Vulnerabilidades explotables hoy
4,338en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,242
- Alto9,242
- Medio5,232
- Bajo501
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2005-2847—98.9%
——30——CVE-2021-22175—98.9%
KEV—80GitLab Server-Side Request Forgery (SSRF) Vulnerability—CVE-2014-9118—98.9%
——30——CVE-2014-3507—98.9%
——30——CVE-2014-0644—98.9%
——30——CVE-2015-7007—98.9%
——30——CVE-2018-4233—98.9%
——30——CVE-2020-1967—98.9%
——30——CVE-2006-2502—98.9%
——30——CVE-2006-5702—98.9%
——30——CVE-2023-278239.8 CRÍ98.9%
——30An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.53dCVE-1999-0191—98.9%
——30——CVE-2023-50231—98.9%
——30——CVE-2025-14611—98.9%
KEV—80Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability—CVE-2018-3949—98.9%
——30——CVE-2009-0043—98.9%
——30——CVE-2021-24307—98.9%
——30——CVE-2023-45249—98.9%
KEV—80Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability—CVE-2024-37843—98.9%
——30——CVE-2022-23940—98.9%
——30——CVE-2018-7739—98.9%
——30——CVE-2022-245629.8 CRÍ98.9%
——30In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.53dCVE-2015-1642—98.9%
KEV—80Microsoft Office Memory Corruption Vulnerability—CVE-2008-3922—98.9%
——30——CVE-2019-0541—98.9%
KEV—80Microsoft MSHTML Remote Code Execution Vulnerability—CVE-2024-3922—98.9%
——30——CVE-2022-1058—98.9%
——30——CVE-2014-8142—98.9%
——30——CVE-2012-2539—98.9%
KEV—80Microsoft Word Remote Code Execution Vulnerability—CVE-2024-50498—98.9%
——30——CVE-2026-534358.8 ALT98.9%
——30In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards.
This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller.4dCVE-2024-6396—98.9%
——30——CVE-2006-6761—98.9%
——30——CVE-2019-11577—98.9%
——30——CVE-2019-9760—98.9%
——30——CVE-2010-0248—98.9%
——30——CVE-2018-0840—98.9%
——30——CVE-2006-3459—98.9%
——30——CVE-2020-12028—98.9%
——30——CVE-2022-38419—98.9%
——30——