Vulnerabilities exploitable today
371,173in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,229
- High8,582
- Medium6,298
- Low585
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-713415.5 MED—
———Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally.10hCVE-2026-713407.0 HIG—
———Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.11hCVE-2026-713396.7 MED—
———Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.11hCVE-2026-713386.4 MED—
———Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.11hCVE-2026-713377.8 HIG—
———Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.11hCVE-2026-713368.8 HIG—
———Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network.9hCVE-2026-713337.0 HIG—
———Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.11hCVE-2026-713327.0 HIG—
———Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally.11hCVE-2026-713307.5 HIG—
———Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network.8hCVE-2026-713296.8 MED—
———Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.9hCVE-2026-713288.8 HIG—
———Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.11hCVE-2026-705877.5 HIG—
———Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.8hCVE-2026-705868.8 HIG—
———Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code over a network.11hCVE-2026-705857.0 HIG—
———Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally.11hCVE-2026-705847.8 HIG—
———Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally.9hCVE-2026-705837.8 HIG—
———Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges locally.11hCVE-2026-705817.8 HIG—
———Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.11hCVE-2026-705797.5 HIG—
———Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose information over a network.9hCVE-2026-705787.0 HIG—
———Heap-based buffer overflow in Windows Credential Guard allows an authorized attacker to elevate privileges locally.11hCVE-2026-705777.0 HIG—
———Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.11hCVE-2026-705755.3 MED—
———Null pointer dereference in Windows Schannel allows an authorized attacker to deny service over a network.8hCVE-2026-705747.8 HIG—
———Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.11hCVE-2026-705737.0 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.11hCVE-2026-705727.8 HIG—
———Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.11hCVE-2026-705707.5 HIG—
———Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine11hCVE-2026-705697.8 HIG—
———Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.11hCVE-2026-705687.0 HIG—
———Heap-based buffer overflow in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.11hCVE-2026-705677.0 HIG—
———Double free in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.11hCVE-2026-705657.0 HIG—
———Use after free in Windows AF_UNIX Socket Provider allows an authorized attacker to elevate privileges locally.11hCVE-2026-705647.8 HIG—
———Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.11hCVE-2026-750218.1 HIG—
———fastify-cli starts the Node.js Inspector when a debug flag is used, but it ignores the explicit bind address the user supplies and binds the Inspector to a broadly reachable address instead of the intended loopback. As a result the debugging interface can be exposed beyond the local machine, and because the Inspector protocol allows arbitrary code evaluation, a remote party that reaches it can achieve remote code execution on the developer's machine. This affects fastify-cli from 1.5.0 up to 8.0.1. Users should upgrade to fastify-cli 8.0.1, which honors the configured Inspector bind address.10hCVE-2026-733105.9 MED—
———XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one recorded at authorization time. Attackers can exchange an intercepted authorization code using a mismatched redirect URI to steal OAuth2 tokens from intercepted authorization flows.10hCVE-2026-733136.8 MED—
———XenForo before 2.3.13 contains a multi-factor authentication bypass vulnerability in the passkey TFA provider that allows an authenticated attacker to complete login as another user by submitting their own registered passkey credential during the WebAuthn assertion step. The passkey verification path performs a global credential lookup without validating that the matched credential belongs to the user whose login is pending, enabling an attacker who knows a target account's password to sign the challenge with their own passkey and bypass multi-factor authentication on both public forum and ACP login paths.10hCVE-2026-733158.6 HIG—
———XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying a crafted certificate URL in webhook headers without scheme, hostname, or allowlist validation. Attackers can submit a crafted POST to the PayPal webhook callback endpoint to reach internal network resources including cloud instance metadata services, potentially disclosing IAM credentials or enabling secondary internal service exploitation.10hCVE-2026-733167.5 HIG—
———XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. Attackers can replay a valid webhook payload to trigger duplicate payment events, resulting in repeated subscription activations and unauthorized account upgrades.10hCVE-2026-705638.1 HIG—
———Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network.11hCVE-2026-733196.1 MED—
———XenForo before 2.3.13 contains a cross-site scripting vulnerability in the dynamic redirect handler that allows unauthenticated attackers to execute arbitrary JavaScript in the board origin by crafting a malicious javascript: URI that bypasses host validation. Attackers can embed the board hostname in the URI authority component and use percent-encoded newlines to evade server-side filters, causing authenticated users who perform a Follow action to execute attacker-supplied JavaScript in their browser.10hCVE-2026-705627.0 HIG—
———Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.11hCVE-2026-703518.8 HIG—
———Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network.11hCVE-2026-703428.1 HIG—
———Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network.9h