PULSE
EN VIVO21señales / 24h
FEED
ransomnova reclama a Marpatech · Technologyransomnova reclama a Canal 9 Litoral · AR · Telecommunicationransomqilin reclama a Evergreen Title · US · Financial Servicesransomplay reclama a Tax MT · MT · Business Servicesransomplay reclama a Kreysler & Associates · US · Business Servicesransomnova reclama a La Financière d'Orion (finorion) · FR · Financial Servicesransomchaos reclama a argonautms.com · RU · Technologyransomdragonforce reclama a One Community FCU · US · Financial Servicesransomqilin reclama a RehaVital Gesundheitsservice GmbH · DE · Healthcareransomnova reclama a Tèrra Aventura · PT · Hospitality and Tourismransomnova reclama a Koperasi Karyawan PT Aplikanusa Lintasarta · ID · Telecommunicationransomakira reclama a Novasport s.r.o. · CZ · Consumer Servicesransomakira reclama a Finer & Finer · Consumer Servicesransommorpheus reclama a Kyowa Singapore Pte Ltd · SG · Business Servicesransomnova reclama a Marpatech · Technologyransomnova reclama a Canal 9 Litoral · AR · Telecommunicationransomqilin reclama a Evergreen Title · US · Financial Servicesransomplay reclama a Tax MT · MT · Business Servicesransomplay reclama a Kreysler & Associates · US · Business Servicesransomnova reclama a La Financière d'Orion (finorion) · FR · Financial Servicesransomchaos reclama a argonautms.com · RU · Technologyransomdragonforce reclama a One Community FCU · US · Financial Servicesransomqilin reclama a RehaVital Gesundheitsservice GmbH · DE · Healthcareransomnova reclama a Tèrra Aventura · PT · Hospitality and Tourismransomnova reclama a Koperasi Karyawan PT Aplikanusa Lintasarta · ID · Telecommunicationransomakira reclama a Novasport s.r.o. · CZ · Consumer Servicesransomakira reclama a Finer & Finer · Consumer Servicesransommorpheus reclama a Kyowa Singapore Pte Ltd · SG · Business Services
CVE Watch351,724 en archivo total

Vulnerabilidades explotables hoy

351,724en la vista actual

Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.

En catálogo KEV1,651
Nuevos KEV · 24H0
Exploit Today ≥ 701,587

Distribución · última ventana

  • Crítico
    1,765
  • Alto
    5,628
  • Medio
    4,518
  • Bajo
    412
Filtros

Ventana

Severidad

Filtros

Vulnerabilidades351,401–351,440 · 351,724
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-164477.3 ALT
0A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument Filedata[] leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.14h
CVE-2026-9499
0An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that is not NUL-terminated (for example, one created with QByteArray::fromRawData()), the codec-name matching routine reads past the end of the supplied buffer. In most cases this results in an incorrect text codec being selected; in the worst case, if the over-read reaches unmapped memory, the process crashes (denial of service). The over-read is bounded by the length of the longest codec-name candidate, and the out-of-bounds bytes are only compared internally against Qt's fixed list of codec names, so no data is disclosed to an attacker. Applications that do not pass non-NUL-terminated QByteArrays to QTextCodec::codecForName() are not exposed. The affected code resides in the Qt5Compat module from Qt 6.0.0 onward, and in Qt Core (qtbase) in Qt 4.x and Qt 5.x.17h
CVE-2026-598455.3 MED
0A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.12h
CVE-2026-598446.5 MED
0A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.12h
CVE-2026-164057.5 ALT
0Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.11h
CVE-2026-646069.8 CRÍ
0Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from before 1.4.0. Users are recommended to upgrade to version 1.4.0, which fixes the issue.12h
CVE-2026-650079.6 CRÍ
0The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks before the account-management ACL runs and authorizes the caller on only the admin.login permission (the baseline permission held by every panel user). This allows any user with admin.login to mint a persistent API key bound to any account, and the forged key inherits the target account's API permissions. On installs where an API-enabled account holds broader permissions, this enables account impersonation and privilege escalation up to account takeover.12h
CVE-2026-650089.8 CRÍ
0Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to call_user_func_array() without any allowlist. Because the form plugin routes page frontmatter through this path, an authenticated account with the admin.pages (or api.pages.write) permission can plant a malicious callable directive in a page. The command then executes as the web-server user whenever anyone — including an unauthenticated visitor — accesses the page.12h
CVE-2026-598423.7 BAJ
0A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.12h
CVE-2026-16179.8 CRÍ
0Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama allows SQL Injection. This issue affects Turkhotspot 5651 Loglama: from 5.1.2 before 5.1.3.14h
CVE-2026-164616.5 MED
0A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), version numbers from a remote RPCBPROC_DUMP reply are written into a fixed-size stack buffer without bounds checking. A user or administrator who runs `rpcinfo -s` against a malicious or compromised rpcbind endpoint could experience a crash or denial of service of the rpcinfo client.12h
CVE-2026-67926.5 MED
0Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexCity: from 5.536.0 through 11052026.14h
CVE-2026-598463.9 BAJ
0A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.12h
CVE-2026-16410
0JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153.12h
CVE-2026-16404
0Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.12h
CVE-2026-16403
0Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153.12h
CVE-2026-16402
0Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153.12h
CVE-2026-16401
0Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153.12h
CVE-2026-16400
0Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153.12h
CVE-2026-16399
0Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153.12h
CVE-2025-66327
0.0%
0
CVE-2026-16398
0Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153.12h
CVE-2025-66328
0.0%
0
CVE-2026-163976.5 MED
0Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.11h
CVE-2026-16396
0Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.12h
CVE-2026-163959.8 CRÍ
0Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153.11h
CVE-2026-163949.1 CRÍ
0Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153.11h
CVE-2026-16393
0Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.12h
CVE-2026-16392
0JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153.12h
CVE-2026-16391
0Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.12h
CVE-2026-16390
0Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.12h
CVE-2026-16389
0Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153.12h
CVE-2026-16388
0Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153.12h
CVE-2026-16387
0Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.12h
CVE-2026-14278
0Rejected reason: After further coordination, CVE was determined to not be warranted.13d
CVE-2026-16386
0Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.12h
CVE-2026-16385
0Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.12h
CVE-2026-16383
0Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.12h
CVE-2026-16382
0Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153.12h
CVE-2026-16381
0Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.12h