Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,453
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-541147.8 HIG26.4%
——8Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.55dCVE-2026-585327.8 HIG26.4%
——8Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.55dCVE-2026-561757.8 HIG26.4%
——8Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.56dCVE-2026-504127.8 HIG26.4%
——8Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.57dCVE-2025-49726—26.4%
——8——CVE-2026-504937.8 HIG26.4%
——8Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.55dCVE-2026-476358.4 HIG26.4%
——8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.55dCVE-2026-503157.8 HIG26.4%
——8Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.55dCVE-2024-13451—26.4%
——8——CVE-2026-502937.8 HIG26.4%
——8Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.55dCVE-2022-29836—26.4%
——8——CVE-2026-1193—26.4%
——8——CVE-2025-2491—26.4%
——8——CVE-2026-504417.8 HIG26.4%
——8Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.55dCVE-2026-504337.8 HIG26.4%
——8Use after free in Windows Media allows an authorized attacker to elevate privileges locally.55dCVE-2017-18669—26.4%
——8——CVE-2025-15351—26.4%
——8——CVE-2024-5829—26.4%
——8——CVE-2026-503637.8 HIG26.4%
——8Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.55dCVE-2026-504947.8 HIG26.4%
——8Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.56dCVE-2026-503828.8 HIG26.4%
——8Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.55dCVE-2020-27123—26.4%
——8——CVE-2026-504357.8 HIG26.4%
——8Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.55dCVE-2019-10476—26.4%
——8——CVE-2026-506928.8 HIG26.4%
——8Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.55dCVE-2025-53076—26.4%
——8——CVE-2020-12039—26.4%
——8——CVE-2026-585367.8 HIG26.4%
——8Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.55dCVE-2021-38204—26.4%
——8——CVE-2025-36354—26.4%
——8——CVE-2026-549877.8 HIG26.4%
——8Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.55dCVE-2026-33659—26.4%
——8——CVE-2024-37603—26.3%
——8——CVE-2026-147976.3 MED26.3%
——8A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. This vulnerability affects unknown code of the file /apartment-visitor/edit-apartment.php. Executing a manipulation of the argument editid can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.71dCVE-2012-4948—26.3%
——8——CVE-2026-162617.5 HIG26.3%
——8The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from unverified third-party sign-in data, allowing unauthenticated attackers to reset any user's password or log in as any existing account, including administrators, and take over the site.20dCVE-2026-504997.8 HIG26.3%
——8Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.55dCVE-2026-482086.5 MED26.3%
——8An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially crafted SVG payloads via email content, leading to browser-side resource exhaustion and denial of service when affected tickets are opened by an agent or customer. The issue can be exploited without JavaScript execution and is not mitigated by the configured Content Security Policy (CSP).
This issue affects OTRS:
* 7.0.X
* 8.0.X
* 2023.X
* 2024.X
* 2025.X
* 2026.X before 2026.4.X
Please note that ((OTRS)) Community Edition 6.x and before are vulnerable. Products based on the ((OTRS)) Community Edition also very likely to be affected56dCVE-2004-2258—26.3%
——8——CVE-2026-147676.3 MED26.3%
——8A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. This affects an unknown part of the file /ecommerce-website-php/customer/confirm.php of the component POST Parameter Handler. The manipulation of the argument invoice_no results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.71d