Vulnerabilidades explotables hoy
350,242en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,647
Nuevos KEV · 24H0
Exploit Today ≥ 701,583
Distribución · última ventana
- Crítico1,426
- Alto4,734
- Medio3,925
- Bajo306
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-213837.1 ALT0.0%
——0Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security.13dCVE-2026-50267—0.0%
——0——CVE-2025-48641—0.0%
——0——CVE-2025-66323—0.0%
——0——CVE-2023-21290—0.0%
——0——CVE-2022-48451—0.0%
——0——CVE-2023-20785—0.0%
——0——CVE-2023-20801—0.0%
——0——CVE-2023-20687—0.0%
——0——CVE-2025-36921—0.0%
——0——CVE-2023-20750—0.0%
——0——CVE-2023-44128—0.0%
——0——CVE-2021-25502—0.0%
——0——CVE-2026-28538—0.0%
——0——CVE-2026-28537—0.0%
——0——CVE-2023-20686—0.0%
——0——CVE-2025-58303—0.0%
——0——CVE-2025-48960—0.0%
——0——CVE-2025-36751—0.0%
——0——CVE-2025-596176.6 MED0.0%
——0Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.14dCVE-2024-29779—0.0%
——0——CVE-2025-47374—0.0%
——0——CVE-2022-47331—0.0%
——0——CVE-2026-61606——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61457. Reason: This candidate is a duplicate of CVE-2026-61457. Notes: All CVE users should reference CVE-2026-61457 instead of this candidate.6dCVE-2025-66331—0.0%
——0——CVE-2026-61710——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61453. Reason: This candidate is a duplicate of CVE-2026-61453. Notes: All CVE users should reference CVE-2026-61453 instead of this candidate.6dCVE-2023-21178—0.0%
——0——CVE-2026-24090—0.0%
——0——CVE-2025-66320—0.0%
——0——CVE-2026-28539—0.0%
——0——CVE-2025-66322—0.0%
——0——CVE-2026-0121—0.0%
——0——CVE-2025-66321—0.0%
——0——CVE-2025-68969—0.0%
——0——CVE-2025-48625—0.0%
——0——CVE-2025-66332—0.0%
——0——CVE-2026-218248.8 ALT—
——0HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.13hCVE-2026-62418——
——0Low-privileged authenticated Server-Side Request Forgery (SSRF)
vulnerability in Apache Syncope via Connectors and Resources check.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1.
Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.10hCVE-2026-53405——
——0Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start the process. When a BPMN process containing a Groovy scriptTask is imported and started, the Groovy script is executed directly on the server, with no sandbox.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1.
Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by wrapping Flowable's Groovy scriptTasks with security sandbox.10hCVE-2026-637556.5 MED—
——0SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH clauses in UPDATE, UPSERT, INSERT ON DUPLICATE KEY UPDATE, and RELATE update-variant statements) against full record data before enforcing PERMISSIONS FOR SELECT WHERE restrictions. An authenticated user — including Record and Scope users — can exploit this ordering flaw to read the full contents of any table in the database they are authenticated against, bypassing table-level permission checks. Exfiltration is most direct when scripting functions are enabled (--allow-scripting), but is also possible via SurrealQL's THROW statement and timing-based side channels without scripting. The vulnerability is confined to the attacker's current database and does not cross namespace or database isolation boundaries.14h