Vulnerabilities exploitable today
371,173in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,229
- High8,582
- Medium6,298
- Low586
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-697978.8 HIG—
———Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.9hCVE-2026-698017.8 HIG—
———Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.9hCVE-2026-698035.9 MED—
———Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.7hCVE-2026-698047.5 HIG—
———Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.9hCVE-2026-698057.5 HIG—
———External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.9hCVE-2026-698067.0 HIG—
———Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.9hCVE-2026-694987.0 HIG—
———Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.9hCVE-2026-694976.5 MED—
———Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over a network.6hCVE-2026-694969.8 CRI—
———Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network.7hCVE-2026-694958.8 HIG—
———Heap-based buffer overflow in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.9hCVE-2026-694948.8 HIG—
———Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.9hCVE-2026-694939.8 CRI—
———Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.9hCVE-2026-694927.0 HIG—
———Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.9hCVE-2026-698078.0 HIG—
———Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an authorized attacker to elevate privileges over a network.9hCVE-2026-12611——
———A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive.
This is caused by a race condition in the server when handling RST_STREAM frames and GOAWAY frames sent by the client.
The race condition "resets" the HTTP2Flusher.terminated, previously set to a non-null value, to the null value, allowing entries to be enqueued in the flusher that however will never be processed. These unprocessed entries are the ones that would unblock the write-blocked threads.13hCVE-2026-19203——
———A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling.
This is caused by Jetty accepting a lone LF character as a terminator in parts of chunked request parsing. Depending on the Jetty version and configured HTTP compliance mode, this may occur in chunk extensions, chunk data termination, or trailer termination.12hCVE-2026-62437——
———When guests are terminated, various pieces of cleanup need carrying out.
The cleaning up of PCI devices which were assigned to guests, and the
associated removal of tracking structures for IRQs used by the devices
occurs relatively early in the process. Unfortunately after that point
the guest about to be terminated could cause its device model (DM) to
re-establish such tracking structures, by having it bind one or more IRQs
anew. While some of those tracking structures would still be cleaned up
later on, at least one would not be.8hCVE-2026-733183.8 LOW—
———XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any ACP administrator to access and submit force-agreement forms regardless of their assigned permissions. Attackers can bypass the option permission declared in the navigation configuration to update the global policy last-updated timestamp, forcing all users to re-agree to the privacy policy or terms of service.7hCVE-2026-693045.9 MED—
———Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.7hCVE-2026-693117.0 HIG—
———Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally.8hCVE-2026-693107.0 HIG—
———Use after free in Windows DNS allows an authorized attacker to elevate privileges locally.8hCVE-2026-77089——
———Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.13hCVE-2026-77091——
———DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and Index Store.13hCVE-2026-77092——
———Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor.13hCVE-2026-77097——
———Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.13hCVE-2026-77098——
———Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.13hCVE-2026-77101——
———CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.13hCVE-2026-77102——
———CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.13hCVE-2026-77103——
———CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.13hCVE-2026-77104——
———CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.13hCVE-2026-77105——
———CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.13hCVE-2026-77106——
———Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.13hCVE-2026-79602——
———A guest with a PCI device assigned that has at least a BAR on the IO port
space can trigger a BUG() in Xen.8hCVE-2026-796034.3 MED—
———x86 PV guests can free memory pages while still keeping a stale TLB entry
pointing to them. A TLB flush is only issued by Xen (if needed) when the
page is re-used. Since it's possible for the page to be scrubbed ahead of
the TLB flush, there's a window where a PV guest can modify an already
scrubbed page.8hCVE-2026-333874.6 MED—
———A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required privileges can define a dashboard containing a malicious payload, or a victim can be socially engineered into importing a malicious dashboard. When the victim views or imports the dashboard, the payload executes in their browser context, allowing the attacker to modify application data or disrupt application availability.8hCVE-2026-333887.4 HIG—
———An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges. A remote authenticated user with limited privileges can view a limited subset of the available entries in the Credentials Manager. The actual credential values are not directly visible, but the user can delete entries or edit their properties. An attacker who deletes or edits an entry can disrupt authentication for dependent devices, and one who manipulates an entry's configuration may be able to indirectly obtain the credentials.8hCVE-2026-733216.5 MED—
———XenForo before 2.3.13 contains an uncontrolled recursion vulnerability in the BBCode parser that allows authenticated attackers to cause persistent denial of service by submitting a post with deeply nested BBCode tags. Attackers can craft a single malicious post with sufficient nesting depth to exceed PHP's stack limit, causing fatal errors that repeatedly terminate PHP-FPM workers for all visitors rendering the affected thread.7hCVE-2026-693097.0 HIG—
———Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.8hCVE-2026-333897.5 HIG—
———An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote host's identity, and no option was provided to enable it. A man-in-the-middle attacker positioned between a sensor and a polled device can, during a polling session, impersonate the device and intercept the communication, including the credentials used to access it. The captured credentials can then be replayed to authenticate against the device itself or against other devices sharing the same credentials, allowing the attacker to access and tamper with the device's data and to disrupt its operations.8hCVE-2026-333915.4 MED—
———An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can remotely bypass the intended access control of the web management interface and modify the Smart Polling discovery configuration. This allows the attacker to disrupt the visibility of assets in the monitored network.8h