Vulnerabilities exploitable today
370,813in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,187
- High8,406
- Medium6,046
- Low572
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-627448.8 HIG—
———Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.2hCVE-2026-627597.5 HIG—
———Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.2hCVE-2026-627626.5 MED—
———Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.2hCVE-2026-628016.5 MED—
———Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network.2hCVE-2026-628047.8 HIG—
———External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.2hCVE-2026-628107.8 HIG—
———Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.2hCVE-2026-628137.5 HIG—
———Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.2hCVE-2026-628958.8 HIG—
———Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.2hCVE-2026-649186.5 MED—
———Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network.2hCVE-2026-656699.6 CRI—
———Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.2hCVE-2026-657728.8 HIG—
———Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.2hCVE-2026-658126.8 MED—
———Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.2hCVE-2026-668148.8 HIG—
———Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.2h