PULSE
EN VIVO17señales / 24h
FEED
ransomnova reclama a Koplarla · ID · Not Foundransomqilin reclama a Bolt & Nut Manufacturing · GB · Manufacturingransomchaos reclama a wikoff.com · US · Business Servicesransomdoommageddon reclama a Reni Farmácias Associadas · BR · Healthcareransomunsafe reclama a CCR Solutions · BR · Business Servicesransomqilin reclama a PP+K · BR · Not Foundransomqilin reclama a Eana · AR · Not Foundransomqilin reclama a Synergy Products · TR · Not Foundransomnova reclama a meralmanisa · TR · Not Foundransomnova reclama a Dephub · ID · Not Foundransomnova reclama a Jota Joias Premium · BR · Consumer Servicesransomqilin reclama a Don Tortaco Mexican Grill · US · Hospitality and Tourismransomqilin reclama a Associated Theatrical Contractors · US · Business Servicesransompayload reclama a CKR Consulting Engineers · Business Servicesransomnova reclama a Koplarla · ID · Not Foundransomqilin reclama a Bolt & Nut Manufacturing · GB · Manufacturingransomchaos reclama a wikoff.com · US · Business Servicesransomdoommageddon reclama a Reni Farmácias Associadas · BR · Healthcareransomunsafe reclama a CCR Solutions · BR · Business Servicesransomqilin reclama a PP+K · BR · Not Foundransomqilin reclama a Eana · AR · Not Foundransomqilin reclama a Synergy Products · TR · Not Foundransomnova reclama a meralmanisa · TR · Not Foundransomnova reclama a Dephub · ID · Not Foundransomnova reclama a Jota Joias Premium · BR · Consumer Servicesransomqilin reclama a Don Tortaco Mexican Grill · US · Hospitality and Tourismransomqilin reclama a Associated Theatrical Contractors · US · Business Servicesransompayload reclama a CKR Consulting Engineers · Business Services
CVE Watch349,997 en archivo total

Vulnerabilidades explotables hoy

349,997en la vista actual

Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.

En catálogo KEV1,647
Nuevos KEV · 24H0
Exploit Today ≥ 701,583

Distribución · última ventana

  • Crítico
    1,336
  • Alto
    4,379
  • Medio
    3,753
  • Bajo
    298
Filtros

Ventana

Severidad

Filtros

Vulnerabilidades347,521–347,560 · 349,997
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2024-25984
0.6%
0
CVE-2022-20300
0.6%
0
CVE-2022-20426
0.6%
0
CVE-2025-71111
0.5%
0
CVE-2022-47450
0.6%
0
CVE-2022-47330
0.6%
0
CVE-2026-401064.7 MED
0.6%
0Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above prior to 4.14.5 contain a heap-based buffer overflow vulnerability in the syscheck component of the Wazuh agent for Windows. When expanding registry paths containing wildcards (* or ?), the agent allocates a fixed-size heap buffer of 256 bytes (OS_SIZE_256). By creating a registry subkey with a maximum allowed length (255 characters) inside a monitored path, a low-privileged local attacker can force an out-of-bounds write during string concatenation. Since wazuh-agent.exe runs as NT AUTHORITY\SYSTEM, this can lead to a silent Denial of Service (blinding the agent) or potentially Local Privilege Escalation (LPE). This issue has been fixed in version 4.14.5.10h
CVE-2026-23161
0.6%
0
CVE-2023-20704
0.6%
0
CVE-2022-20344
0.6%
0
CVE-2023-21276
0.6%
0
CVE-2025-20645
0.6%
0
CVE-2022-20016
0.6%
0
CVE-2023-21374
0.6%
0
CVE-2023-20703
0.6%
0
CVE-2024-34733
0.6%
0
CVE-2024-32906
0.6%
0
CVE-2022-20326
0.6%
0
CVE-2022-20259
0.6%
0
CVE-2023-32835
0.6%
0
CVE-2025-48647
0.6%
0
CVE-2024-27226
0.6%
0
CVE-2026-8920
0.6%
0Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this can also cause a single feature to become unavailable . Refer to the ' Security Update for Aura Wallpaper Service ' section on the ASUS Security Advisory for more information.5d
CVE-2023-21087
0.6%
0
CVE-2026-542666.1 MED
0.6%
0Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, Angular's HttpTransferCache caches HTTP requests made during Server-Side Rendering (SSR) so that they can be reused during client-side hydration. This avoids repeating the same HTTP requests on the client. The cached responses are stored in TransferState using a cache key generated by hashing request properties (method, response type, mapped URL, serialized body, and sorted query parameters). The cache keys are generated using a weak 32-bit DJB2-like polynomial rolling hash. The 32-bit hash space is extremely small, allowing attackers to find hash collisions. An attacker can easily find a query parameter string (e.g., q=aaCAZMMM for a search request) that produces the exact same 32-bit hash as a sensitive endpoint (e.g., /api/user/profile). When a victim visits a crafted link containing the colliding parameter, the SSR process executes both the search request and the profile request. Due to the hash collision, the search response overwrites the profile response in the TransferState cache. This vulnerability is fixed in 22.0.1, 21.2.17, and 20.3.25.11d
CVE-2022-36847
0.6%
0
CVE-2024-27231
0.6%
0
CVE-2023-20607
0.6%
0
CVE-2022-20263
0.6%
0
CVE-2026-28711
0.6%
0
CVE-2026-23294
0.6%
0
CVE-2026-556555.0 MED
0.6%
0A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.12d
CVE-2022-20310
0.6%
0
CVE-2023-20706
0.6%
0
CVE-2025-41647
0.6%
0
CVE-2022-36849
0.6%
0
CVE-2023-21026
0.6%
0
CVE-2022-20312
0.6%
0
CVE-2023-21257
0.6%
0
CVE-2025-48590
0.6%
0