Vulnerabilities exploitable today
373,020in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,219
- High8,129
- Medium6,192
- Low613
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-698017.8 HIG24.5%
——7Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.4dCVE-2026-705647.8 HIG24.5%
——7Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.4dCVE-2016-7628—24.5%
——7——CVE-2023-28018—24.5%
——7——CVE-2026-693077.8 HIG24.5%
——7Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.4dCVE-2026-695927.8 HIG24.5%
——7Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.4dCVE-2025-58692—24.5%
——7——CVE-2026-30867—24.5%
——7——CVE-2025-28041—24.5%
——7——CVE-2025-28965—24.5%
——7——CVE-2026-693487.8 HIG24.5%
——7Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.4dCVE-2025-0521—24.5%
——7——CVE-2019-15265—24.5%
——7——CVE-2025-0660—24.5%
——7——CVE-2024-11379—24.5%
——7——CVE-2026-50014—24.5%
——7——CVE-2026-4633—24.5%
——7——CVE-2024-342687.1 HIG24.5%
——7EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow unsecured bluetooth connections. This vulnerability allows attackers to gain full access to the device without authentication.57dCVE-2020-27585—24.5%
——7——CVE-2025-4762—24.5%
——7——CVE-2026-733956.5 MED24.5%
——7Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions.24dCVE-2026-695097.8 HIG24.5%
——7Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.4dCVE-2025-705456.1 MED24.5%
——7A stored cross-site scripting (XSS) vulnerability exists in the web management interface of the PPC (Belden) ONT 2K05X router running firmware v1.1.9_206L. The Common Gateway Interface (CGI) component improperly handles user-supplied input, allowing a remote, unauthenticated attacker to inject arbitrary JavaScript that is persistently stored and executed when the affected interface is accessed.70dCVE-2022-48805—24.5%
——7——CVE-2026-56664—24.5%
——7——CVE-2026-696047.8 HIG24.5%
——7Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.4dCVE-2026-34067—24.5%
——7——CVE-2023-1641—24.5%
——7——CVE-2026-695447.8 HIG24.5%
——7Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.4dCVE-2026-180777.5 HIG24.5%
——7IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow.25dCVE-2026-697587.8 HIG24.5%
——7Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.4dCVE-2020-1688—24.5%
——7——CVE-2022-49526—24.5%
——7——CVE-2023-1640—24.5%
——7——CVE-2023-34005—24.5%
——7——CVE-2024-10777—24.5%
——7——CVE-2025-55271—24.5%
——7——CVE-2008-2308—24.5%
——7——CVE-2009-4235—24.5%
——7——CVE-2021-31998—24.5%
——7——