Vulnerabilidades explotables hoy
368,208en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,694
Nuevos KEV · 24H0
Exploit Today ≥ 701,631
Distribución · última ventana
- Crítico2,140
- Alto7,668
- Medio5,506
- Bajo542
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2023-53512—4.1%
——1——CVE-2026-105534.3 MED4.1%
——1The jQuery Hover Footnotes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the jqFootnotes_options_subpanel function. This makes it possible for unauthenticated attackers to update the plugin's settings with arbitrary values that, because option values such as jqfoot_anchor_open, jqfoot_anchor_close, and jqfoot_title are echoed unescaped into frontend page content, can be chained into persistent Cross-Site Scripting affecting all site visitors via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Successful exploitation of the CSRF vulnerability can be chained into stored Cross-Site Scripting, as the overwritten option values are persisted via update_option() without sanitization and rendered unescaped on the frontend.43dCVE-2026-521317.5 ALT4.1%
——1llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function.1dCVE-2023-53406—4.1%
——1——CVE-2023-542107.8 ALT4.1%
——1In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: Avoid use-after-free in dbg for hci_remove_adv_monitor()
KASAN reports that there's a use-after-free in
hci_remove_adv_monitor(). Trawling through the disassembly, you can
see that the complaint is from the access in bt_dev_dbg() under the
HCI_ADV_MONITOR_EXT_MSFT case. The problem case happens because
msft_remove_monitor() can end up freeing the monitor
structure. Specifically:
hci_remove_adv_monitor() ->
msft_remove_monitor() ->
msft_remove_monitor_sync() ->
msft_le_cancel_monitor_advertisement_cb() ->
hci_free_adv_monitor()
Let's fix the problem by just stashing the relevant data when it's
still valid.31dCVE-2023-53409—4.1%
——1——CVE-2026-23042—4.1%
——1——CVE-2025-4975—4.1%
——1——CVE-2026-272685.5 MED4.1%
——1Illustrator versions 29.8.4, 30.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.7dCVE-2023-53415—4.1%
——1——CVE-2026-23048—4.1%
——1——CVE-2023-53411—4.1%
——1——CVE-2026-3590—4.1%
——1——CVE-2023-53416—4.1%
——1——CVE-2025-38537—4.1%
——1——CVE-2025-48285—4.1%
——1——CVE-2024-9576—4.0%
——1——CVE-2025-43360—4.1%
——1——CVE-2025-38726—4.1%
——1——CVE-2025-22098—4.1%
——1——CVE-2023-53300—4.1%
——1——CVE-2026-27068—4.1%
——1——CVE-2021-30278—4.1%
——1——CVE-2023-53405—4.1%
——1——CVE-2025-66662.0 BAJ4.1%
——1A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125. Affected by this vulnerability is an unknown functionality of the component NFC Handler. Executing a manipulation can lead to use of hard-coded cryptographic key
. The physical device can be targeted for the attack. A high complexity level is associated with this attack. The exploitation appears to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.18dCVE-2023-53414—4.1%
——1——CVE-2025-9157—4.1%
——1——CVE-2026-3091—4.1%
——1——CVE-2023-53532—4.1%
——1——CVE-2020-27031—4.1%
——1——CVE-2023-53424—4.1%
——1——CVE-2022-39097—4.1%
——1——CVE-2025-3907—4.1%
——1——CVE-2016-20042—4.1%
——1——CVE-2024-45555—4.1%
——1——CVE-2025-68836—4.1%
——1——CVE-2026-23044—4.1%
——1——CVE-2025-61554—4.1%
——1——CVE-2023-21262—4.1%
——1——CVE-2025-12590—4.1%
——1——