Vulnerabilidades explotables hoy
352,162en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,653
Nuevos KEV · 24H0
Exploit Today ≥ 701,590
Distribución · última ventana
- Crítico2,073
- Alto6,924
- Medio5,904
- Bajo547
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-8804—0.3%
——0Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing values such as passwords to be stored in cleartext in the agent's local transaction state cache. Affected versions of the resource_api module include all versions between 1.5.0 - 1.9.1 and 2.0.0 The issue was fixed in puppet resource_api 1.9.2 and 2.0.1 released with Puppet Core 8.20.0 and PE 2023.8.10 & PE 2025.11.0.17dCVE-2026-00777.8 ALT0.3%
——0In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.1dCVE-2026-4541—0.3%
——0——CVE-2022-20118—0.3%
——0——CVE-2025-22438—0.3%
——0——CVE-2022-44435—0.3%
——0——CVE-2022-42765—0.3%
——0——CVE-2025-0824—0.3%
——0——CVE-2023-21345—0.3%
——0——CVE-2025-11009—0.3%
——0——CVE-2024-53028—0.3%
——0——CVE-2022-48443—0.3%
——0——CVE-2022-48444—0.3%
——0——CVE-2023-48339—0.3%
——0——CVE-2022-48445—0.3%
——0——CVE-2026-111588.6 ALT0.3%
——0Insufficient validation of untrusted input in Downloads in Google Chrome on Mac prior to 149.0.7827.53 allowed a local attacker to potentially perform a sandbox escape via a crafted AppleScript command. (Chromium security severity: Medium)10hCVE-2018-9369—0.3%
——0——CVE-2025-22850—0.3%
——0——CVE-2025-48533—0.3%
——0——CVE-2025-36929—0.3%
——0——CVE-2026-28758—0.3%
——0——CVE-2023-21366—0.3%
——0——CVE-2025-7383—0.3%
——0——CVE-2026-13742—0.3%
——0——CVE-2025-48541—0.3%
——0——CVE-2023-48358—0.3%
——0——CVE-2026-328484.7 MED0.3%
——0NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem that allows local attackers to trigger a double-free condition by concurrently issuing CIOCCRYPT operations on the same session identifier on SMP systems. Attackers can exploit mutable per-operation state embedded in the csession struct to corrupt kernel heap memory.9dCVE-2023-21104—0.3%
——0——CVE-2026-53692—0.3%
——0Redeight CMS version 1.0 uses the MD5 algorithm without a salt to store user passwords. Because MD5 is a cryptographically broken algorithm and lacks salting, attackers who obtain the password hashes can trivially reverse them using rainbow tables, leading to the exposure of plaintext credentials.23dCVE-2024-49730—0.3%
——0——CVE-2024-20075—0.3%
——0——CVE-2025-48563—0.3%
——0——CVE-2022-20155—0.3%
——0——CVE-2024-40656—0.3%
——0——CVE-2022-33703—0.3%
——0——CVE-2024-40669—0.3%
——0——CVE-2025-47323—0.3%
——0——CVE-2023-40631—0.3%
——0——CVE-2022-42757—0.3%
——0——CVE-2025-47317—0.3%
——0——