Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Filter and search through 145 vulnerabilities
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-56155 | Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally... | 7.8 | 728 | Neutral | Yes |
| Yes |
| CVE-2026-45498 | Microsoft Defender Denial of Service Vulnerability | 7.5 | 721 | Neutral | Yes | Yes |
| CVE-2026-42897 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to p... | 6.1 | 569 | Neutral | Yes | Yes |
| CVE-2026-41091 | Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. | 7.8 | 767 | Low | Yes | Yes |
| CVE-2026-32202 | Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. | 4.3 | 396 | Neutral | Yes | Yes |
| CVE-2026-32201 | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 6.5 | 598 | Neutral | Yes | Yes |
| CVE-2026-21533 | Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. | 7.8 | 728 | Neutral | Yes | Yes |
| CVE-2026-21525 | Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally. | 6.2 | 477 | Neutral | Yes | Yes |
| CVE-2026-21519 | Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | 7.8 | 728 | Neutral | Yes | Yes |
| CVE-2026-21514 | Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally. | 7.8 | 767 | Neutral | Yes | Yes |
| CVE-2026-21509 | Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally. | 7.8 | 728 | Neutral | Yes | Yes |
| CVE-2026-20805 | Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. | 5.5 | 486 | Neutral | Yes | Yes |
| CVE-2025-62215 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate... | 7.0 | 584 | Neutral | Yes | Yes |
| CVE-2025-59230 | Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | 7.8 | 771 | Neutral | Yes | Yes |
| CVE-2025-47827 | In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a cr... | 4.6 | 405 | Neutral | Yes | Yes |
| CVE-2025-32706 | Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 7.8 | 814 | Neutral | Yes | Yes |
| CVE-2025-30397 | Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a net... | 7.5 | 676 | Neutral | Yes | Yes |
| CVE-2025-26633 | Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. | 7.0 | 584 | Neutral | Yes | Yes |
| CVE-2025-24993 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | 7.8 | 728 | Neutral | Yes | Yes |
| CVE-2025-24991 | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | 5.5 | 508 | Neutral | Yes | Yes |