CVEs whose exploitation probability jumped significantly in the last 24 hours, based on EPSS scores.
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2025-53770 | Microsoft SharePoint Server Remote Code Execution Vulnerability | CRITICAL | 9.8 | 100.0%ile | Microsoft | 2025-07-08 |
| CVE-2025-49704 | Microsoft SharePoint Remote Code Execution Vulnerability | HIGH | 8.8 | 100.0%ile | Microsoft | 2025-07-08 |
| CVE-2025-53771 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 6.5 | 100.0%ile | Microsoft | 2025-07-08 |
| CVE-2025-49706 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 6.5 | 100.0%ile | Microsoft | 2025-07-08 |
| CVE-2026-43284 | xfrm: esp: avoid in-place decrypt on shared skb frags | HIGH | 7.8 | 99.8%ile | Microsoft | 2026-05-12 |
| CVE-2026-43500 | rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present | HIGH | 7.8 | 99.8%ile | Microsoft | 2026-05-12 |
| CVE-2023-21547 | Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability | HIGH | 7.5 | 99.8%ile | Microsoft | 2023-01-10 |
| CVE-2023-21758 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | HIGH | 7.5 | 99.8%ile | Microsoft | 2023-01-10 |
| CVE-2024-27316 | Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames | HIGH | 7.5 | 99.8%ile | Microsoft | 2024-04-09 |
| CVE-2023-45288 | HTTP/2 CONTINUATION flood in net/http | HIGH | 7.5 | 99.8%ile | Microsoft | 2024-04-09 |
| CVE-2024-2961 | The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 | HIGH | 7.3 | 99.8%ile | Microsoft | 2024-04-09 |
| CVE-2026-31431 | crypto: algif_aead - Revert to operating out-of-place | MEDIUM | 5.5 | 99.8%ile | Microsoft | 2026-04-14 |
| CVE-2024-27983 | An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets | HIGH | 8.2 | 99.7%ile | Microsoft | 2024-04-09 |
| CVE-2024-26256 | Libarchive Remote Code Execution Vulnerability | HIGH | 7.8 | 99.7%ile | Microsoft | 2024-04-09 |
| CVE-2024-30044 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 7.2 | 99.7%ile | Microsoft | 2024-05-14 |
| CVE-2024-28182 | Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usage | MEDIUM | 5.3 | 99.7%ile | Microsoft | 2024-04-09 |
| CVE-2025-49844 | Security Advisory 0139 | UNKNOWN | — | 99.7%ile | Arista | 2026-05-18 |
| CVE-2026-41089 | Windows Netlogon Remote Code Execution Vulnerability | CRITICAL | 9.8 | 99.6%ile | Microsoft | 2026-05-12 |
| CVE-2023-50868 | MITRE: CVE-2023-50868 NSEC3 closest encloser proof can exhaust CPU | HIGH | 7.5 | 99.6%ile | Microsoft | 2024-06-11 |
| CVE-2026-50522 | Microsoft SharePoint Remote Code Execution Vulnerability | CRITICAL | 9.8 | 99.5%ile | Microsoft | 2026-07-14 |
| CVE-2025-6965 | Integer Truncation on SQLite | CRITICAL | 9.8 | 99.5%ile | Microsoft | 2025-07-08 |
| CVE-2026-21509 | Microsoft Office Security Feature Bypass Vulnerability | HIGH | 7.8 | 99.4%ile | Microsoft | 2026-01-13 |
| CVE-2023-22458 | Integer overflow in multiple Redis commands can lead to denial-of-service | MEDIUM | 5.5 | 99.4%ile | Microsoft | 2023-01-10 |
| CVE-2026-42897 | Microsoft Exchange Server Spoofing Vulnerability | HIGH | 8.1 | 99.3%ile | Microsoft | 2026-05-12 |
| CVE-2024-30088 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 99.3%ile | Microsoft | 2024-06-11 |
| CVE-2023-21768 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 99.2%ile | Microsoft | 2023-01-10 |
| CVE-2026-42945 | NGINX ngx_http_rewrite_module vulnerability | HIGH | 8.1 | 99.1%ile | Microsoft | 2026-05-12 |
| CVE-2025-29971 | Web Threat Defense (WTD.sys) Denial of Service Vulnerability | HIGH | 7.5 | 99.1%ile | Microsoft | 2025-05-13 |
| CVE-2024-26212 | DHCP Server Service Denial of Service Vulnerability | HIGH | 7.5 | 99.1%ile | Microsoft | 2024-04-09 |
| CVE-2026-32202 | Windows Shell Spoofing Vulnerability | MEDIUM | 4.3 | 99.1%ile | Microsoft | 2026-04-14 |
| CVE-2026-45498 | Microsoft Defender Denial of Service Vulnerability | MEDIUM | 4.0 | 99.1%ile | Microsoft | 2026-05-12 |
| CVE-2022-37436 | Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting | MEDIUM | 5.3 | 99.0%ile | Microsoft | 2023-01-10 |
| CVE-2026-33824 | Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability | CRITICAL | 9.8 | 98.9%ile | Microsoft | 2026-04-14 |
| CVE-2023-21742 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 98.9%ile | Microsoft | 2023-01-10 |
| CVE-2023-22809 | In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen | HIGH | 7.8 | 98.9%ile | Microsoft | 2023-01-10 |
| CVE-2026-49160 | HTTP.sys Denial of Service Vulnerability | HIGH | 7.5 | 98.9%ile | Microsoft | 2026-06-09 |
| CVE-2024-30043 | Microsoft SharePoint Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 98.9%ile | Microsoft | 2024-05-14 |
| CVE-2024-2511 | Unbounded memory growth with session handling in TLSv1.3 | MEDIUM | 5.9 | 98.9%ile | Microsoft | 2024-04-09 |
| CVE-2026-23918 | Apache HTTP Server: http2: double free and possible RCE on early reset | HIGH | 8.8 | 98.8%ile | Microsoft | 2026-05-12 |
| CVE-2022-3736 | named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queries | HIGH | 7.5 | 98.8%ile | Microsoft | 2023-01-10 |
| CVE-2024-29988 | SmartScreen Prompt Security Feature Bypass Vulnerability | HIGH | 8.8 | 98.7%ile | Microsoft | 2024-04-09 |
| CVE-2024-30080 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | CRITICAL | 9.8 | 98.6%ile | Microsoft | 2024-06-11 |
| CVE-2022-41903 | Integer overflow in `git archive` `git log --format` leading to RCE in git | CRITICAL | 9.8 | 98.6%ile | Microsoft | 2023-01-10 |
| CVE-2023-21674 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | HIGH | 8.8 | 98.6%ile | Microsoft | 2023-01-10 |
| CVE-2023-21887 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versions that are affecte | MEDIUM | 4.9 | 98.6%ile | Microsoft | 2023-01-10 |
| CVE-2026-34486 | Apache Tomcat Missing Encryption of Sensitive Data Vulnerability | HIGH | — | 98.6%ile | CISA-KEV | 2026-08-04 |
| CVE-2024-2756 | __Host-/__Secure- cookie bypass due to partial CVE-2022-31629 fix | MEDIUM | 6.5 | 98.4%ile | Microsoft | 2024-04-09 |
| CVE-2022-35977 | Integer overflow in certain command arguments can drive Redis to OOM panic | MEDIUM | 5.5 | 98.4%ile | Microsoft | 2023-01-10 |
| CVE-2026-45484 | Microsoft SharePoint Elevation of Privilege Vulnerability | HIGH | 8.8 | 98.3%ile | Microsoft | 2026-06-09 |
| CVE-2024-1874 | Command injection via array-ish $command parameter of proc_open() | CRITICAL | 9.4 | 98.2%ile | Microsoft | 2024-04-09 |
| CVE-2024-21907 | VulnCheck: CVE-2024-21907 Improper Handling of Exceptional Conditions in Newtonsoft.Json | UNKNOWN | — | 98.2%ile | Microsoft | 2025-09-09 |
| CVE-2026-20963 | Microsoft SharePoint Remote Code Execution Vulnerability | CRITICAL | 9.8 | 98.0%ile | Microsoft | 2026-01-13 |
| CVE-2024-32002 | GitHub: CVE-2024-32002 Recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote | CRITICAL | 9.0 | 98.0%ile | Microsoft | 2024-05-14 |
| CVE-2024-4323 | Fluent Bit Memory Corruption Vulnerability | CRITICAL | 9.8 | 97.9%ile | Microsoft | 2024-05-14 |
| CVE-2023-52755 | ksmbd: fix slab out of bounds write in smb_inherit_dacl() | HIGH | 8.4 | 97.9%ile | Microsoft | 2024-05-14 |
| CVE-2026-49975 | Apache HTTP Server: mod_http2 denial of service | HIGH | 7.5 | 97.9%ile | Microsoft | 2026-06-09 |
| CVE-2025-47981 | SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | CRITICAL | 9.8 | 97.7%ile | Microsoft | 2025-07-08 |
| CVE-2024-35250 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 97.7%ile | Microsoft | 2024-06-11 |
| CVE-2026-20945 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 97.7%ile | Microsoft | 2026-04-14 |
| CVE-2024-27322 | R Language Vulnerable to Arbitrary Code Execution via Malicious RDS Files (v1.4.0–<4.4.0) | HIGH | 8.8 | 97.6%ile | Microsoft | 2024-04-09 |
| CVE-2024-26230 | Windows Telephony Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 97.6%ile | Microsoft | 2024-04-09 |
| CVE-2025-30394 | Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | MEDIUM | 5.9 | 97.6%ile | Microsoft | 2025-05-13 |
| CVE-2026-47291 | HTTP.sys Remote Code Execution Vulnerability | CRITICAL | 9.8 | 97.5%ile | Microsoft | 2026-06-09 |
| CVE-2026-56164 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | MEDIUM | 5.3 | 97.5%ile | Microsoft | 2026-07-14 |
| CVE-2025-30397 | Scripting Engine Memory Corruption Vulnerability | HIGH | 7.5 | 97.4%ile | Microsoft | 2025-05-13 |
| CVE-2026-32201 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 6.5 | 97.4%ile | Microsoft | 2026-04-14 |
| CVE-2024-24576 | Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows | CRITICAL | 10.0 | 97.2%ile | Microsoft | 2024-04-09 |
| CVE-2026-45502 | Microsoft Exchange Server Information Disclosure Vulnerability | MEDIUM | 5.0 | 97.2%ile | Microsoft | 2026-06-09 |
| CVE-2025-54918 | Windows NTLM Elevation of Privilege Vulnerability | HIGH | 8.8 | 97.0%ile | Microsoft | 2025-09-09 |
| CVE-2025-55234 | Windows SMB Elevation of Privilege Vulnerability | HIGH | 8.8 | 97.0%ile | Microsoft | 2025-09-09 |
| CVE-2026-20872 | NTLM Hash Disclosure Spoofing Vulnerability | MEDIUM | 6.5 | 97.0%ile | Microsoft | 2026-01-13 |
| CVE-2024-29990 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | CRITICAL | 9.0 | 96.9%ile | Microsoft | 2024-04-09 |
| CVE-2026-20947 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 96.9%ile | Microsoft | 2026-01-13 |
| CVE-2025-54897 | Microsoft SharePoint Remote Code Execution Vulnerability | HIGH | 8.8 | 96.9%ile | Microsoft | 2025-09-09 |
| CVE-2026-20925 | NTLM Hash Disclosure Spoofing Vulnerability | MEDIUM | 6.5 | 96.8%ile | Microsoft | 2026-01-13 |
| CVE-2022-3924 | named configured to answer from stale cache may terminate unexpectedly at recursive-clients soft quota | HIGH | 7.5 | 96.6%ile | Microsoft | 2023-01-10 |
| CVE-2026-45657 | Windows Kernel Remote Code Execution Vulnerability | CRITICAL | 9.8 | 96.5%ile | Microsoft | 2026-06-09 |
| CVE-2024-4947 | Chromium: CVE-2024-4947 Type Confusion in V8 | UNKNOWN | — | 96.4%ile | Microsoft | 2024-05-14 |
| CVE-2024-3833 | Chromium: CVE-2024-3833 Object corruption in WebAssembly | UNKNOWN | — | 96.4%ile | Microsoft | 2024-04-09 |
| CVE-2024-26209 | Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | MEDIUM | 5.5 | 96.3%ile | Microsoft | 2024-04-09 |
| CVE-2024-30085 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 96.2%ile | Microsoft | 2024-06-11 |
| CVE-2025-47984 | Windows GDI Information Disclosure Vulnerability | HIGH | 7.5 | 96.2%ile | Microsoft | 2025-07-08 |
| CVE-2022-3094 | An UPDATE message flood may cause named to exhaust all available memory | HIGH | 7.5 | 96.0%ile | Microsoft | 2023-01-10 |
| CVE-2024-26218 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 95.9%ile | Microsoft | 2024-04-09 |
| CVE-2024-3156 | Chromium: CVE-2024-3156 Inappropriate implementation in V8 | UNKNOWN | — | 95.9%ile | Microsoft | 2024-04-09 |
| CVE-2024-26158 | Microsoft Install Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 95.8%ile | Microsoft | 2024-04-09 |
| CVE-2025-40775 | DNS message with invalid TSIG causes an assertion failure | HIGH | 7.5 | 95.8%ile | Microsoft | 2025-05-13 |
| CVE-2024-30050 | Windows Mark of the Web Security Feature Bypass Vulnerability | MEDIUM | 5.4 | 95.6%ile | Microsoft | 2024-05-14 |
| CVE-2026-50518 | Windows DHCP Server Remote Code Execution Vulnerability | CRITICAL | 9.8 | 95.5%ile | Microsoft | 2026-07-14 |
| CVE-2026-40372 | ASP.NET Core Elevation of Privilege Vulnerability | CRITICAL | 9.1 | 95.5%ile | Microsoft | 2026-04-14 |
| CVE-2025-37924 | ksmbd: fix use-after-free in kerberos authentication | HIGH | 7.8 | 95.5%ile | Microsoft | 2025-05-13 |
| CVE-2024-4761 | Chromium: CVE-2024-4761 Out of bounds write in V8 | UNKNOWN | — | 95.5%ile | Microsoft | 2024-05-14 |
| CVE-2026-50656 | Microsoft Defender Elevation of Privilege Vulnerability | HIGH | 7.8 | 95.4%ile | Microsoft | 2026-06-09 |
| CVE-2025-29962 | Windows Media Remote Code Execution Vulnerability | HIGH | 8.8 | 95.3%ile | Microsoft | 2025-05-13 |
| CVE-2026-9256 | NGINX ngx_http_rewrite_module vulnerability | HIGH | 8.1 | 95.2%ile | Microsoft | 2026-05-12 |
| CVE-2025-49719 | Microsoft SQL Server Information Disclosure Vulnerability | HIGH | 7.5 | 95.2%ile | Microsoft | 2025-07-08 |
| CVE-2024-5274 | Chromium: CVE-2024-5274 Type Confusion in V8 | UNKNOWN | — | 95.1%ile | Microsoft | 2024-05-14 |
| CVE-2026-41091 | Microsoft Defender Elevation of Privilege Vulnerability | HIGH | 7.8 | 95.0%ile | Microsoft | 2026-05-12 |
| CVE-2024-30087 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 95.0%ile | Microsoft | 2024-06-11 |
| CVE-2024-26229 | Windows CSC Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 94.9%ile | Microsoft | 2024-04-09 |
| CVE-2026-45659 | Microsoft SharePoint Remote Code Execution Vulnerability | HIGH | 8.8 | 94.8%ile | Microsoft | 2026-05-12 |
| CVE-2025-6558 | Chromium: CVE-2025-6558 Incorrect validation of untrusted input in ANGLE and GPU | UNKNOWN | — | 94.8%ile | Microsoft | 2025-07-08 |
| CVE-2025-7656 | Chromium: CVE-2025-7656 Integer overflow in V8 | UNKNOWN | — | 94.8%ile | Microsoft | 2025-07-08 |
| CVE-2024-4058 | Chromium: CVE-2024-4058 Type Confusion in ANGLE | UNKNOWN | — | 94.7%ile | Microsoft | 2024-04-09 |
| CVE-2026-50508 | Windows NTLM Spoofing Vulnerability | MEDIUM | 6.5 | 94.6%ile | Microsoft | 2026-06-09 |
| CVE-2025-6554 | Chromium: CVE-2025-6554 Type Confusion in V8 | UNKNOWN | — | 94.6%ile | Microsoft | 2025-07-08 |
| CVE-2024-4671 | Chromium: CVE-2024-4671 Use after free in Visuals | UNKNOWN | — | 94.4%ile | Microsoft | 2024-05-14 |
| CVE-2026-20860 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 94.2%ile | Microsoft | 2026-01-13 |
| CVE-2024-30089 | Microsoft Streaming Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 94.2%ile | Microsoft | 2024-06-11 |
| CVE-2025-41244 | VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-202 | HIGH | 7.8 | 94.1%ile | Microsoft | 2025-09-09 |
| CVE-2026-42824 | M365 Copilot Information Disclosure Vulnerability | MEDIUM | 6.5 | 94.0%ile | Microsoft | 2026-06-09 |
| CVE-2026-0907 | Chromium: CVE-2026-0907 Incorrect security UI in Split View | UNKNOWN | — | 94.0%ile | Microsoft | 2026-01-13 |
| CVE-2026-4890 | CVE-2026-4890 | HIGH | 7.5 | 93.7%ile | Microsoft | 2026-05-12 |
| CVE-2025-49724 | Windows Connected Devices Platform Service Remote Code Execution Vulnerability | HIGH | 8.8 | 93.5%ile | Microsoft | 2025-07-08 |
| CVE-2026-46300 | net: skbuff: preserve shared-frag marker during coalescing | HIGH | 7.8 | 93.5%ile | Microsoft | 2026-05-12 |
| CVE-2026-42980 | NT OS Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 93.5%ile | Microsoft | 2026-06-09 |
| CVE-2026-20959 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 93.5%ile | Microsoft | 2026-01-13 |
| CVE-2024-3566 | Command injection vulnerability in programing languages on Microsoft Windows operating system. | CRITICAL | 9.8 | 93.4%ile | Microsoft | 2024-04-09 |
| CVE-2024-30034 | Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | MEDIUM | 5.5 | 93.4%ile | Microsoft | 2024-05-14 |
| CVE-2026-33825 | Microsoft Defender Elevation of Privilege Vulnerability | HIGH | 7.8 | 93.3%ile | Microsoft | 2026-04-14 |
| CVE-2022-41953 | Git clone remote code execution vulnerability in git-for-windows | HIGH | 7.8 | 93.3%ile | Microsoft | 2023-01-10 |
| CVE-2025-10891 | Chromium: CVE-2025-10891 Integer overflow in V8 | UNKNOWN | — | 93.2%ile | Microsoft | 2025-09-09 |
| CVE-2026-0628 | Chromium: CVE-2026-0628 Insufficient policy enforcement in WebView tag | UNKNOWN | — | 93.1%ile | Microsoft | 2026-01-13 |
| CVE-2022-4379 | A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allow | HIGH | 7.5 | 92.9%ile | Microsoft | 2023-01-10 |
| CVE-2026-4891 | CVE-2026-4891 | MEDIUM | 5.3 | 92.8%ile | Microsoft | 2026-05-12 |
| CVE-2026-58644 | Microsoft SharePoint Remote Code Execution Vulnerability | CRITICAL | 9.8 | 92.6%ile | Microsoft | 2026-07-14 |
| CVE-2024-30084 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 92.5%ile | Microsoft | 2024-06-11 |
| CVE-2024-30051 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 92.2%ile | Microsoft | 2024-05-14 |
| CVE-2024-20685 | Azure Private 5G Core Denial of Service Vulnerability | MEDIUM | 5.9 | 92.0%ile | Microsoft | 2024-04-09 |
| CVE-2026-41103 | Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability | CRITICAL | 9.1 | 91.9%ile | Microsoft | 2026-05-12 |
| CVE-2025-10585 | Chromium: CVE-2025-10585 Type Confusion in V8 | UNKNOWN | — | 91.9%ile | Microsoft | 2025-09-09 |
| CVE-2025-4664 | Chromium: CVE-2025-4664 Insufficient policy enforcement in Loader | UNKNOWN | — | 91.9%ile | Microsoft | 2025-05-13 |
| CVE-2026-20817 | Windows Error Reporting Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 91.8%ile | Microsoft | 2026-01-13 |
| CVE-2023-21752 | Windows Backup Service Elevation of Privilege Vulnerability | HIGH | 7.1 | 91.8%ile | Microsoft | 2023-01-10 |
| CVE-2024-30037 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | MEDIUM | 5.5 | 91.8%ile | Microsoft | 2024-05-14 |
| CVE-2024-30078 | Windows Wi-Fi Driver Remote Code Execution Vulnerability | HIGH | 8.8 | 91.6%ile | Microsoft | 2024-06-11 |
| CVE-2026-50507 | Windows BitLocker Security Feature Bypass Vulnerability | MEDIUM | 6.8 | 91.4%ile | Microsoft | 2026-06-09 |
| CVE-2026-20805 | Desktop Window Manager Information Disclosure Vulnerability | MEDIUM | 5.5 | 91.4%ile | Microsoft | 2026-01-13 |
| CVE-2026-5281 | Chromium: CVE-2026-5281 Use after free in Dawn | UNKNOWN | — | 91.4%ile | Microsoft | 2026-04-14 |
| CVE-2024-26234 | Proxy Driver Spoofing Vulnerability | MEDIUM | 6.7 | 91.2%ile | Microsoft | 2024-04-09 |
| CVE-2024-5841 | Chromium: CVE-2024-5841 Use after free in V8 | UNKNOWN | — | 91.2%ile | Microsoft | 2024-06-11 |
| CVE-2026-40369 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 90.9%ile | Microsoft | 2026-05-12 |
| CVE-2022-45639 | OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a cra | HIGH | 7.8 | 90.8%ile | Microsoft | 2023-01-10 |
| CVE-2025-53020 | Apache HTTP Server: HTTP/2 DoS by Memory Increase | HIGH | 7.5 | 90.7%ile | Microsoft | 2025-07-08 |
| CVE-2024-30032 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 90.6%ile | Microsoft | 2024-05-14 |
| CVE-2022-48303 | GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jum | MEDIUM | 5.5 | 90.6%ile | Microsoft | 2023-01-10 |
| CVE-2026-40364 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 8.4 | 90.4%ile | Microsoft | 2026-05-12 |
| CVE-2026-20840 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 90.4%ile | Microsoft | 2026-01-13 |
| CVE-2024-30091 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 90.1%ile | Microsoft | 2024-06-11 |
| CVE-2024-30025 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 90.1%ile | Microsoft | 2024-05-14 |
Updated 2026-08-04. EPSS = Exploit Prediction Scoring System (FIRST.org). TRENDING = EPSS jumped ≥5 percentage points since yesterday.