Vulnerabilidades explotables hoy
351,720en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,651
Nuevos KEV · 24H0
Exploit Today ≥ 701,587
Distribución · última ventana
- Crítico1,750
- Alto5,599
- Medio4,484
- Bajo405
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2022-20078—1.0%
——0——CVE-2022-26470—1.0%
——0——CVE-2022-26467—1.0%
——0——CVE-2022-49781—1.0%
——0——CVE-2021-39751—1.0%
——0——CVE-2025-48511—1.0%
——0——CVE-2023-33894—1.0%
——0——CVE-2022-20077—1.0%
——0——CVE-2023-21181—1.0%
——0——CVE-2025-29933—1.0%
——0——CVE-2022-33688—1.0%
——0——CVE-2023-33886—1.0%
——0——CVE-2023-33887—1.0%
——0——CVE-2022-20115—1.0%
——0——CVE-2023-20585—1.0%
——0——CVE-2023-33890—1.0%
——0——CVE-2026-43433—1.0%
——0——CVE-2022-33697—1.0%
——0——CVE-2022-33687—1.0%
——0——CVE-2022-20260—1.0%
——0——CVE-2025-27708—1.0%
——0——CVE-2022-20002—1.0%
——0——CVE-2021-39774—1.0%
——0——CVE-2024-38411—1.0%
——0——CVE-2024-38414—1.0%
——0——CVE-2023-33884—1.0%
——0——CVE-2023-33885—1.0%
——0——CVE-2023-33888—1.0%
——0——CVE-2023-33889—1.0%
——0——CVE-2021-39748—0.9%
——0——CVE-2025-33088—1.0%
——0——CVE-2023-53614—1.0%
——0——CVE-2017-13321—1.0%
——0——CVE-2022-32633—1.0%
——0——CVE-2025-48653—1.0%
——0——CVE-2026-452226.1 MED1.0%
——0Summarize versions through 0.14.1, fixed in commit 0cfb0fb, creates the daemon configuration directory and file with default filesystem permissions that may be world-readable on Unix-like systems, allowing local attackers to read bearer tokens and API credentials stored in ~/.summarize/daemon.json. A local attacker can exploit these permissive permissions to read the daemon bearer token and persisted provider credentials, enabling unauthorized access to the daemon or recovery of sensitive API keys.7dCVE-2022-26465—1.0%
——0——CVE-2022-26466—1.0%
——0——CVE-2026-415162.5 BAJ1.0%
——0OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 4.5.0 and prior to version 4.11.0, the RSA PKCS#1 v1.5 decryption implementation in the Hisilicon HPRE crypto driver uses non-constant-time `memcmp()` for label hash verification and has multiple distinguishable error paths. This creates a Bleichenbacher-style padding oracle that allows an attacker to recover RSA PKCS#1 v1.5 plaintext. Version 4.11.0 contains a patch. As a workaround, disable Hisilicon HPRE RSA driver with `CFG_HISILICON_ACC_V3=n`.14dCVE-2026-42480—1.0%
——0——