Vulnerabilities exploitable today
371,173in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,229
- High8,582
- Medium6,298
- Low586
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-692897.8 HIG—
———Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an authorized attacker to elevate privileges locally.8hCVE-2026-785084.6 MED—
———Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack.6hCVE-2026-692885.5 MED—
———Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.6hCVE-2026-692877.0 HIG—
———Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.8hCVE-2026-692865.5 MED—
———Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to disclose information locally.6hCVE-2026-692847.8 HIG—
———Heap-based buffer overflow in Windows DCOM Server allows an authorized attacker to elevate privileges locally.8hCVE-2026-692837.8 HIG—
———Heap-based buffer overflow in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally.8hCVE-2026-692828.8 HIG—
———Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.7hCVE-2026-692817.0 HIG—
———Use after free in Windows License Manager allows an authorized attacker to elevate privileges locally.9hCVE-2026-692807.0 HIG—
———Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.9hCVE-2026-692797.0 HIG—
———Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.9hCVE-2026-692777.8 HIG—
———Stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.9hCVE-2026-785099.8 CRI—
———Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.8hCVE-2026-692769.8 CRI—
———Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network.7hCVE-2026-692757.0 HIG—
———Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.9hCVE-2026-692747.1 HIG—
———Use after free in Windows Win32K allows an authorized attacker to elevate privileges over a network.9hCVE-2026-692738.8 HIG—
———Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.9hCVE-2026-785109.8 CRI—
———Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.6hCVE-2026-692727.1 HIG—
———Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.9hCVE-2026-692718.0 HIG—
———Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.7hCVE-2026-692707.8 HIG—
———Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.9hCVE-2026-785118.8 HIG—
———Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.6hCVE-2026-692688.8 HIG—
———Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.9hCVE-2026-692676.5 MED—
———Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally.6hCVE-2026-785128.8 HIG—
———Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.6hCVE-2026-692668.8 HIG—
———Integer overflow or wraparound in Windows DHCP Server allows an unauthorized attacker to execute code over a network.7hCVE-2026-692657.8 HIG—
———Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.9hCVE-2026-688986.5 MED—
———Out-of-bounds read in Windows iSCSI allows an unauthorized attacker to deny service over a network.6hCVE-2026-688977.0 HIG—
———Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.9hCVE-2026-688967.8 HIG—
———Absolute path traversal in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.9hCVE-2026-688955.5 MED—
———Numeric truncation error in Internet Storage Name Service allows an authorized attacker to disclose information locally.8hCVE-2026-688948.0 HIG—
———Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network.9hCVE-2026-688937.1 HIG—
———Use after free in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges over a network.9hCVE-2026-688927.8 HIG—
———Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.9hCVE-2026-688914.7 MED—
———Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.6hCVE-2026-688907.8 HIG—
———Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.7hCVE-2026-688887.8 HIG—
———Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.9hCVE-2026-688877.5 HIG—
———Out-of-bounds read in Windows Message Queuing Queue Manager allows an unauthorized attacker to deny service over a network.6hCVE-2026-688865.5 MED—
———Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally.6hCVE-2026-688857.8 HIG—
———Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.7h