Vulnerabilities exploitable today
371,523in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,229
- High8,605
- Medium6,350
- Low586
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-730217.8 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.14hCVE-2026-730207.8 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.15hCVE-2026-730194.3 MED—
———Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network.15hCVE-2026-730188.8 HIG—
———Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.15hCVE-2026-730168.8 HIG—
———Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.6hCVE-2026-730157.8 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.15hCVE-2026-730147.8 HIG—
———Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally.15hCVE-2026-730138.8 HIG—
———Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.15hCVE-2026-730117.8 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.14hCVE-2026-730109.8 CRI—
———Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.15hCVE-2026-730085.5 MED—
———Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally.14hCVE-2026-730027.8 HIG—
———Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.15hCVE-2026-729967.8 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.15hCVE-2026-729917.8 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.15hCVE-2026-729907.8 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.14hCVE-2026-21094——
———Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 allows adjacent attackers to write out-of-bounds memory.5hCVE-2026-21095——
———Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.5hCVE-2026-729868.8 HIG—
———Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.15hCVE-2026-730045.5 MED—
———Missing authentication for critical function in Windows Autopilot allows an authorized attacker to perform tampering locally.15hCVE-2026-730037.0 HIG—
———Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.15hCVE-2026-730017.8 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.14hCVE-2026-730007.8 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.15hCVE-2026-729996.8 MED—
———Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to elevate privileges with a physical attack.15hCVE-2026-21096——
———Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.5hCVE-2026-729977.8 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.15hCVE-2026-21097——
———Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.5hCVE-2026-729957.8 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.14hCVE-2026-729947.8 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.15hCVE-2026-729937.8 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.15hCVE-2026-729927.8 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.15hCVE-2026-729897.5 HIG—
———Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network.14hCVE-2026-729887.8 HIG—
———Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.15hCVE-2026-729878.1 HIG—
———Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.15hCVE-2026-21098——
———Improper access control in Link to Windows prior to SMR Sep-2026 Release 1 allows local attackers to establish a connection with the PC without proper user interaction.5hCVE-2026-729799.8 CRI—
———Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.15hCVE-2026-729776.5 MED—
———Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.14hCVE-2026-729765.0 MED—
———Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally.13hCVE-2026-729756.5 MED—
———Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.14hCVE-2026-729746.5 MED—
———Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.14hCVE-2026-729738.8 HIG—
———Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.6h