Vulnerabilities exploitable today
358,897in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,704
- High11,656
- Medium7,416
- Low682
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-658136.5 MED—
——0Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.12hCVE-2026-658147.8 HIG—
——0Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.13hCVE-2026-663016.5 MED—
——0Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network.1dCVE-2026-667997.8 HIG—
——0Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.1dCVE-2026-687927.8 HIG—
——0Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally.13hCVE-2026-657996.7 MED—
——0Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.22hCVE-2026-658066.5 MED—
——0Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.11hCVE-2026-658107.8 HIG—
——0Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.13hCVE-2026-658118.8 HIG—
——0Improper input validation in Power BI allows an authorized attacker to execute code over a network.22hCVE-2026-668028.1 HIG—
——0Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.22hCVE-2026-668047.8 HIG—
——0Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.11hCVE-2026-687937.8 HIG—
——0Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.11hCVE-2026-613487.0 HIG—
——0Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.22hCVE-2026-195598.8 HIG—
——0Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)7hCVE-2026-613497.8 HIG—
——0Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.22hCVE-2026-591277.8 HIG—
——0Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.22hCVE-2026-613504.6 MED—
——0Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.11hCVE-2026-688095.5 MED—
——0Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.1dCVE-2026-688067.8 HIG—
——0Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally.10hCVE-2026-688085.5 MED—
——0Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.10hCVE-2026-688107.8 HIG—
——0Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.10hCVE-2026-688117.8 HIG—
——0Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.10hCVE-2026-688127.8 HIG—
——0Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.10hCVE-2026-688135.5 MED—
——0Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.10hCVE-2026-688147.8 HIG—
——0Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.10hCVE-2026-541235.5 MED—
——0Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally.13hCVE-2026-195608.8 HIG—
——0Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)13hCVE-2026-661497.8 HIG—
——0Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.22hCVE-2026-613605.5 MED—
——0Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.1dCVE-2026-701308.4 HIG—
——0Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.22hCVE-2026-693068.2 HIG—
——0Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.1dCVE-2026-688157.8 HIG—
——0Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.10hCVE-2026-688167.8 HIG—
——0Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.10hCVE-2026-688177.8 HIG—
——0Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.10hCVE-2026-688195.9 MED—
——0Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.13hCVE-2026-692239.1 CRI—
——0Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF).
This issue affects Apache Allura: before 1.19.1.
Users are recommended to upgrade to version 1.19.1, which fixes the issue.6hCVE-2026-693208.8 HIG—
——0Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.13hCVE-2026-675587.4 HIG—
——0The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live session token information and inject forged hormone measurements into the victim's cloud record and clinical trend view.11hCVE-2026-680679.8 CRI—
——0The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.13hCVE-2026-613637.5 HIG—
——0Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.13h