Vulnerabilities exploitable today
358,897in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,708
- High11,665
- Medium7,438
- Low683
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-73212——
——0Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_turn_server.c uses ioa_addr_in_range() in src/client/ns_turn_ioaddr.c without canonicalizing IPv4-compatible, 6to4, and 64:ff9b::/96 NAT64 address forms, allowing an authenticated RFC 6062 TCP CONNECT relay client to bypass an IPv4 denied-peer-ip range when the Coturn host has a useful translation route. This issue is fixed in version 4.13.1.1dCVE-2026-627865.5 MED—
——0Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.8hCVE-2026-73066——
——0Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolve.cpp to wrap the convolution output-channel count, undersizing the forward-pass output buffer while writes use the unwrapped element count and causing a heap out-of-bounds write during OCR recognition. This issue is fixed in version 5.5.3.1dCVE-2026-628824.3 MED—
——0Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.7hCVE-2026-628294.6 MED—
——0Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.1dCVE-2026-627985.5 MED—
——0Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.1dCVE-2026-627965.5 MED—
——0Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.1dCVE-2026-627755.5 MED—
——0Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.1dCVE-2026-73213——
——0Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_turn_ioaddr.c uses a component-wise comparison for native IPv6 min-max intervals in ioa_addr_in_range(), allowing an authenticated TURN client to relay to an IPv6 peer that is numerically within a configured non-prefix-aligned denied-peer-ip range but is classified as outside it. This issue is fixed in version 4.16.0.1dCVE-2026-627747.0 HIG—
——0Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.1dCVE-2026-627737.0 HIG—
——0Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.10hCVE-2026-627707.8 HIG—
——0Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.19hCVE-2026-73215——
——0Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, turnports_allocate_even() in src/apps/relay/turn_ports.c marks the unused odd sibling port as TPS_TAKEN_ODD for an EVEN-PORT Allocate request with reservation bit R=0 even though no RTCP socket will release it, allowing an authenticated client to permanently exhaust the relay port pool and cause subsequent allocations to fail with STUN error 508. This issue is fixed in version 4.17.0.1dCVE-2026-73214——
——0Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and create_new_connected_udp_socket() in src/apps/relay/dtls_listener.c retain OpenSSL dtls1_reassemble_fragment() state for a 35-byte fragmented ClientHello declaring a 650,000-byte handshake before cookie validation, allowing an unauthenticated remote sender using fresh UDP tuples to exhaust memory without TURN credentials, a completed handshake, a valid cookie, or source spoofing. This issue is fixed in version 4.16.0.49mCVE-2026-627527.8 HIG—
——0Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.19hCVE-2026-627517.8 HIG—
——0Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.19hCVE-2026-627357.8 HIG—
——0Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.19hCVE-2026-627347.0 HIG—
——0Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.10hCVE-2026-732166.5 MED—
——0Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in src/server/ns_turn_server.c prematurely calls dec_quota() and releases bandwidth accounting during the first-stage close of a mobility-enabled allocation while preserving the allocation, relay socket, session, and mobility ticket, allowing an authenticated client to bypass --user-quota and --total-quota and exhaust relay ports. This issue is fixed in version 4.17.0.1dCVE-2026-73217——
——0Cursor is a code editor built for programming with AI. Prior to 3.1.2, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode to replace a virtual environment's Python executable with a malicious wrapper that the Microsoft Python extension invokes outside the sandbox, allowing arbitrary host commands with the user's privileges, including modifying files outside the workspace and launching applications. This issue is fixed in version 3.1.2.1dCVE-2026-73218——
——0Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Docker Desktop and the Dev Containers CLI are installed, to launch a privileged container and mount Docker's virtiofs0, granting read and write access to the user's home directory and enabling host command execution with the user's privileges without an additional permission prompt. This issue is fixed in version 3.0.0.1dCVE-2026-627337.8 HIG—
——0Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.19hCVE-2026-627727.8 HIG—
——0Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally.10hCVE-2026-627717.8 HIG—
——0Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.10hCVE-2026-627696.7 MED—
——0Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.19hCVE-2026-627687.8 HIG—
——0Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.10hCVE-2026-627547.8 HIG—
——0Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.10hCVE-2026-627537.0 HIG—
——0Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.10hCVE-2026-11733——
——0A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device.16hCVE-2026-627227.8 HIG—
——0Heap-based buffer overflow in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.10hCVE-2026-627217.8 HIG—
——0Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.10hCVE-2026-627206.5 MED—
——0Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.8hCVE-2026-627107.8 HIG—
——0Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.10hCVE-2026-627095.5 MED—
——0Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.1dCVE-2026-627026.8 MED—
——0Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.1dCVE-2026-627017.8 HIG—
——0Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.19hCVE-2026-11736——
——0A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.16hCVE-2026-619277.0 HIG—
——0Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.19hCVE-2026-619237.8 HIG—
——0Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.1dCVE-2026-619216.5 MED—
——0Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.1d