.601%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows Message Queuing Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

CWE-122Aug 11, 2026
CVSS7.8v3.1EPSS0.246%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Active Directory Security Feature Bypass Vulnerability

Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.

CWE-326Aug 11, 2026
CVSS5.3v3.1EPSS0.294%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows Win32k Elevation of Privilege Vulnerability

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CWE-416Aug 11, 2026
CVSS7.8v3.1EPSS2.31%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows Installer Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CWE-122Aug 11, 2026
CVSS7.8v3.1EPSS0.264%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows Kernel Elevation of Privilege Vulnerability

Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.

CWE-284Aug 11, 2026
CVSS7.8v3.1EPSS0.248%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows iSCSI Target Service Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.

CWE-122Aug 11, 2026
CVSS8.1v3.1EPSS0.557%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows iSCSI Target Service Denial of Service Vulnerability

Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.

CWE-476Aug 11, 2026
CVSS7.5v3.1EPSS0.872%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows DWM Core Library Elevation of Privilege Vulnerability

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CWE-416Aug 11, 2026
CVSS7.8v3.1EPSS1.64%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows NTFS Information Disclosure Vulnerability

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

CWE-125Aug 11, 2026
CVSS5.5v3.1EPSS0.306%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows Win32k Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

CWE-122Aug 11, 2026
CVSS7.8v3.1EPSS0.246%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows DNS Elevation of Privilege Vulnerability

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

CWE-122CWE-197Aug 11, 2026
CVSS6.7v3.1EPSS0.256%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows DNS Elevation of Privilege Vulnerability

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

CWE-122CWE-197Aug 11, 2026
CVSS6.7v3.1EPSS0.332%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows NTFS Elevation of Privilege Vulnerability

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

CWE-125Aug 11, 2026
CVSS7.8v3.1EPSS0.246%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows User Profile Service Elevation of Privilege Vulnerability

Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.

CWE-59Aug 11, 2026
CVSS7.8v3.1EPSS2.39%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows GDI+ Remote Code Execution Vulnerability

Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.

CWE-122CWE-190Aug 11, 2026
CVSS8.8v3.1EPSS0.633%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX