Vulnerabilities exploitable today
372,403in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,230
- High8,254
- Medium6,232
- Low617
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-24781—23.7%
——7——CVE-2023-27115—23.7%
——7——CVE-2025-2405—23.7%
——7——CVE-2025-62475—23.7%
——7——CVE-2023-0706—23.7%
——7——CVE-2026-839777.8 HIG23.7%
——7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2dCVE-2024-53459—23.7%
——7——CVE-2025-62476—23.7%
——7——CVE-2007-3800—23.7%
——7——CVE-2024-34794—23.7%
——7——CVE-2025-7865—23.7%
——7——CVE-2010-2470—23.7%
——7——CVE-2024-11934—23.7%
——7——CVE-2026-619267.8 HIG23.7%
——7Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.26dCVE-2026-619347.8 HIG23.7%
——7Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.29dCVE-2024-9735—23.7%
——7——CVE-2025-27601—23.7%
——7——CVE-2026-627477.8 HIG23.7%
——7Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.26dCVE-2011-3177—23.7%
——7——CVE-2025-25213—23.7%
——7——CVE-2010-0429—23.7%
——7——CVE-2024-47822—23.7%
——7——CVE-2026-619237.8 HIG23.7%
——7Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.26dCVE-2026-627547.8 HIG23.7%
——7Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.26dCVE-2026-839877.8 HIG23.7%
——7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.1dCVE-2026-627017.8 HIG23.7%
——7Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.26dCVE-2026-32814—23.7%
——7——CVE-2026-874395.3 MED23.7%
——7Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)2dCVE-2026-627197.8 HIG23.7%
——7Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.26dCVE-2026-839677.8 HIG23.7%
——7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2dCVE-2026-08977.5 HIG23.7%
——7Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a crash of the Python interpreter via a crafted .keras archive containing a valid model.weights.h5 file whose dataset declares an extremely large shape.59dCVE-2026-626927.8 HIG23.7%
——7Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.26dCVE-2026-13348—23.7%
——7CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an arbitrary number of authentication attempts when redirect handling is disabled.10dCVE-2026-40482—23.7%
——7——CVE-2025-54004—23.7%
——7——CVE-2005-1961—23.7%
——7——CVE-2024-50612—23.7%
——7——CVE-2023-26991—23.7%
——7——CVE-2026-706357.1 HIG23.7%
——7TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authenticated attackers to cause query-result integrity failures or backend crashes by supplying a crafted Simple8b selector-11 value, which is stored in the signed int16 Arrow dictionary-index type and bypasses index validation checks in bulk text dictionary decompression. Attackers with direct DML access to a non-frozen physical compressed hypertable relation can trigger an out-of-bounds read before the base of the live offsets array through the VectorAgg single-text hashing strategy, resulting in incorrect aggregation output, backend SIGSEGV, or PostgreSQL crash recovery depending on build configuration.10dCVE-2026-627527.8 HIG23.7%
——7Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.26d