Vulnerabilities exploitable today
371,173in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,229
- High8,582
- Medium6,298
- Low585
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-729338.8 HIG—
———Heap-based buffer overflow in Microsoft WDAC OLE DB provider for SQL allows an unauthorized attacker to execute code over a network.12hCVE-2026-729327.5 HIG—
———Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network.10hCVE-2026-729314.7 MED—
———Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny service locally.9hCVE-2026-729307.0 HIG—
———Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to execute code locally.12hCVE-2026-729297.8 HIG—
———Improper validation of integrity check value in Windows Installer allows an authorized attacker to elevate privileges locally.12hCVE-2026-729287.5 HIG—
———Use after free in Windows DNS allows an authorized attacker to execute code over a network.12hCVE-2026-729276.7 MED—
———Heap-based buffer overflow in Winsock allows an authorized attacker to elevate privileges locally.12hCVE-2026-729267.0 HIG—
———Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate privileges locally.10hCVE-2026-713528.8 HIG—
———Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows an authorized attacker to execute code over a network.12hCVE-2026-713517.0 HIG—
———Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.12hCVE-2026-713506.8 MED—
———Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.12hCVE-2026-713496.8 MED—
———Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.12hCVE-2026-713486.8 MED—
———Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.12hCVE-2026-713457.8 HIG—
———Out-of-bounds write in Windows Spaceport.sys allows an authorized attacker to execute code locally.12hCVE-2026-713437.8 HIG—
———Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to execute code locally.12hCVE-2026-713427.0 HIG—
———Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.12hCVE-2026-713415.5 MED—
———Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally.11hCVE-2026-713407.0 HIG—
———Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.12hCVE-2026-713396.7 MED—
———Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.12hCVE-2026-713386.4 MED—
———Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.12hCVE-2026-713377.8 HIG—
———Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.12hCVE-2026-713368.8 HIG—
———Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network.10hCVE-2026-713337.0 HIG—
———Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.12hCVE-2026-713327.0 HIG—
———Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally.12hCVE-2026-713307.5 HIG—
———Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network.9hCVE-2026-713296.8 MED—
———Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.10hCVE-2026-713288.8 HIG—
———Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.12hCVE-2026-705877.5 HIG—
———Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.9hCVE-2026-705868.8 HIG—
———Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code over a network.12hCVE-2026-705857.0 HIG—
———Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally.12hCVE-2026-705847.8 HIG—
———Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally.10hCVE-2026-705837.8 HIG—
———Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges locally.12hCVE-2026-705817.8 HIG—
———Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.12hCVE-2026-705797.5 HIG—
———Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose information over a network.10hCVE-2026-705787.0 HIG—
———Heap-based buffer overflow in Windows Credential Guard allows an authorized attacker to elevate privileges locally.12hCVE-2026-705777.0 HIG—
———Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.12hCVE-2026-705755.3 MED—
———Null pointer dereference in Windows Schannel allows an authorized attacker to deny service over a network.9hCVE-2026-705747.8 HIG—
———Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.12hCVE-2026-705737.0 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.12hCVE-2026-705727.8 HIG—
———Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.12h