CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-50508MEDIUM | Windows NTLM Spoofing VulnerabilityExposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. CWE-200Jun 9, 2026 | CVSS6.5v3.1 | EPSS8.68% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43893HIGH | Windows Encrypting File System (EFS) Elevation of Privilege VulnerabilityWindows Encrypting File System (EFS) Elevation of Privilege Vulnerability | CVSS7.5v3.1 | EPSS6.62% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43883HIGH | Windows Installer Elevation of Privilege VulnerabilityWindows Installer Elevation of Privilege Vulnerability CWE-269Dec 15, 2021 | CVSS7.8v3.1 | EPSS12% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43248HIGH | Windows Digital Media Receiver Elevation of Privilege VulnerabilityWindows Digital Media Receiver Elevation of Privilege Vulnerability CWE-269Dec 15, 2021 | CVSS7.8v3.1 | EPSS0.53% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43247HIGH | Windows TCP/IP Driver Elevation of Privilege VulnerabilityWindows TCP/IP Driver Elevation of Privilege Vulnerability | CVSS7.8v3.1 | EPSS0.901% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43246MEDIUM | Windows Hyper-V Denial of Service VulnerabilityWindows Hyper-V Denial of Service Vulnerability CWE-400Dec 15, 2021 | CVSS5.6v3.1 | EPSS0.75% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43244MEDIUM | Windows Kernel Information Disclosure VulnerabilityWindows Kernel Information Disclosure Vulnerability Dec 15, 2021 | CVSS6.5v3.1 | EPSS0.817% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43240HIGH | NTFS Set Short Name Elevation of Privilege VulnerabilityNTFS Set Short Name Elevation of Privilege Vulnerability CWE-269Dec 15, 2021 | CVSS7.8v3.1 | EPSS0.557% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43239HIGH | Windows Recovery Environment Agent Elevation of Privilege VulnerabilityWindows Recovery Environment Agent Elevation of Privilege Vulnerability CWE-269Dec 15, 2021 | CVSS7.1v3.1 | EPSS0.544% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43238HIGH | Windows Remote Access Elevation of Privilege VulnerabilityWindows Remote Access Elevation of Privilege Vulnerability | CVSS7.8v3.1 | EPSS0.892% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43237HIGH | Windows Setup Elevation of Privilege VulnerabilityWindows Setup Elevation of Privilege Vulnerability | CVSS7.8v3.1 | EPSS1.05% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43236HIGH | Microsoft Message Queuing Information Disclosure VulnerabilityMicrosoft Message Queuing Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-43222. Dec 15, 2021 | CVSS7.5v3.1 | EPSS3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43235MEDIUM | Storage Spaces Controller Information Disclosure VulnerabilityStorage Spaces Controller Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-43227. CWE-668Dec 15, 2021 | CVSS5.5v3.1 | EPSS0.769% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43234HIGH | Windows Fax Service Remote Code Execution VulnerabilityWindows Fax Service Remote Code Execution Vulnerability Dec 15, 2021 | CVSS7.8v3.1 | EPSS2.06% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43233HIGH | Remote Desktop Client Remote Code Execution VulnerabilityRemote Desktop Client Remote Code Execution Vulnerability CWE-94Dec 15, 2021 | CVSS7.5v3.1 | EPSS2.24% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43232HIGH | Windows Event Tracing Remote Code Execution VulnerabilityWindows Event Tracing Remote Code Execution Vulnerability CWE-94Dec 15, 2021 | CVSS7.8v3.1 | EPSS2.06% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43231HIGH | Windows NTFS Elevation of Privilege VulnerabilityWindows NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-43229, CVE-2021-43230. CWE-269Dec 15, 2021 | CVSS7.8v3.1 | EPSS0.701% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43230HIGH | Windows NTFS Elevation of Privilege VulnerabilityWindows NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-43229, CVE-2021-43231. CWE-269Dec 15, 2021 | CVSS7.8v3.1 | EPSS0.557% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43229HIGH | Windows NTFS Elevation of Privilege VulnerabilityWindows NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-43230, CVE-2021-43231. CWE-269Dec 15, 2021 | CVSS7.8v3.1 | EPSS1.76% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43228HIGH | SymCrypt Denial of Service VulnerabilitySymCrypt Denial of Service Vulnerability CWE-400Dec 15, 2021 | CVSS7.5v3.1 | EPSS3.66% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43227MEDIUM | Storage Spaces Controller Information Disclosure VulnerabilityStorage Spaces Controller Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-43235. CWE-668Dec 15, 2021 | CVSS5.5v3.1 | EPSS0.769% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43226HIGH | Windows Common Log File System Driver Elevation of Privilege VulnerabilityWindows Common Log File System Driver Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-43207. CWE-269Dec 15, 2021 | CVSS7.8v3.1 | EPSS3.07% | PoCs0 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2021-43224MEDIUM | Windows Common Log File System Driver Information Disclosure VulnerabilityWindows Common Log File System Driver Information Disclosure Vulnerability CWE-668Dec 15, 2021 | CVSS5.5v3.1 | EPSS3.87% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43223HIGH | Windows Remote Access Connection Manager Elevation of Privilege VulnerabilityWindows Remote Access Connection Manager Elevation of Privilege Vulnerability CWE-269Dec 15, 2021 | CVSS7.8v3.1 | EPSS0.53% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43222HIGH | Microsoft Message Queuing Information Disclosure VulnerabilityMicrosoft Message Queuing Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-43236. CWE-668Dec 15, 2021 | CVSS7.5v3.1 | EPSS3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |