Vulnerabilities exploitable today
370,813in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,187
- High8,406
- Medium6,046
- Low572
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-676336.5 MED—
———Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.5hCVE-2026-839827.8 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.5hCVE-2026-676318.8 HIG—
———Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.5hCVE-2026-676306.5 MED—
———Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.5hCVE-2026-676296.5 MED—
———Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.5hCVE-2026-839837.8 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.5hCVE-2026-839857.8 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.5hCVE-2026-676246.5 MED—
———Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.5hCVE-2026-673936.5 MED—
———Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.5hCVE-2026-673906.5 MED—
———Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.5hCVE-2026-839867.8 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.5hCVE-2026-673896.5 MED—
———Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.5hCVE-2026-673888.8 HIG—
———Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.5hCVE-2026-839877.8 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.5hCVE-2026-673866.5 MED—
———Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.5hCVE-2026-839887.8 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.5hCVE-2026-673858.8 HIG—
———Use after free in SQL Server allows an authorized attacker to execute code over a network.5hCVE-2026-839897.5 HIG—
———Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.5hCVE-2026-673848.8 HIG—
———Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.5hCVE-2026-839907.8 HIG—
———Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.5hCVE-2026-839915.5 MED—
———Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.5hCVE-2026-673836.5 MED—
———Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.5hCVE-2026-673818.8 HIG—
———Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.5hCVE-2026-673808.8 HIG—
———Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.5hCVE-2026-673798.5 HIG—
———Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.5hCVE-2026-673788.5 HIG—
———Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.5hCVE-2026-839928.8 HIG—
———Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.5hCVE-2026-673767.5 HIG—
———Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.5hCVE-2026-673738.8 HIG—
———Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.5hCVE-2026-839957.8 HIG—
———Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.5hCVE-2026-673708.8 HIG—
———Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.5hCVE-2026-839968.8 HIG—
———Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.5hCVE-2026-673696.5 MED—
———Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.5hCVE-2026-839978.1 HIG—
———Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.5hCVE-2026-839988.8 HIG—
———Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.5hCVE-2026-839997.0 HIG—
———Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.5hCVE-2026-840007.8 HIG—
———Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.5hCVE-2026-840017.5 HIG—
———Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network.5hCVE-2026-840037.4 HIG—
———Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.5hCVE-2026-673688.8 HIG—
———Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.5h