Vulnerabilities exploitable today
372,403in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,230
- High8,254
- Medium6,232
- Low617
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-76598—23.7%
——7Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing via onAjax_getFolders in Fabrik < 4.7.2 - The onAjax_getFolders method of the elements model allows arbitrary directory listings.18dCVE-2025-2307—23.7%
——7——CVE-2025-62477—23.7%
——7——CVE-2026-685848.6 HIG23.7%
——7SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform no password check despite protecting the primary getDoc endpoint. Anonymous attackers can retrieve full content of password-protected documents by obtaining internal block IDs from reader-accessible endpoints and calling unprotected content endpoints to bypass the password gate.16dCVE-2026-619327.8 HIG23.7%
——7Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.26dCVE-2026-627687.8 HIG23.7%
——7Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.25dCVE-2024-3654—23.7%
——7——CVE-2024-12457—23.7%
——7——CVE-2026-613557.8 HIG23.7%
——7Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.29dCVE-2026-790015.3 MED23.7%
——7Information leak in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)16dCVE-2022-31011—23.7%
——7——CVE-2026-627177.8 HIG23.7%
——7Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.26dCVE-2025-21162—23.7%
——7——CVE-2025-52337—23.7%
——7——CVE-2024-41687—23.7%
——7——CVE-2013-5493—23.7%
——7——CVE-2026-185347.4 HIG23.7%
——7ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to imitate browser interface elements and increasing spoofing risk.8dCVE-2026-659766.5 MED23.7%
——7Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.300, a connected peer can send repeated DCLP DataChunk messages to ClipboardChunk::assemble() in src/lib/deskflow/ClipboardChunk.cpp, causing the server path in src/lib/server/ClientProxy1_6.cpp or client path in src/lib/client/ServerProxy.cpp to append data beyond the DataStart declared size and configured clipboard limit before DataEnd validation, exhausting receiver memory. This issue is fixed in continuous build 1.26.0.300.2dCVE-2026-839827.8 HIG23.7%
——7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2dCVE-2023-42908—23.7%
——7——CVE-2025-42603—23.7%
——7——CVE-2025-8616—23.7%
——7——CVE-2023-34130—23.7%
——7——CVE-2026-24850—23.7%
——7——CVE-2025-11369—23.7%
——7——CVE-2025-4375—23.7%
——7——CVE-2025-66205—23.7%
——7——CVE-2026-839727.8 HIG23.7%
——7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2dCVE-2023-43090—23.7%
——7——CVE-2026-732238.1 HIG23.7%
——7electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious SFTP server to write attacker-controlled content outside the temporary directory because the server-controlled filename name used by editWithSystemEditor in src/client/components/sftp/file-item.jsx is interpolated into path.resolve without sanitization. This issue is fixed in version 3.15.120.2dCVE-2023-42903—23.7%
——7——CVE-2026-839817.8 HIG23.7%
——7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.1dCVE-2026-7703—23.7%
——7——CVE-2026-839807.8 HIG23.7%
——7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2dCVE-2026-18323—23.7%
——7——CVE-2025-6778—23.7%
——7——CVE-2026-839867.8 HIG23.7%
——7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2dCVE-2026-839797.8 HIG23.7%
——7Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.1dCVE-2026-839787.8 HIG23.7%
——7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2dCVE-2026-839707.8 HIG23.7%
——7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2d