Vulnerabilidades explotables hoy
352,162en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,653
Nuevos KEV · 24H0
Exploit Today ≥ 701,590
Distribución · última ventana
- Crítico2,073
- Alto6,924
- Medio5,904
- Bajo547
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2025-48908—0.3%
——0——CVE-2026-114812.5 BAJ0.3%
——0A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.LookupByContentHash of the file indexer/chunker.go of the component Postgres Embedding Cache. Executing a manipulation of the argument content_hash can lead to use of weak hash. The attack needs to be launched locally. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.9hCVE-2024-40669—0.3%
——0——CVE-2026-45413—0.3%
——0MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, user passwords are stored using unsalted MD5 hashes, making them trivially crackable via rainbow tables or GPU-accelerated brute force (hashcat). This vulnerability is fixed in 2.9.1.5hCVE-2024-47032—0.3%
——0——CVE-2025-20653—0.3%
——0——CVE-2026-6066—0.3%
——0——CVE-2022-42758—0.3%
——0——CVE-2026-625635.4 MED0.3%
——0Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Work in Process, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Work in Process accessible data as well as unauthorized read access to a subset of Oracle Work in Process accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).1dCVE-2022-39885—0.3%
——0——CVE-2022-39886—0.3%
——0——CVE-2023-48357—0.3%
——0——CVE-2025-0824—0.3%
——0——CVE-2023-40636—0.3%
——0——CVE-2023-40113—0.3%
——0——CVE-2023-42653—0.3%
——0——CVE-2025-13162—0.3%
——0——CVE-2023-21270—0.3%
——0——CVE-2023-21141—0.3%
——0——CVE-2026-00777.8 ALT0.3%
——0In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.23hCVE-2025-20979—0.3%
——0——CVE-2022-39887—0.3%
——0——CVE-2026-22614—0.3%
——0——CVE-2022-33703—0.3%
——0——CVE-2025-47323—0.3%
——0——CVE-2025-11009—0.3%
——0——CVE-2022-42757—0.3%
——0——CVE-2023-40631—0.3%
——0——CVE-2026-00877.8 ALT0.3%
——0In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app link due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.23hCVE-2025-7071—0.3%
——0——CVE-2025-48562—0.3%
——0——CVE-2024-44098—0.3%
——0——CVE-2026-42408—0.3%
——0——CVE-2025-53177—0.3%
——0——CVE-2024-29783—0.3%
——0——CVE-2024-20026—0.3%
——0——CVE-2024-20116—0.3%
——0——CVE-2026-43326—0.3%
——0——CVE-2022-20071—0.3%
——0——CVE-2022-42769—0.3%
——0——