Vulnerabilities exploitable today
373,020in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,219
- High8,129
- Medium6,192
- Low613
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-729977.8 HIG24.5%
——7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.1dCVE-2026-705727.8 HIG24.5%
——7Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.1dCVE-2026-696877.8 HIG24.5%
——7Integer underflow (wrap or wraparound) in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.3dCVE-2026-729657.8 HIG24.5%
——7Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally.4dCVE-2026-1945—24.5%
——7——CVE-2026-626977.8 HIG24.5%
——7Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.4dCVE-2026-694247.8 HIG24.5%
——7Heap-based buffer overflow in Windows Distributed File System (DFS) allows an authorized attacker to elevate privileges locally.4dCVE-2026-561777.8 HIG24.5%
——7Use after free in Windows Server allows an authorized attacker to elevate privileges locally.4dCVE-2024-51563—24.5%
——7——CVE-2026-694327.8 HIG24.5%
——7Heap-based buffer overflow in Volume Manager Driver allows an authorized attacker to elevate privileges locally.4dCVE-2026-4615—24.5%
——7——CVE-2020-27184—24.5%
——7——CVE-2026-694807.8 HIG24.5%
——7Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.4dCVE-2025-0860—24.5%
——7——CVE-2026-850936.5 MED24.5%
——7Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retrieving episodic memory points. Authenticated attackers with MEMORY:READ permission can retrieve all users' stored conversation messages and personal data by paginating through the collection using the offset cursor.2dCVE-2024-31957—24.5%
——7——CVE-2025-49266—24.5%
——7——CVE-2024-25657—24.5%
——7——CVE-2017-14737—24.5%
——7——CVE-2024-8918—24.5%
——7——CVE-2026-5150—24.5%
——7——CVE-2025-1968—24.5%
——7——CVE-2026-40924—24.5%
——7——CVE-2024-11333—24.5%
——7——CVE-2026-692957.8 HIG24.5%
——7Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally.4dCVE-2026-44549—24.5%
——7——CVE-2026-688887.8 HIG24.5%
——7Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.4dCVE-2025-69428—24.5%
——7——CVE-2024-28158—24.5%
——7——CVE-2025-0783—24.5%
——7——CVE-2026-95517.3 HIG24.5%
——7A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of the file ParkingRecord/ExportParkingRecords of the component API Endpoint. The manipulation of the argument Value leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.52dCVE-2008-2313—24.5%
——7——CVE-2026-693897.8 HIG24.5%
——7Heap-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.4dCVE-2024-11761—24.5%
——7——CVE-2026-713457.8 HIG24.5%
——7Out-of-bounds write in Windows Spaceport.sys allows an authorized attacker to execute code locally.4dCVE-2026-705817.8 HIG24.5%
——7Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2dCVE-2026-774897.8 HIG24.5%
——7Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.1dCVE-2026-102907.3 HIG24.5%
——7A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unknown function of the file tour.php of the component GET Parameter Handler. Executing a manipulation of the argument tour can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.52dCVE-2026-697907.8 HIG24.5%
——7Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to elevate privileges locally.4dCVE-2026-888596.3 MED24.5%
——7A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript handler incorrectly assigns an attacker-controlled JavaScript URL to an iframe's source. This action leads to arbitrary JavaScript execution within the mail-viewing context, effectively bypassing the security measures designed to prevent script execution in email content.2d