PULSE
LIVE22signals / 24h
FEED
ransomkairos reclama a LR Reed · AU · Business Servicesransomnova reclama a VNSO · Not Foundransomblacknevas reclama a Zuni Shopping Center, Inc. · US · Consumer Servicesransomqilin reclama a P & A Construction · US · Constructionransombraincipher reclama a windiam.com · Technologyransomqilin reclama a Primeline Logistics · IE · Transportation/Logisticsransomqilin reclama a Recsa · CR · Not Foundransomqilin reclama a Salida Union School District · US · Educationransomchaos reclama a neopharmlabs.com · US · Healthcareransomqilin reclama a Cpcg · BR · Not Foundransomqilin reclama a EFU Life Assurance · PK · Financial Servicesransomqilin reclama a Infina Health · Healthcareransomm3rx reclama a ubfreight.com · Transportation/Logisticsransomkrybit reclama a dhli.in · IN · Not Foundransomkairos reclama a LR Reed · AU · Business Servicesransomnova reclama a VNSO · Not Foundransomblacknevas reclama a Zuni Shopping Center, Inc. · US · Consumer Servicesransomqilin reclama a P & A Construction · US · Constructionransombraincipher reclama a windiam.com · Technologyransomqilin reclama a Primeline Logistics · IE · Transportation/Logisticsransomqilin reclama a Recsa · CR · Not Foundransomqilin reclama a Salida Union School District · US · Educationransomchaos reclama a neopharmlabs.com · US · Healthcareransomqilin reclama a Cpcg · BR · Not Foundransomqilin reclama a EFU Life Assurance · PK · Financial Servicesransomqilin reclama a Infina Health · Healthcareransomm3rx reclama a ubfreight.com · Transportation/Logisticsransomkrybit reclama a dhli.in · IN · Not Found
CVE Watch351,837 in full archive

Vulnerabilities exploitable today

8,311in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,651
New KEV · 24H0
Exploit Today ≥ 701,587

Distribution · last window

  • Critical
    1,811
  • High
    5,855
  • Medium
    4,717
  • Low
    452
Filters

Window

Severity

Flags

Vulnerabilities3,841–3,880 · 8,311
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-503357.8 HIG
19.9%
6Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.6h
CVE-2026-503345.5 MED
27.7%
8Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally.6h
CVE-2026-503327.8 HIG
28.0%
8Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.6h
CVE-2026-503317.8 HIG
15.1%
5Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.6h
CVE-2026-503307.5 HIG
62.5%
19Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.6h
CVE-2026-503297.8 HIG
75.4%
23Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.6h
CVE-2026-503287.5 HIG
64.2%
19Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.2d
CVE-2026-503277.8 HIG
27.0%
8Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.6h
CVE-2026-503267.8 HIG
23.2%
7Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.6h
CVE-2026-503245.9 MED
52.0%
16Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.6h
CVE-2026-503227.0 HIG
8.7%
3Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.6h
CVE-2026-503217.8 HIG
5.0%
1Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.6h
CVE-2026-503177.8 HIG
9.9%
3Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to elevate privileges locally.6h
CVE-2026-503157.8 HIG
23.2%
7Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.6h
CVE-2026-503147.8 HIG
34.6%
10Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.6d
CVE-2026-503137.8 HIG
35.3%
11Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.6h
CVE-2026-503124.7 MED
24.9%
7Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.6h
CVE-2026-503104.7 MED
21.8%
7Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.6h
CVE-2026-503097.8 HIG
15.1%
5Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.6h
CVE-2026-503077.0 HIG
10.1%
3Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.6h
CVE-2026-503067.8 HIG
15.1%
5Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.6h
CVE-2026-503057.8 HIG
8.2%
2Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.6h
CVE-2026-503047.5 HIG
61.3%
18Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.6h
CVE-2026-503024.2 MED
14.7%
4Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.6h
CVE-2026-503017.8 HIG
22.4%
7Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.6d
CVE-2026-40186.4 MED
0.6%
0TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local access and with the PROCMGR_AID_TRACE ability, to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel.7d
CVE-2026-40177.4 HIG
2.1%
1Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with local access to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel.7d
CVE-2026-491775.5 MED
21.9%
7Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.6h
CVE-2026-485805.5 MED
36.3%
11Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.7d
CVE-2026-483687.8 HIG
7.8%
2Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.7d
CVE-2026-483657.8 HIG
7.8%
2Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.7d
CVE-2026-483097.8 HIG
6.2%
2Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.7d
CVE-2026-479695.5 MED
9.7%
3Audition is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.7d
CVE-2026-479687.8 HIG
8.8%
3Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.8d
CVE-2026-479677.8 HIG
8.7%
3Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.8d
CVE-2026-476427.8 HIG
31.6%
9Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.6d
CVE-2026-472958.8 HIG
56.4%
17Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.5h
CVE-2026-472907.8 HIG
31.6%
9Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.6d
CVE-2026-457567.5 HIG
43.5%
13Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.3.0-BETA1 until 7.4.12 and 8.0.12, the JsonPath component compiles attacker-controlled match() and search() filter patterns directly into preg_match() without a length cap, i-regexp restriction, or bounded backtracking, allowing catastrophic-backtracking expressions to pin worker CPU and cause denial of service. This issue is fixed in versions 7.4.12 and 8.0.12.1d
CVE-2026-450778.6 HIG
36.3%
11Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911 by default and processes each received frame with unserialize(base64_decode($message)) without authentication, integrity checks, or an allowed_classes allowlist, allowing any reachable host to submit attacker-chosen serialized PHP payloads that can crash the listener and may trigger object-injection gadget effects. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.7d