Vulnerabilities exploitable today
358,498in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,606
Distribution · last window
- Critical2,687
- High11,687
- Medium7,450
- Low690
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-188608.7 HIG—
———Velociraptor allows multi-tenant deployments named "Orgs".
By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment.
Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines the ORG_ADMIN permission on the ROOT org.
This issue results from the Velociraptor server allowing for the deletion of Orgs by incorrectly checking the ORG_ADMIN permission of callers within the calling ORG instead of the ROOT org. However, Org admins of child orgs were able to add this permission to their ACL token within their own org. This allows an administrator in a child org, which is not also an administrator in the ROOT org, to delete other orgs.11hCVE-2026-657747.8 HIG—
———Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.2hCVE-2026-186366.8 MED—
———The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefixes. This prefix check can be bypassed allowing a user to access usually denied files. If the user has read permission in the ROOT org, this allows access to other orgs, in which the user may not have permission.11hCVE-2020-37264——
———Rejected reason: This CVE ID has been rejected.16hCVE-2026-657976.7 MED—
———Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.2hCVE-2026-657986.7 MED—
———Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.2hCVE-2020-37263——
———Rejected reason: This CVE ID has been rejected.16hCVE-2020-37261——
———Rejected reason: This CVE ID has been rejected.16hCVE-2020-37260——
———Rejected reason: This CVE ID has been rejected.16hCVE-2026-687947.8 HIG—
———Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.2hCVE-2026-687957.8 HIG—
———Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.2hCVE-2026-687967.8 HIG—
———Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.2hCVE-2026-687975.5 MED—
———Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.9hCVE-2026-687987.8 HIG—
———Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.2hCVE-2020-37258——
———Rejected reason: This CVE ID has been rejected.16hCVE-2026-687995.5 MED—
———Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.10hCVE-2026-688007.8 HIG—
———Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.2hCVE-2020-37257——
———Rejected reason: This CVE ID has been rejected.16h