Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,453
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-497958.8 HIG26.4%
——8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.55dCVE-2026-504797.8 HIG26.4%
——8Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.57dCVE-2026-549877.8 HIG26.4%
——8Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.55dCVE-2026-503297.8 HIG26.4%
——8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.55dCVE-2026-585367.8 HIG26.4%
——8Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.55dCVE-2026-33659—26.4%
——8——CVE-2020-12039—26.4%
——8——CVE-2024-37369—26.4%
——8——CVE-2026-586017.8 HIG26.4%
——8Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.55dCVE-2024-22911—26.4%
——8——CVE-2003-0177—26.4%
——8——CVE-2026-106275.3 MED26.4%
——8The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view the titles, dates, descriptions, and location details of events and locations that administrators have marked as draft, pending, trashed, or private.19dCVE-2026-506708.8 HIG26.4%
——8Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.61dCVE-2019-10460—26.4%
——8——CVE-2019-20618—26.4%
——8——CVE-2020-12309—26.4%
——8——CVE-2017-18666—26.4%
——8——CVE-2008-3896—26.4%
——8——CVE-2021-3447—26.4%
——8——CVE-2025-49687—26.4%
——8——CVE-2024-0749—26.4%
——8——CVE-2017-18668—26.4%
——8——CVE-2026-7552—26.4%
——8——CVE-2022-40132—26.4%
——8——CVE-2026-504867.8 HIG26.4%
——8Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.55dCVE-2019-10461—26.4%
——8——CVE-2025-36354—26.4%
——8——CVE-2025-48138—26.4%
——8——CVE-2026-504778.8 HIG26.4%
——8Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.55dCVE-2025-53076—26.4%
——8——CVE-2026-561767.8 HIG26.4%
——8Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.55dCVE-2026-503877.8 HIG26.4%
——8Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.55dCVE-2021-38204—26.4%
——8——CVE-1999-0370—26.4%
——8——CVE-2026-586327.8 HIG26.4%
——8Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.55dCVE-2026-506878.8 HIG26.4%
——8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.55dCVE-2025-0658—26.4%
——8——CVE-2026-504217.8 HIG26.4%
——8Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.55dCVE-2026-504138.8 HIG26.4%
——8Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.55dCVE-2025-52878—26.4%
——8——