Vulnerabilities exploitable today
373,020in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,219
- High8,129
- Medium6,192
- Low613
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-22239—24.5%
——7——CVE-2026-694757.8 HIG24.5%
——7Untrusted pointer dereference in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.4dCVE-2025-57520—24.5%
——7——CVE-2026-694897.8 HIG24.5%
——7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2dCVE-2026-729967.8 HIG24.5%
——7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.23hCVE-2025-29904—24.5%
——7——CVE-2025-12377—24.5%
——7——CVE-2026-4956—24.5%
——7——CVE-2008-4214—24.5%
——7——CVE-2021-34412—24.5%
——7——CVE-2025-49316—24.5%
——7——CVE-2026-673116.8 MED24.5%
——7Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects against the IP blacklist. Attackers with Builder role can configure a REST datasource pointing to an external server that returns a redirect to internal IP addresses, bypassing blacklist protection to access cloud metadata endpoints and internal services.12dCVE-2026-888596.3 MED24.5%
——7A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript handler incorrectly assigns an attacker-controlled JavaScript URL to an iframe's source. This action leads to arbitrary JavaScript execution within the mail-viewing context, effectively bypassing the security measures designed to prevent script execution in email content.2dCVE-2026-697907.8 HIG24.5%
——7Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to elevate privileges locally.4dCVE-2026-697877.8 HIG24.5%
——7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2dCVE-2026-774897.8 HIG24.5%
——7Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.1dCVE-2026-697097.8 HIG24.5%
——7Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.4dCVE-2026-697077.8 HIG24.5%
——7Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.2dCVE-2026-696857.8 HIG24.5%
——7Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.4dCVE-2026-102907.3 HIG24.5%
——7A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unknown function of the file tour.php of the component GET Parameter Handler. Executing a manipulation of the argument tour can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.52dCVE-2026-705817.8 HIG24.5%
——7Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2dCVE-2026-705847.8 HIG24.5%
——7Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally.4dCVE-2026-58287.3 HIG24.5%
——7A vulnerability was found in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /functions/addcomment.php. The manipulation of the argument postid results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.51dCVE-2026-695087.8 HIG24.5%
——7Stack-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.4dCVE-2026-695897.8 HIG24.5%
——7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2dCVE-2026-695327.8 HIG24.5%
——7Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.4dCVE-2026-698227.8 HIG24.5%
——7Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.4dCVE-2026-698447.8 HIG24.5%
——7Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.4dCVE-2026-8704—24.5%
——7——CVE-2024-38394—24.5%
——7——CVE-2026-58247.3 HIG24.5%
——7A security vulnerability has been detected in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /userchecklogin.php. Such manipulation of the argument userid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.51dCVE-2026-95527.3 HIG24.5%
——7A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown code of the component Search API Endpoint. The manipulation of the argument Value results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.52dCVE-2026-208537.4 HIG24.5%
——7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate privileges locally.44dCVE-2026-6153—24.5%
——7——CVE-2026-712927.2 HIG24.5%
——7Subrion CMS's admin grid sorting helper, _gridGetSorting in includes/classes/ia.base.controller.admin.php, whitelists the (ASC/DESC) request parameter via in_array, but falls back to the raw, attacker-supplied GET parameter whenever the requested key is not present in the per-controller whitelist array: , which is then placed into %s with only backtick-quoting and no escaping.17dCVE-2026-729657.8 HIG24.5%
——7Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally.4dCVE-2026-729977.8 HIG24.5%
——7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.1dCVE-2026-561777.8 HIG24.5%
——7Use after free in Windows Server allows an authorized attacker to elevate privileges locally.4dCVE-2024-51563—24.5%
——7——CVE-2026-705727.8 HIG24.5%
——7Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.1d