Vulnerabilities exploitable today
371,173in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,229
- High8,582
- Medium6,298
- Low585
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-695695.7 MED—
———Untrusted pointer dereference in Windows Print Spooler Components allows an authorized attacker to deny service over a network.8hCVE-2026-695685.5 MED—
———Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to disclose information locally.9hCVE-2026-695677.0 HIG—
———Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.10hCVE-2026-695666.8 MED—
———Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.10hCVE-2026-695647.0 HIG—
———Heap-based buffer overflow in Windows Online Certificate Status Protocol (OCSP) allows an authorized attacker to elevate privileges locally.10hCVE-2026-819528.8 HIG—
———Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.8hCVE-2026-819537.8 HIG—
———Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.10hCVE-2026-695637.0 HIG—
———Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.10hCVE-2026-695626.5 MED—
———Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network.9hCVE-2026-695617.8 HIG—
———Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally.10hCVE-2026-695607.0 HIG—
———Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.10hCVE-2026-695595.8 MED—
———Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.9hCVE-2026-695568.8 HIG—
———Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.9hCVE-2026-695545.5 MED—
———Missing authentication for critical function in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.10hCVE-2026-695537.1 HIG—
———Missing authorization in Windows Hyper-V allows an authorized attacker to elevate privileges over a network.10hCVE-2026-819547.8 HIG—
———Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.10hCVE-2026-819558.8 HIG—
———Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.10hCVE-2026-819567.8 HIG—
———Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.10hCVE-2026-695518.8 HIG—
———Use after free in Windows DNS allows an authorized attacker to execute code over a network.10hCVE-2026-695497.0 HIG—
———Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.10hCVE-2026-695484.6 MED—
———Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to disclose information with a physical attack.10hCVE-2026-819585.5 MED—
———Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.9hCVE-2026-695478.8 HIG—
———Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.10hCVE-2026-819597.8 HIG—
———Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.10hCVE-2026-695468.1 HIG—
———Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.10hCVE-2026-695447.8 HIG—
———Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.10hCVE-2026-695427.8 HIG—
———Heap-based buffer overflow in Windows Camera Frame Server Monitor allows an authorized attacker to elevate privileges locally.10hCVE-2026-695417.8 HIG—
———Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.9hCVE-2026-695407.0 HIG—
———Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally.10hCVE-2026-695397.5 HIG—
———Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.10hCVE-2026-695387.8 HIG—
———Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally.10hCVE-2026-695367.1 HIG—
———Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.10hCVE-2026-695357.8 HIG—
———Numeric truncation error in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.10hCVE-2026-695347.8 HIG—
———Improper neutralization of special elements used in a command ('command injection') in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.10hCVE-2026-695315.5 MED—
———Unintended proxy or intermediary ('confused deputy') in Microsoft Windows Speech allows an authorized attacker to perform tampering locally.10hCVE-2026-695308.1 HIG—
———Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.10hCVE-2026-695298.8 HIG—
———Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.9hCVE-2026-695287.8 HIG—
———Missing authentication for critical function in Windows Shell allows an authorized attacker to elevate privileges locally.10hCVE-2026-695275.5 MED—
———Out-of-bounds read in Windows USB Mass Storage Class Driver allows an authorized attacker to disclose information locally.8hCVE-2026-819607.8 HIG—
———Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.10h