Vulnerabilidades explotables hoy
4,338en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,242
- Alto9,242
- Medio5,232
- Bajo501
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2023-6553—99.9%
——30——CVE-2012-1462—99.9%
——30——CVE-2022-2024—99.9%
——30——CVE-2021-45382—99.9%
KEV—80D-Link Multiple Routers Remote Code Execution Vulnerability—CVE-2021-26295—99.9%
——30——CVE-2020-11738—99.9%
KEV—80WordPress Snap Creek Duplicator Plugin File Download Vulnerability—CVE-2022-21661—99.9%
——30——CVE-2025-618847.5 ALT99.9%
KEVR80Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability27dCVE-2021-252996.1 MED99.9%
——30Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal his/her session cookies or it can be chained with the previous bugs to get one-click remote command execution (RCE) on the Nagios XI server.53dCVE-2012-1453—99.9%
——30——CVE-2018-15745—99.9%
——30——CVE-2019-16662—99.9%
——30——CVE-2022-43769—99.9%
KEV—80Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability—CVE-2025-34028—99.9%
KEV—80Commvault Command Center Path Traversal Vulnerability—CVE-2015-7450—99.9%
KEV—80IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.—CVE-2023-0315—99.9%
——30——CVE-2019-18818—99.9%
——30——CVE-2013-0422—99.9%
KEVR80Oracle JRE Remote Code Execution Vulnerability—CVE-2021-36380—99.9%
KEV—80Sunhillo SureLine OS Command Injection Vulnerablity—CVE-2016-10045—99.9%
——30——CVE-2013-5211—99.9%
——30——CVE-2012-0392—99.9%
——30——CVE-2021-3378—99.9%
——30——CVE-2016-3714—99.9%
KEV—80ImageMagick Improper Input Validation Vulnerability—CVE-2024-4358—99.9%
KEV—80Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability—CVE-2021-26812—99.9%
——30——CVE-2021-404448.8 ALT99.9%
KEVR80Microsoft MSHTML Remote Code Execution Vulnerability20dCVE-2024-56145—99.9%
KEV—80Craft CMS Code Injection Vulnerability—CVE-2019-9082—99.9%
KEV—80ThinkPHP Remote Code Execution Vulnerability—CVE-2020-12116—99.9%
——30——CVE-2016-6601—99.9%
——30——CVE-2023-23397—99.9%
KEV—80Microsoft Office Outlook Privilege Escalation Vulnerability—CVE-2007-3010—99.9%
KEV—80Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability—CVE-2023-27524—99.9%
KEV—80Apache Superset Insecure Default Initialization of Resource Vulnerability—CVE-2021-22054—99.9%
KEV—80Omnissa Workspace ONE Server-Side Request Forgery—CVE-2018-17456—99.9%
——30——CVE-2023-26360—99.9%
KEV—80Adobe ColdFusion Deserialization of Untrusted Data Vulnerability—CVE-2020-1956—99.9%
KEV—80Apache Kylin OS Command Injection Vulnerability—CVE-2020-25213—99.9%
KEV—80WordPress File Manager Plugin Remote Code Execution Vulnerability—CVE-2020-1943—99.9%
——30——