Vulnerabilities exploitable today
358,897in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,706
- High11,663
- Medium7,433
- Low683
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-541235.5 MED—
——0Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally.12hCVE-2026-613475.5 MED—
——0Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.1dCVE-2026-613456.5 MED—
——0Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.10hCVE-2026-613467.0 HIG—
——0Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.9hCVE-2026-613487.0 HIG—
——0Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.21hCVE-2026-67188——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.14dCVE-2026-613657.8 HIG—
——0Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.12hCVE-2026-613647.8 HIG—
——0Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.12hCVE-2026-613617.0 HIG—
——0Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.21hCVE-2026-613597.8 HIG—
——0Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.12hCVE-2026-613537.8 HIG—
——0Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.12hCVE-2026-613637.5 HIG—
——0Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.12hCVE-2026-613605.5 MED—
——0Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.1dCVE-2026-613497.8 HIG—
——0Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.21hCVE-2026-591277.8 HIG—
——0Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.21hCVE-2026-613504.6 MED—
——0Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.10hCVE-2026-51240——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.12dCVE-2026-51245——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.12dCVE-2026-51283——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.12dCVE-2026-66051——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.14dCVE-2026-51282——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.12dCVE-2026-20415—0.0%
——0——CVE-2026-28539—0.0%
——0——CVE-2025-66332—0.0%
——0——CVE-2026-00947.8 HIG0.0%
——0In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.21dCVE-2026-51236——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.12dCVE-2023-20914—0.0%
——0——CVE-2026-51246——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.12dCVE-2026-51239——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.12dCVE-2026-58407——
——0Rejected reason: Please submit CVE requests for each vulnerability.30dCVE-2026-49945——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.35dCVE-2026-62287——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61873. Reason: This candidate is a duplicate of CVE-2026-61873. Notes: All CVE users should reference CVE-2026-61873 instead of this candidate.28dCVE-2026-68869——
——0Rejected reason: This CVE ID was assigned in error. Upon further review, the reported issue does not represent a security vulnerability and does not require a CVE record.9dCVE-2026-0121—0.0%
——0——CVE-2026-62164——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-60087. Reason: This candidate is a duplicate of CVE-2026-60087. Notes: All CVE users should reference CVE-2026-60087 instead of this candidate.28dCVE-2026-240907.1 HIG0.0%
——0Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.21dCVE-2023-54375——
——0Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.7dCVE-2026-62177——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-60085. Reason: This candidate is a duplicate of CVE-2026-60085. Notes: All CVE users should reference CVE-2026-60085 instead of this candidate.28dCVE-2026-61710——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61453. Reason: This candidate is a duplicate of CVE-2026-61453. Notes: All CVE users should reference CVE-2026-61453 instead of this candidate.28dCVE-2026-591305.6 MED—
——0No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.8h