PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET Professional
CVE Watch371,173 in full archive

Vulnerabilities exploitable today

371,173in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637

Distribution · last window

  • Critical
    2,229
  • High
    8,582
  • Medium
    6,298
  • Low
    585
Filters

Window

Severity

Flags

Vulnerabilities370,841–370,880 · 371,173
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-713415.5 MED
Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally.10h
CVE-2026-713407.0 HIG
Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.11h
CVE-2026-713396.7 MED
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.11h
CVE-2026-713386.4 MED
Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.11h
CVE-2026-713377.8 HIG
Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.11h
CVE-2026-713368.8 HIG
Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network.9h
CVE-2026-713337.0 HIG
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.11h
CVE-2026-713327.0 HIG
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally.11h
CVE-2026-713307.5 HIG
Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network.8h
CVE-2026-713296.8 MED
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.9h
CVE-2026-713288.8 HIG
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.11h
CVE-2026-705877.5 HIG
Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.8h
CVE-2026-705868.8 HIG
Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code over a network.11h
CVE-2026-705857.0 HIG
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally.11h
CVE-2026-705847.8 HIG
Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally.9h
CVE-2026-705837.8 HIG
Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges locally.11h
CVE-2026-705817.8 HIG
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.11h
CVE-2026-705797.5 HIG
Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose information over a network.9h
CVE-2026-705787.0 HIG
Heap-based buffer overflow in Windows Credential Guard allows an authorized attacker to elevate privileges locally.11h
CVE-2026-705777.0 HIG
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.11h
CVE-2026-705755.3 MED
Null pointer dereference in Windows Schannel allows an authorized attacker to deny service over a network.8h
CVE-2026-705747.8 HIG
Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.11h
CVE-2026-705737.0 HIG
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.11h
CVE-2026-705727.8 HIG
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.11h
CVE-2026-705707.5 HIG
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine11h
CVE-2026-705697.8 HIG
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.11h
CVE-2026-705687.0 HIG
Heap-based buffer overflow in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.11h
CVE-2026-705677.0 HIG
Double free in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.11h
CVE-2026-705657.0 HIG
Use after free in Windows AF_UNIX Socket Provider allows an authorized attacker to elevate privileges locally.11h
CVE-2026-705647.8 HIG
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.11h
CVE-2026-750218.1 HIG
fastify-cli starts the Node.js Inspector when a debug flag is used, but it ignores the explicit bind address the user supplies and binds the Inspector to a broadly reachable address instead of the intended loopback. As a result the debugging interface can be exposed beyond the local machine, and because the Inspector protocol allows arbitrary code evaluation, a remote party that reaches it can achieve remote code execution on the developer's machine. This affects fastify-cli from 1.5.0 up to 8.0.1. Users should upgrade to fastify-cli 8.0.1, which honors the configured Inspector bind address.10h
CVE-2026-733105.9 MED
XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one recorded at authorization time. Attackers can exchange an intercepted authorization code using a mismatched redirect URI to steal OAuth2 tokens from intercepted authorization flows.10h
CVE-2026-733136.8 MED
XenForo before 2.3.13 contains a multi-factor authentication bypass vulnerability in the passkey TFA provider that allows an authenticated attacker to complete login as another user by submitting their own registered passkey credential during the WebAuthn assertion step. The passkey verification path performs a global credential lookup without validating that the matched credential belongs to the user whose login is pending, enabling an attacker who knows a target account's password to sign the challenge with their own passkey and bypass multi-factor authentication on both public forum and ACP login paths.10h
CVE-2026-733158.6 HIG
XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying a crafted certificate URL in webhook headers without scheme, hostname, or allowlist validation. Attackers can submit a crafted POST to the PayPal webhook callback endpoint to reach internal network resources including cloud instance metadata services, potentially disclosing IAM credentials or enabling secondary internal service exploitation.10h
CVE-2026-733167.5 HIG
XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. Attackers can replay a valid webhook payload to trigger duplicate payment events, resulting in repeated subscription activations and unauthorized account upgrades.10h
CVE-2026-705638.1 HIG
Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network.11h
CVE-2026-733196.1 MED
XenForo before 2.3.13 contains a cross-site scripting vulnerability in the dynamic redirect handler that allows unauthenticated attackers to execute arbitrary JavaScript in the board origin by crafting a malicious javascript: URI that bypasses host validation. Attackers can embed the board hostname in the URI authority component and use percent-encoded newlines to evade server-side filters, causing authenticated users who perform a Follow action to execute attacker-supplied JavaScript in their browser.10h
CVE-2026-705627.0 HIG
Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.11h
CVE-2026-703518.8 HIG
Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network.11h
CVE-2026-703428.1 HIG
Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network.9h