Vulnerabilities exploitable today
370,813in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,187
- High8,406
- Medium6,046
- Low572
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-697067.1 HIG—
———Use after free in Windows Win32K allows an authorized attacker to elevate privileges over a network.4hCVE-2026-586117.8 HIG—
———Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.4hCVE-2026-697077.8 HIG—
———Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.4hCVE-2026-586007.8 HIG—
———Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.4hCVE-2026-585997.8 HIG—
———Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.4hCVE-2026-697087.0 HIG—
———Use after free in Windows Web Platform Storage allows an authorized attacker to elevate privileges locally.4hCVE-2026-570997.5 HIG—
———Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.4hCVE-2026-570987.5 HIG—
———Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.4hCVE-2026-561987.8 HIG—
———Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.4hCVE-2026-561777.8 HIG—
———Use after free in Windows Server allows an authorized attacker to elevate privileges locally.4hCVE-2026-561727.8 HIG—
———Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.4hCVE-2026-550078.1 HIG—
———Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.4hCVE-2026-546115.5 MED—
———InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated attackers to execute any PHP code via the component installer. It is possible to upload a malicious component into the server, however, it won't be installed, but upload files will be executed. Normally all php files in upload folder are not executed, however, by uploading custom .htaccess it becomes possible. Version 2.18.2 contains a fix.4hCVE-2026-503497.0 HIG—
———Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.4hCVE-2026-487073.1 LOW—
———InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality (`system/core/uploader.php` at lines 509-532). When the "upload from URL" feature follows an HTTP redirect, the redirected target URL bypasses the private IP address blacklist check. This allows authenticated users to scan and access internal network services. Version 2.18.2 contains a fix.4hCVE-2026-472978.1 HIG—
———Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.4hCVE-2026-866684.3 MED—
———A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation of the argument outerSrc/selectPhoto leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.4hCVE-2026-697097.8 HIG—
———Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.4hCVE-2026-866674.7 MED—
———A weakness has been identified in aircheng-org iWebShop-5 up to 5.15. The affected element is the function member_list of the file controllers/member.php. This manipulation of the argument Search causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.4hCVE-2026-86073——
———n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, the OAuth token endpoint bound an authorization code's first access token to the consented resource but did not bind its refresh token. Refreshing checked only that the requested resource was registered, not that it matched the original grant. An OAuth client approved for one workflow could substitute a different workflow URL in the resource parameter and obtain a valid token for an unapproved workflow accessible to the consenting user. This issue is fixed in versions 2.37.7 and 2.38.1.5hCVE-2026-697107.5 HIG—
———Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally.4hCVE-2026-697117.0 HIG—
———Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.4hCVE-2026-697128.8 HIG—
———Use after free in Windows Key Distribution Center allows an authorized attacker to execute code over a network.4hCVE-2026-697134.4 MED—
———Dependency on vulnerable third-party component in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.4hCVE-2026-697148.0 HIG—
———Stack-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges over a network.4hCVE-2026-697159.8 CRI—
———Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network.4hCVE-2026-843938.1 HIG—
———A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here>4hCVE-2026-697168.8 HIG—
———Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.4hCVE-2026-697178.0 HIG—
———Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privileges over a network.4hCVE-2026-843922.7 LOW—
———A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.6, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an authenticated attacker to crash the httpsd daemon via crafted HTTP requests.4hCVE-2026-697196.5 MED—
———Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.4hCVE-2026-697207.8 HIG—
———Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.4hCVE-2026-697228.8 HIG—
———Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.4hCVE-2026-697235.7 MED—
———Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information over a network.4hCVE-2026-697248.8 HIG—
———Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.4hCVE-2026-843916.5 MED—
———A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here>4hCVE-2026-843893.1 LOW—
———A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or commands via <insert attack vector here>4hCVE-2026-843877.2 HIG—
———A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthorized code or commands via <insert attack vector here>4hCVE-2026-697257.8 HIG—
———Double free in Windows Hello allows an authorized attacker to elevate privileges locally.4hCVE-2026-697278.0 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network.4h