Vulnerabilidades explotables hoy
350,369en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,651
Nuevos KEV · 24H4
Exploit Today ≥ 701,587
Distribución · última ventana
- Crítico1,484
- Alto4,943
- Medio4,052
- Bajo320
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-82854.3 MED—
——0Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc. FlexCity allows Excessive Allocation.
This issue affects FlexCity: from 5.536.0 through 11052026.3hCVE-2026-67926.5 MED—
——0Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects FlexCity: from 5.536.0 through 11052026.3hCVE-2026-16359——
——0Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.3hCVE-2026-598463.9 BAJ—
——0A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.3hCVE-2026-164457.5 ALT—
——0A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot.3hCVE-2026-16370——
——0Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153.3hCVE-2026-16412——
——0Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.3hCVE-2026-158115.8 MED0.0%
——0A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. This omission leaves raw encryption keys resident in memory after the associated structures are freed. A local attacker capable of leveraging memory disclosure techniques could exploit this flaw to retrieve the active encryption key, allowing them to decrypt cluster network communications or inject malicious packets to cause severe high-availability cluster instability.10hCVE-2026-16358——
——0Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.3hCVE-2026-16410——
——0JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153.3hCVE-2026-16409——
——0Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153.3hCVE-2026-16408——
——0Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153.3hCVE-2026-16407——
——0Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153.3hCVE-2026-646069.8 CRÍ—
——0Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected
This issue affects Apache Fory: from before 1.4.0.
Users are recommended to upgrade to version 1.4.0, which fixes the issue.2hCVE-2026-213705.3 MED0.0%
——0Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.14dCVE-2026-14278——
——0Rejected reason: After further coordination, CVE was determined to not be warranted.12dCVE-2026-16377——
——0Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.3hCVE-2026-16349——
——0Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.3hCVE-2026-0112—0.0%
——0——CVE-2026-16406——
——0Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153.3hCVE-2026-16371——
——0Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.3hCVE-2026-16404——
——0Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.3hCVE-2026-16372——
——0Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153.3hCVE-2026-16403——
——0Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153.3hCVE-2026-16402——
——0Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153.3hCVE-2026-16401——
——0Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153.3hCVE-2026-16350——
——0Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.3hCVE-2026-16400——
——0Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153.3hCVE-2026-16351——
——0Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.3hCVE-2026-16373——
——0Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153.3hCVE-2026-16399——
——0Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153.3hCVE-2026-16352——
——0Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.3hCVE-2026-16398——
——0Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153.3hCVE-2026-16397——
——0Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.3hCVE-2026-64627——
——0Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerability. When the GraphQL API is mounted with public introspection disabled (graphQLPublicIntrospection: false, the default), schema-derived 'Did you mean ...?' suggestions were still returned in GraphQL error messages produced during variable coercion, which were not covered by the introspection-hardening control (that only handled validation errors). An unauthenticated caller possessing only the public application id can iteratively recover hidden schema identifiers — including registered Cloud Code function names and Parse class and field names — by submitting queries or mutations whose variables contain near-miss enum values or input-object field names. This is a follow-up bypass of GHSA-8cph-rgr4-g5vj. The issue is fixed in 9.10.0-alpha.4 and 8.6.85.4hCVE-2026-16353——
——0Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.3hCVE-2026-16396——
——0Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.3hCVE-2026-16357——
——0Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.3hCVE-2026-16374——
——0Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.3hCVE-2026-16354——
——0Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.3h