Vulnerabilities exploitable today
373,020in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,219
- High8,129
- Medium6,192
- Low613
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-698017.8 HIG24.5%
——7Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.4dCVE-2021-44954—24.5%
——7——CVE-2026-22459—24.5%
——7——CVE-2026-692697.8 HIG24.5%
——7Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.4dCVE-2026-705647.8 HIG24.5%
——7Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.4dCVE-2026-705747.8 HIG24.5%
——7Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.2dCVE-2026-695927.8 HIG24.5%
——7Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.4dCVE-2024-45504—24.5%
——7——CVE-2014-8519—24.5%
——7——CVE-2026-693077.8 HIG24.5%
——7Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.4dCVE-2023-28018—24.5%
——7——CVE-2019-10688—24.5%
——7——CVE-2021-46775—24.5%
——7——CVE-2013-3272—24.5%
——7——CVE-2022-47180—24.5%
——7——CVE-2026-3172—24.5%
——7——CVE-2005-0580—24.5%
——7——CVE-2024-10787—24.5%
——7——CVE-2026-156734.4 MED24.5%
——7The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via 'checkout_payment_plans' and 'order_status' Settings in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is a second-order SQL injection: the malicious payload is stored in the 'checkout_payment_plans' and 'order_status' settings via update_option() and executed later when the cod_to_prepaid_cart_notification_sendsms_hook WP-Cron event fires SA_CodTOPrepaid::sendSms().47dCVE-2026-180777.5 HIG24.5%
——7IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow.25dCVE-2026-56664—24.5%
——7——CVE-2016-7628—24.5%
——7——CVE-2008-3930—24.5%
——7——CVE-2023-52284—24.5%
——7——CVE-2008-4984—24.5%
——7——CVE-2026-688457.8 HIG24.5%
——7Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.4dCVE-2021-1593—24.5%
——7——CVE-2015-7238—24.5%
——7——CVE-2023-4302—24.5%
——7——CVE-2023-41365—24.5%
——7——CVE-2005-0620—24.5%
——7——CVE-2005-1617—24.5%
——7——CVE-2005-0119—24.5%
——7——CVE-2026-698417.8 HIG24.5%
——7Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.3dCVE-2024-6518—24.5%
——7——CVE-2021-31523—24.5%
——7——CVE-2024-6521—24.5%
——7——CVE-2004-1795—24.5%
——7——CVE-2025-28896—24.5%
——7——CVE-2025-41772—24.5%
——7——