CVEs whose exploitation probability jumped significantly in the last 24 hours, based on EPSS scores.
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2024-4577 | Argument Injection in PHP-CGI | CRITICAL | 9.8 | 100.0%ile | Microsoft | 2024-06-11 |
| CVE-2023-21554 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | CRITICAL | 9.8 | 99.9%ile | Microsoft | 2023-04-11 |
| CVE-2015-0204 | OSSN-0045: = Vulnerable clients allow a TLS protocol downgrade (FREAK)= | UNKNOWN | — | 99.9%ile | OpenStack | 2026-08-27 |
| CVE-2026-43284 | xfrm: esp: avoid in-place decrypt on shared skb frags | HIGH | 7.8 | 99.8%ile | Microsoft | 2026-05-12 |
| CVE-2026-43500 | rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present | HIGH | 7.8 | 99.8%ile | Microsoft | 2026-05-12 |
| CVE-2023-21769 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | HIGH | 7.5 | 99.8%ile | Microsoft | 2023-04-11 |
| CVE-2023-28302 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | HIGH | 7.5 | 99.8%ile | Microsoft | 2023-04-11 |
| CVE-2026-50522 | Microsoft SharePoint Remote Code Execution Vulnerability | CRITICAL | 9.8 | 99.7%ile | Microsoft | 2026-07-14 |
| CVE-2017-14491 | OSSN-0082: = Heap and Stack based buffer overflows in dnsmasq prior to version 2.78 = | UNKNOWN | — | 99.7%ile | OpenStack | 2026-08-27 |
| CVE-2026-41089 | Windows Netlogon Remote Code Execution Vulnerability | CRITICAL | 9.8 | 99.6%ile | Microsoft | 2026-05-12 |
| CVE-2023-50868 | MITRE: CVE-2023-50868 NSEC3 closest encloser proof can exhaust CPU | HIGH | 7.5 | 99.6%ile | Microsoft | 2024-06-11 |
| CVE-2017-11826 | Microsoft Office Remote Code Execution Vulnerability | UNKNOWN | — | 99.6%ile | Microsoft | 2017-10-10 |
| CVE-2026-45659 | Microsoft SharePoint Remote Code Execution Vulnerability | HIGH | 8.8 | 99.5%ile | Microsoft | 2026-05-12 |
| CVE-2026-42897 | Microsoft Exchange Server Spoofing Vulnerability | HIGH | 8.1 | 99.4%ile | Microsoft | 2026-05-12 |
| CVE-2026-21509 | Microsoft Office Security Feature Bypass Vulnerability | HIGH | 7.8 | 99.4%ile | Microsoft | 2026-01-13 |
| CVE-2026-42945 | NGINX ngx_http_rewrite_module vulnerability | HIGH | 8.1 | 99.3%ile | Microsoft | 2026-05-12 |
| CVE-2024-30088 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 99.3%ile | Microsoft | 2024-06-11 |
| CVE-2017-11802 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 99.3%ile | Microsoft | 2017-10-10 |
| CVE-2017-11809 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 99.3%ile | Microsoft | 2017-10-10 |
| CVE-2017-11771 | Windows Search Remote Code Execution Vulnerability | HIGH | 8.1 | 99.2%ile | Microsoft | 2017-10-10 |
| CVE-2017-11799 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 99.2%ile | Microsoft | 2017-10-10 |
| CVE-2017-11811 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 99.2%ile | Microsoft | 2017-10-10 |
| CVE-2026-45498 | Microsoft Defender Denial of Service Vulnerability | MEDIUM | 4.0 | 99.2%ile | Microsoft | 2026-05-12 |
| CVE-2017-11774 | Microsoft Outlook Security Feature Bypass Vulnerability | UNKNOWN | — | 99.1%ile | Microsoft | 2017-10-10 |
| CVE-2017-11810 | Scripting Engine Memory Corruption Vulnerability | HIGH | 7.5 | 99.0%ile | Microsoft | 2017-10-10 |
| CVE-2023-28425 | CVE-2023-28425 | MEDIUM | 5.5 | 99.0%ile | Microsoft | 2023-04-11 |
| CVE-2026-55040 | Microsoft SharePoint Server Security Feature Bypass Vulnerability | CRITICAL | 9.1 | 98.9%ile | Microsoft | 2026-07-14 |
| CVE-2026-49160 | HTTP.sys Denial of Service Vulnerability | HIGH | 7.5 | 98.9%ile | Microsoft | 2026-06-09 |
| CVE-2026-23918 | Apache HTTP Server: http2: double free and possible RCE on early reset | HIGH | 8.8 | 98.8%ile | Microsoft | 2026-05-12 |
| CVE-2023-28252 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 98.8%ile | Microsoft | 2023-04-11 |
| CVE-2017-11793 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 98.8%ile | Microsoft | 2017-10-10 |
| CVE-2017-11812 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 98.8%ile | Microsoft | 2017-10-10 |
| CVE-2024-30080 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | CRITICAL | 9.8 | 98.7%ile | Microsoft | 2024-06-11 |
| CVE-2023-2033 | Chromium: CVE-2023-2033 Type Confusion in V8 | UNKNOWN | — | 98.6%ile | Microsoft | 2023-04-11 |
| CVE-2025-53778 | Windows NTLM Elevation of Privilege Vulnerability | HIGH | 8.8 | 98.5%ile | Microsoft | 2025-08-12 |
| CVE-2026-45484 | Microsoft SharePoint Elevation of Privilege Vulnerability | HIGH | 8.8 | 98.4%ile | Microsoft | 2026-06-09 |
| CVE-2023-28231 | DHCP Server Service Remote Code Execution Vulnerability | HIGH | 8.8 | 98.4%ile | Microsoft | 2023-04-11 |
| CVE-2026-20963 | Microsoft SharePoint Remote Code Execution Vulnerability | CRITICAL | 9.8 | 98.3%ile | Microsoft | 2026-01-13 |
| CVE-2026-33112 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 98.3%ile | Microsoft | 2026-05-12 |
| CVE-2017-11779 | Windows DNSAPI Remote Code Execution Vulnerability | HIGH | 8.1 | 98.3%ile | Microsoft | 2017-10-10 |
| CVE-2026-49975 | Apache HTTP Server: mod_http2 denial of service | HIGH | 7.5 | 98.3%ile | Microsoft | 2026-06-09 |
| CVE-2024-21907 | VulnCheck: CVE-2024-21907 Improper Handling of Exceptional Conditions in Newtonsoft.Json | UNKNOWN | — | 98.3%ile | Microsoft | 2025-09-09 |
| CVE-2024-5585 | Command injection via array-ish $command parameter of proc_open() (bypass CVE-2024-1874 fix) | HIGH | 8.8 | 98.1%ile | Microsoft | 2024-06-11 |
| CVE-2026-21510 | Windows Shell Security Feature Bypass Vulnerability | HIGH | 8.8 | 97.9%ile | Microsoft | 2026-02-10 |
| CVE-2025-50154 | Microsoft Windows File Explorer Spoofing Vulnerability | MEDIUM | 6.5 | 97.9%ile | Microsoft | 2025-08-12 |
| CVE-2026-56164 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | MEDIUM | 5.3 | 97.9%ile | Microsoft | 2026-07-14 |
| CVE-2024-35250 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 97.8%ile | Microsoft | 2024-06-11 |
| CVE-2017-8717 | Microsoft JET Database Engine Remote Code Execution Vulnerability | HIGH | 7.1 | 97.8%ile | Microsoft | 2017-10-10 |
| CVE-2025-53772 | Web Deploy Remote Code Execution Vulnerability | HIGH | 8.8 | 97.7%ile | Microsoft | 2025-08-12 |
| CVE-2017-8718 | Microsoft JET Database Engine Remote Code Execution Vulnerability | HIGH | 7.1 | 97.7%ile | Microsoft | 2017-10-10 |
| CVE-2026-47291 | HTTP.sys Remote Code Execution Vulnerability | CRITICAL | 9.8 | 97.6%ile | Microsoft | 2026-06-09 |
| CVE-2026-2441 | Chromium: CVE-2026-2441 Use after free in CSS | UNKNOWN | — | 97.6%ile | Microsoft | 2026-02-10 |
| CVE-2017-11825 | Microsoft Office Remote Code Execution Vulnerability | UNKNOWN | — | 97.6%ile | Microsoft | 2017-10-10 |
| CVE-2025-55234 | Windows SMB Elevation of Privilege Vulnerability | HIGH | 8.8 | 97.3%ile | Microsoft | 2025-09-09 |
| CVE-2025-49712 | Microsoft SharePoint Remote Code Execution Vulnerability | HIGH | 8.8 | 97.3%ile | Microsoft | 2025-08-12 |
| CVE-2026-20872 | NTLM Hash Disclosure Spoofing Vulnerability | MEDIUM | 6.5 | 97.3%ile | Microsoft | 2026-01-13 |
| CVE-2017-11816 | Windows GDI Information Disclosure Vulnerability | MEDIUM | 5.5 | 97.3%ile | Microsoft | 2017-10-10 |
| CVE-2026-45502 | Microsoft Exchange Server Information Disclosure Vulnerability | MEDIUM | 5.0 | 97.3%ile | Microsoft | 2026-06-09 |
| CVE-2017-11769 | TRIE Remote Code Execution Vulnerability | MEDIUM | 4.2 | 97.3%ile | Microsoft | 2017-10-10 |
| CVE-2025-54897 | Microsoft SharePoint Remote Code Execution Vulnerability | HIGH | 8.8 | 97.2%ile | Microsoft | 2025-09-09 |
| CVE-2025-54918 | Windows NTLM Elevation of Privilege Vulnerability | HIGH | 8.8 | 97.2%ile | Microsoft | 2025-09-09 |
| CVE-2026-20947 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 97.2%ile | Microsoft | 2026-01-13 |
| CVE-2025-53722 | Windows Remote Desktop Services Denial of Service Vulnerability | HIGH | 7.5 | 97.1%ile | Microsoft | 2025-08-12 |
| CVE-2026-20925 | NTLM Hash Disclosure Spoofing Vulnerability | MEDIUM | 6.5 | 97.1%ile | Microsoft | 2026-01-13 |
| CVE-2017-11762 | Microsoft Graphics Remote Code Execution Vulnerability | HIGH | 8.1 | 96.9%ile | Microsoft | 2017-10-10 |
| CVE-2017-11763 | Microsoft Graphics Remote Code Execution Vulnerability | HIGH | 8.1 | 96.9%ile | Microsoft | 2017-10-10 |
| CVE-2026-58644 | Microsoft SharePoint Remote Code Execution Vulnerability | CRITICAL | 9.8 | 96.7%ile | Microsoft | 2026-07-14 |
| CVE-2026-21513 | MSHTML Framework Security Feature Bypass Vulnerability | HIGH | 8.8 | 96.7%ile | Microsoft | 2026-02-10 |
| CVE-2026-45657 | Windows Kernel Remote Code Execution Vulnerability | CRITICAL | 9.8 | 96.6%ile | Microsoft | 2026-06-09 |
| CVE-2023-28219 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | HIGH | 8.1 | 96.6%ile | Microsoft | 2023-04-11 |
| CVE-2023-28220 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | HIGH | 8.1 | 96.6%ile | Microsoft | 2023-04-11 |
| CVE-2026-85706 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 1 | CRITICAL | 10.0 | 96.5%ile | NVD | 2026-09-12 |
| CVE-2017-11781 | W - SMB - DOS Authenticated | MEDIUM | 5.9 | 96.5%ile | Microsoft | 2017-10-10 |
| CVE-2024-30085 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 96.4%ile | Microsoft | 2024-06-11 |
| CVE-2017-11819 | Windows Shell Remote Code Execution Vulnerability | HIGH | 7.5 | 96.4%ile | Microsoft | 2017-10-10 |
| CVE-2017-11815 | Windows SMB Information Disclosure Vulnerability | MEDIUM | 6.4 | 96.2%ile | Microsoft | 2017-10-10 |
| CVE-2025-53760 | Microsoft SharePoint Elevation of Privilege Vulnerability | HIGH | 7.1 | 96.1%ile | Microsoft | 2025-08-12 |
| CVE-2023-28218 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 96.0%ile | Microsoft | 2023-04-11 |
| CVE-2024-5458 | Filter bypass in filter_var (FILTER_VALIDATE_URL) | MEDIUM | 5.3 | 96.0%ile | Microsoft | 2024-06-11 |
| CVE-2026-20841 | Windows Notepad App Remote Code Execution Vulnerability | HIGH | 7.8 | 95.9%ile | Microsoft | 2026-02-10 |
| CVE-2026-50656 | Microsoft Defender Elevation of Privilege Vulnerability | HIGH | 7.8 | 95.8%ile | Microsoft | 2026-06-09 |
| CVE-2026-21249 | Windows NTLM Spoofing Vulnerability | LOW | 3.3 | 95.7%ile | Microsoft | 2026-02-10 |
| CVE-2026-9256 | NGINX ngx_http_rewrite_module vulnerability | HIGH | 8.1 | 95.6%ile | Microsoft | 2026-05-12 |
| CVE-2017-11780 | Windows SMB Remote Code Execution Vulnerability | HIGH | 8.1 | 95.4%ile | Microsoft | 2017-10-10 |
| CVE-2026-8711 | NGINX JavaScript vulnerability | HIGH | 8.1 | 95.3%ile | Microsoft | 2026-05-12 |
| CVE-2025-50165 | Windows Graphics Component Remote Code Execution Vulnerability | CRITICAL | 9.8 | 95.2%ile | Microsoft | 2025-08-12 |
| CVE-2024-30087 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 95.2%ile | Microsoft | 2024-06-11 |
| CVE-2017-11786 | Skype for Business Elevation of Privilege Vulnerability | UNKNOWN | — | 95.2%ile | Microsoft | 2017-10-10 |
| CVE-2017-11776 | Microsoft Outlook Information Disclosure Vulnerability | UNKNOWN | — | 95.2%ile | Microsoft | 2017-10-10 |
| CVE-2026-46300 | net: skbuff: preserve shared-frag marker during coalescing | HIGH | 7.8 | 95.1%ile | Microsoft | 2026-05-12 |
| CVE-2026-4890 | CVE-2026-4890 | HIGH | 7.5 | 95.0%ile | Microsoft | 2026-05-12 |
| CVE-2026-50508 | Windows NTLM Spoofing Vulnerability | MEDIUM | 6.5 | 94.9%ile | Microsoft | 2026-06-09 |
| CVE-2017-11821 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 94.9%ile | Microsoft | 2017-10-10 |
| CVE-2017-11792 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 94.9%ile | Microsoft | 2017-10-10 |
| CVE-2017-11796 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 94.9%ile | Microsoft | 2017-10-10 |
| CVE-2017-11798 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 94.9%ile | Microsoft | 2017-10-10 |
| CVE-2017-11800 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 94.9%ile | Microsoft | 2017-10-10 |
| CVE-2017-11804 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 94.9%ile | Microsoft | 2017-10-10 |
| CVE-2017-11805 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 94.9%ile | Microsoft | 2017-10-10 |
| CVE-2017-11806 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 94.9%ile | Microsoft | 2017-10-10 |
| CVE-2017-11807 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 94.9%ile | Microsoft | 2017-10-10 |
| CVE-2017-11808 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 94.9%ile | Microsoft | 2017-10-10 |
| CVE-2017-11822 | Internet Explorer Memory Corruption Vulnerability | HIGH | 7.5 | 94.8%ile | Microsoft | 2017-10-10 |
| CVE-2026-0907 | Chromium: CVE-2026-0907 Incorrect security UI in Split View | UNKNOWN | — | 94.8%ile | Microsoft | 2026-01-13 |
| CVE-2025-41244 | VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-202 | HIGH | 7.8 | 94.7%ile | Microsoft | 2025-09-09 |
| CVE-2026-20860 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 94.7%ile | Microsoft | 2026-01-13 |
| CVE-2017-11772 | Microsoft Search Information Disclosure Vulnerability | MEDIUM | 5.9 | 94.7%ile | Microsoft | 2017-10-10 |
| CVE-2026-41091 | Microsoft Defender Elevation of Privilege Vulnerability | HIGH | 7.8 | 94.6%ile | Microsoft | 2026-05-12 |
| CVE-2024-30089 | Microsoft Streaming Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 94.6%ile | Microsoft | 2024-06-11 |
| CVE-2017-8727 | Internet Explorer Memory Corruption Vulnerability | HIGH | 7.5 | 94.6%ile | Microsoft | 2017-10-10 |
| CVE-2025-38562 | ksmbd: fix null pointer dereference error in generate_encryptionkey | MEDIUM | 5.5 | 94.6%ile | Microsoft | 2025-08-12 |
| CVE-2017-11813 | Internet Explorer Memory Corruption Vulnerability | HIGH | 7.5 | 94.5%ile | Microsoft | 2017-10-10 |
| CVE-2026-21527 | Microsoft Exchange Server Spoofing Vulnerability | MEDIUM | 6.5 | 94.5%ile | Microsoft | 2026-02-10 |
| CVE-2025-53786 | Microsoft Exchange Server Hybrid Deployment Elevation of Privilege Vulnerability | HIGH | 8.0 | 94.3%ile | Microsoft | 2025-08-12 |
| CVE-2026-42824 | M365 Copilot Information Disclosure Vulnerability | MEDIUM | 6.5 | 94.3%ile | Microsoft | 2026-06-09 |
| CVE-2026-20959 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 94.2%ile | Microsoft | 2026-01-13 |
| CVE-2026-42508 | Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts | CRITICAL | 9.1 | 94.1%ile | Microsoft | 2026-05-12 |
| CVE-2015-5143 | OSSN-0054: = Potential Denial of Service in Horizon login = | UNKNOWN | — | 94.1%ile | OpenStack | 2026-08-27 |
| CVE-2025-53766 | GDI+ Remote Code Execution Vulnerability | CRITICAL | 9.8 | 94.0%ile | Microsoft | 2025-08-12 |
| CVE-2017-8726 | Microsoft Edge based on Edge HTML Information Disclosure Vulnerability | MEDIUM | 4.3 | 94.0%ile | Microsoft | 2017-10-10 |
| CVE-2026-42980 | NT OS Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 93.8%ile | Microsoft | 2026-06-09 |
| CVE-2025-53143 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | HIGH | 8.8 | 93.7%ile | Microsoft | 2025-08-12 |
| CVE-2023-28274 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 93.7%ile | Microsoft | 2023-04-11 |
| CVE-2025-10891 | Chromium: CVE-2025-10891 Integer overflow in V8 | UNKNOWN | — | 93.7%ile | Microsoft | 2025-09-09 |
| CVE-2026-42055 | NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability | HIGH | 8.1 | 93.5%ile | Microsoft | 2026-06-09 |
| CVE-2023-28227 | Windows Bluetooth Driver Remote Code Execution Vulnerability | HIGH | 7.5 | 93.5%ile | Microsoft | 2023-04-11 |
| CVE-2026-0628 | Chromium: CVE-2026-0628 Insufficient policy enforcement in WebView tag | UNKNOWN | — | 93.5%ile | Microsoft | 2026-01-13 |
| CVE-2025-53144 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | HIGH | 8.8 | 93.4%ile | Microsoft | 2025-08-12 |
| CVE-2025-53145 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | HIGH | 8.8 | 93.4%ile | Microsoft | 2025-08-12 |
| CVE-2026-4891 | CVE-2026-4891 | MEDIUM | 5.3 | 93.4%ile | Microsoft | 2026-05-12 |
| CVE-2023-28288 | Microsoft SharePoint Server Spoofing Vulnerability | HIGH | 8.1 | 93.2%ile | Microsoft | 2023-04-11 |
| CVE-2026-68820 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 93.2%ile | Microsoft | 2026-08-11 |
| CVE-2024-30084 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 92.9%ile | Microsoft | 2024-06-11 |
| CVE-2017-11797 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 92.8%ile | Microsoft | 2017-10-10 |
| CVE-2017-11801 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 92.8%ile | Microsoft | 2017-10-10 |
| CVE-2023-2136 | Chromium: CVE-2023-2136 Integer overflow in Skia | UNKNOWN | — | 92.7%ile | Microsoft | 2023-04-11 |
| CVE-2017-11790 | Internet Explorer Information Disclosure Vulnerability | LOW | 3.1 | 92.5%ile | Microsoft | 2017-10-10 |
| CVE-2026-20817 | Windows Error Reporting Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 92.4%ile | Microsoft | 2026-01-13 |
| CVE-2026-41103 | Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability | CRITICAL | 9.1 | 92.3%ile | Microsoft | 2026-05-12 |
| CVE-2025-10585 | Chromium: CVE-2025-10585 Type Confusion in V8 | UNKNOWN | — | 92.3%ile | Microsoft | 2025-09-09 |
| CVE-2015-3310 | Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when th | UNKNOWN | — | 92.3%ile | Microsoft | 2025-08-12 |
| CVE-2026-66804 | Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 92.2%ile | Microsoft | 2026-08-11 |
| CVE-2017-11794 | Microsoft Edge based on Edge HTML Information Disclosure Vulnerability | MEDIUM | 4.3 | 92.2%ile | Microsoft | 2017-10-10 |
| CVE-2026-20805 | Desktop Window Manager Information Disclosure Vulnerability | MEDIUM | 5.5 | 92.1%ile | Microsoft | 2026-01-13 |
| CVE-2024-30078 | Windows Wi-Fi Driver Remote Code Execution Vulnerability | HIGH | 8.8 | 92.0%ile | Microsoft | 2024-06-11 |
| CVE-2023-1390 | CVE-2023-1390 | HIGH | 7.5 | 92.0%ile | Microsoft | 2023-04-11 |
| CVE-2026-21525 | Windows Remote Access Connection Manager Denial of Service Vulnerability | MEDIUM | 6.2 | 91.9%ile | Microsoft | 2026-02-10 |
| CVE-2026-50507 | Windows BitLocker Security Feature Bypass Vulnerability | MEDIUM | 6.8 | 91.8%ile | Microsoft | 2026-06-09 |
| CVE-2024-5841 | Chromium: CVE-2024-5841 Use after free in V8 | UNKNOWN | — | 91.8%ile | Microsoft | 2024-06-11 |
| CVE-2026-40369 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 91.4%ile | Microsoft | 2026-05-12 |
| CVE-2026-20840 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 91.3%ile | Microsoft | 2026-01-13 |
| CVE-2026-42533 | NGINX Map directive and Regex matching vulnerability | HIGH | 8.1 | 91.0%ile | Microsoft | 2026-07-14 |
| CVE-2026-40364 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 8.4 | 90.9%ile | Microsoft | 2026-05-12 |
| CVE-2023-28266 | Windows Common Log File System Driver Information Disclosure Vulnerability | MEDIUM | 5.5 | 90.8%ile | Microsoft | 2023-04-11 |
| CVE-2026-2314 | Chromium: CVE-2026-2314 Heap buffer overflow in Codecs | UNKNOWN | — | 90.8%ile | Microsoft | 2026-02-10 |
| CVE-2024-30091 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 90.6%ile | Microsoft | 2024-06-11 |
| CVE-2026-2313 | Chromium: CVE-2026-2313 Use after free in CSS | UNKNOWN | — | 90.6%ile | Microsoft | 2026-02-10 |
| CVE-2026-20871 | Desktop Window Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 90.5%ile | Microsoft | 2026-01-13 |
| CVE-2026-76698 | A command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gate | MEDIUM | 6.5 | 90.3%ile | NVD | 2026-09-15 |
| CVE-2025-54110 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 8.8 | 90.2%ile | Microsoft | 2025-09-09 |
| CVE-2026-55200 | libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c | HIGH | 8.1 | 90.1%ile | Microsoft | 2026-06-09 |
Updated 2026-09-18. EPSS = Exploit Prediction Scoring System (FIRST.org). TRENDING = EPSS jumped ≥5 percentage points since yesterday.