PULSE
EN VIVO53señales / 24h
FEED
ransomthegentlemen reclama a European Design · CA · Otherransomthegentlemen reclama a MK Jewelry · MK · Retail & E-Commerceransomthegentlemen reclama a GUERREIROS seguros · PT · Financial Servicesransomthegentlemen reclama a Tikona Infinet · IN · Technologyransomthegentlemen reclama a TC Printing · AU · Manufacturingransomthegentlemen reclama a Oldelval Oleoductos del Valle · AR · Energy & Utilitiesransomthegentlemen reclama a Decoupe Laser Services · FR · Manufacturingransomthegentlemen reclama a Thialf · NL · Energy & Utilitiesransomthegentlemen reclama a Title Resources · AU · Financial Servicesransomthegentlemen reclama a Clarke Radiology · AU · Healthcareransomthegentlemen reclama a SICSOE · FR · Not Foundransomthegentlemen reclama a Gloria Maris Groupe · FR · Agriculture and Food Productionransomthegentlemen reclama a Compagnie des Caoutchoucs du Pakidie · Manufacturingransomthegentlemen reclama a HBS Group · AU · Professional Servicesransomthegentlemen reclama a European Design · CA · Otherransomthegentlemen reclama a MK Jewelry · MK · Retail & E-Commerceransomthegentlemen reclama a GUERREIROS seguros · PT · Financial Servicesransomthegentlemen reclama a Tikona Infinet · IN · Technologyransomthegentlemen reclama a TC Printing · AU · Manufacturingransomthegentlemen reclama a Oldelval Oleoductos del Valle · AR · Energy & Utilitiesransomthegentlemen reclama a Decoupe Laser Services · FR · Manufacturingransomthegentlemen reclama a Thialf · NL · Energy & Utilitiesransomthegentlemen reclama a Title Resources · AU · Financial Servicesransomthegentlemen reclama a Clarke Radiology · AU · Healthcareransomthegentlemen reclama a SICSOE · FR · Not Foundransomthegentlemen reclama a Gloria Maris Groupe · FR · Agriculture and Food Productionransomthegentlemen reclama a Compagnie des Caoutchoucs du Pakidie · Manufacturingransomthegentlemen reclama a HBS Group · AU · Professional Services
CVE Watch352,162 en archivo total

Vulnerabilidades explotables hoy

352,162en la vista actual

Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.

En catálogo KEV1,653
Nuevos KEV · 24H0
Exploit Today ≥ 701,590

Distribución · última ventana

  • Crítico
    2,073
  • Alto
    6,924
  • Medio
    5,904
  • Bajo
    547
Filtros

Ventana

Severidad

Filtros

Vulnerabilidades350,921–350,960 · 352,162
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2022-42765
0.3%
0
CVE-2026-8804
0.3%
0Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing values such as passwords to be stored in cleartext in the agent's local transaction state cache. Affected versions of the resource_api module include all versions between 1.5.0 - 1.9.1 and 2.0.0 The issue was fixed in puppet resource_api 1.9.2 and 2.0.1 released with Puppet Core 8.20.0 and PE 2023.8.10 & PE 2025.11.0.17d
CVE-2024-20092
0.3%
0
CVE-2025-68968
0.3%
0
CVE-2025-20653
0.3%
0
CVE-2026-625635.4 MED
0.3%
0Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Work in Process, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Work in Process accessible data as well as unauthorized read access to a subset of Oracle Work in Process accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).1d
CVE-2022-42758
0.3%
0
CVE-2024-47032
0.3%
0
CVE-2022-39885
0.3%
0
CVE-2024-20075
0.3%
0
CVE-2024-40656
0.3%
0
CVE-2025-48563
0.3%
0
CVE-2023-40105
0.3%
0
CVE-2025-31963
0.3%
0
CVE-2026-41971
0.3%
0
CVE-2022-39903
0.3%
0
CVE-2025-36105
0.3%
0
CVE-2025-47315
0.3%
0
CVE-2024-12236
0.3%
0
CVE-2025-36905
0.3%
0
CVE-2026-499585.0 MED
0.3%
0Hermes WebUI before version 0.51.303 contains a time-of-check time-of-use (TOCTOU) race condition vulnerability in the git_discard function within api/workspace_git.py that allows attackers to delete files outside the configured workspace boundary by replacing a validated path component with a symlink after validation but before deletion. Attackers can substitute a workspace-controlled path component with a symlink pointing to an external directory between the safe_resolve_ws() validation step and the subsequent Path.unlink() or shutil.rmtree() deletion call, causing the delete operation to follow the symlink and remove arbitrary files outside the workspace.8h
CVE-2025-32321
0.3%
0
CVE-2023-48355
0.3%
0
CVE-2022-39879
0.3%
0
CVE-2023-28124
0.3%
0
CVE-2023-28576
0.3%
0
CVE-2025-48547
0.3%
0
CVE-2025-21444
0.3%
0
CVE-2025-21445
0.3%
0
CVE-2024-36334
0.3%
0
CVE-2024-43769
0.3%
0
CVE-2023-48348
0.3%
0
CVE-2024-29780
0.3%
0
CVE-2023-48341
0.3%
0
CVE-2025-31655
0.3%
0
CVE-2022-42782
0.3%
0
CVE-2026-162133.3 BAJ
0.3%
0A security flaw has been discovered in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vulnerability is an unknown functionality of the file zinnia/views/mixins/entry_protection.py of the component Protected Entry Password Handler. The manipulation results in cleartext storage of sensitive information. The attack needs to be approached locally. The project was informed of the problem early through an issue report but has not responded yet.3d
CVE-2024-20121
0.3%
0
CVE-2023-48346
0.3%
0
CVE-2023-38436
0.3%
0