Vulnerabilities exploitable today
371,173in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,229
- High8,582
- Medium6,298
- Low585
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-703347.8 HIG—
———Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.11hCVE-2026-702969.8 CRI—
———Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.11hCVE-2026-702905.5 MED—
———Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally.8hCVE-2026-702897.8 HIG—
———Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.11hCVE-2026-742397.2 HIG—
———XenForo before 2.3.13 contains a path traversal vulnerability in the style archive importer on Windows deployments that allows authenticated non-super administrators with style permissions to write arbitrary files outside the intended extraction directory by using backslash-based traversal sequences in ZIP member names. Attackers can craft a malicious ZIP archive with backslash path separators that bypass forward-slash validation to write arbitrary bytes to any web-server-writable path, including the public web root, achieving persistent code execution as the web-server account.10hCVE-2026-866443.5 LOW—
———A vulnerability was determined in star7th showdoc up to 3.9.1. This vulnerability affects unknown code of the file web_src/public/editor.md/editormd.js of the component API Page Save Endpoint. Executing a manipulation can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 3.9.2 is able to resolve this issue. This patch is called a8ea1520850b4242f395247f72e87e597506cef0. Upgrading the affected component is recommended. The vendor confirms: "The fix [...] sets Mermaid `securityLevel` to `strict`, disables `htmlLabels`, and sanitizes rendered SVG with DOMPurify."11hCVE-2026-11891——
———Use After Free vulnerability in Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access already freed memory.
This issue affects Valhall GPU Userspace Driver: from r46p0 through r49p5, from r50p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Userspace Driver: from r46p0 through r49p5, from r50p0 through r54p3, r55p0.14hCVE-2026-702837.0 HIG—
———Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locally.9hCVE-2026-702038.8 HIG—
———Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.11hCVE-2026-701455.5 MED—
———Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.9hCVE-2026-701245.9 MED—
———Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.8hCVE-2026-700915.9 MED—
———Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over a network.10hCVE-2026-700196.5 MED—
———Windows hard link in Windows Compressed Folder allows an unauthorized attacker to disclose information over a network.8hCVE-2026-699898.1 HIG—
———Use after free in DNS Server allows an unauthorized attacker to execute code over a network.11hCVE-2026-699305.9 MED—
———Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.8hCVE-2026-699217.8 HIG—
———Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.11hCVE-2026-699117.0 HIG—
———Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.11hCVE-2026-699109.8 CRI—
———Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.11hCVE-2026-699077.8 HIG—
———Improper handling of insufficient permissions or privileges in Windows Enterprise App Management allows an authorized attacker to elevate privileges locally.11hCVE-2026-699068.2 HIG—
———Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.9hCVE-2026-188518.8 HIG—
———Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.14hCVE-2026-699043.5 LOW—
———Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.9hCVE-2026-699007.8 HIG—
———Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.11hCVE-2026-698967.0 HIG—
———Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally.11hCVE-2026-615169.8 CRI—
———Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session. Attackers can replay the exposed credential against the login handler to establish a fully authenticated administrator session on the device.10hCVE-2026-698954.7 MED—
———Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.9hCVE-2026-698917.0 HIG—
———Use after free in Windows Media allows an authorized attacker to elevate privileges locally.11hCVE-2026-698907.5 HIG—
———Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate privileges locally.9hCVE-2026-7476——
———Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to access already freed memory.
This issue affects Bifrost GPU Kernel Driver: from r49p3 through r49p5, r51p0, from r54p1 through r54p2; Valhall GPU Kernel Driver: from r49p3 through r49p5, from r51p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Kernel Driver: from r49p3 through r49p5, from r51p0 through r54p3, r55p0.14hCVE-2026-698897.0 HIG—
———Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.11hCVE-2026-698817.5 HIG—
———Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network.8hCVE-2026-698786.4 MED—
———Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code locally.11hCVE-2026-561015.3 MED—
———OpenBSD before commit 1ee99df contains an inverted comparison vulnerability in the ieee80211_michael_mic_failure() function within sys/net80211/ieee80211_crypto_tkip.c that allows unauthenticated attackers within RF range to trigger denial of service by sending two malformed TKIP frames separated by more than 60 seconds. Attackers can exploit the reversed TKIP MIC failure countermeasure window check to deauthenticate all associated TKIP stations and block reassociation for up to 90 seconds, while within-window MIC failures that should engage countermeasures are silently discarded, leaving key-recovery attempts undetected.10hCVE-2026-866008.2 HIG—
———In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify the connection configuration can cause the driver to mint a fresh attestation and send it to a host they control. The captured token can be replayed to Snowflake for its remaining lifetime in accounts where that workload identity is already registered. On Azure, the token audience is also taken from connection configuration. Combined with an attacker-controlled host, the driver can request a Managed Identity access token scoped to a non-Snowflake Azure resource and deliver it to the attacker. That path is the only case in which impact extends beyond Snowflake; it is bounded by the token lifetime and the managed identity’s permissions. Successful exploitation requires WORKLOAD_IDENTITY authentication on a workload that already has an ambient cloud identity. Patched driver versions restrict this authenticator to recognized Snowflake hosts. Users must manually upgrade.10hCVE-2026-698768.0 HIG—
———Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.11hCVE-2026-867266.5 MED—
———AVideo through 29.0 contains an information disclosure vulnerability in restreamsActive.json.php that allows authenticated streamers to enumerate source stream keys and identities of all other streamers' active restreams. The endpoint fails to filter results by user ownership, exposing sensitive transmission credentials and streamer identity across all accounts to any user with streaming capability.10hCVE-2026-698758.0 HIG—
———Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.9hCVE-2026-698748.2 HIG—
———Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally.11hCVE-2026-867297.4 HIG—
———WWBN AVideo through commit e01e41ecc (no patched version available) exposes get_api_preauthorize in plugin/API/API.php as a second, undocumented login path. Unlike get_api_signIn, which enforces a rate limit of 10 attempts per 5 minutes via checkRateLimit(), get_api_preauthorize performs the same credential check with no throttling for any client, allowing unlimited remote password guessing against arbitrary accounts, including admin. The endpoint also acts as a credential oracle: it returns the message "Invalid credentials" for both correct and incorrect passwords, while the users_id field in the response body discloses the authenticated identity (users_id:1 on success, users_id:0 on failure), and a correct password establishes a session cookie that remains usable for authenticated API requests. Together these issues permit unauthenticated brute-force account takeover.10hCVE-2026-867328.8 HIG—
———Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject a malicious class via criteria[withTransforms][0][class] that reaches ImageTransforms::normalizeTransform(), then use a PHP gadget chain with yii\rbac\PhpManager to execute code by pointing itemFile to a request log containing PHP payload in the User-Agent header.10h