Vulnerabilidades explotables hoy
367,922en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,687
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,385
- Alto9,631
- Medio5,583
- Bajo549
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-3341—3.5%
——1——CVE-2017-13165—3.5%
——1——CVE-2025-0359—3.5%
——1——CVE-2026-9618—3.5%
——1——CVE-2025-38621—3.5%
——1——CVE-2024-54460—3.5%
——1——CVE-2026-667765.9 MED3.5%
——1SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session context. Successful exploitation requires the attacker to have previously observed matching session values out-of-band, which makes the attack complex to execute. This could result in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.7dCVE-2025-26910—3.5%
——1——CVE-2025-1095—3.5%
——1——CVE-2026-5407—3.5%
——1——CVE-2024-47122—3.5%
——1——CVE-2025-40574—3.5%
——1——CVE-2025-53068—3.5%
——1——CVE-2025-22886—3.5%
——1——CVE-2025-27241—3.5%
——1——CVE-2025-683177.8 ALT3.5%
——1In the Linux kernel, the following vulnerability has been resolved:
io_uring/zctx: check chained notif contexts
Send zc only links ubuf_info for requests coming from the same context.
There are some ambiguous syz reports, so let's check the assumption on
notification completion.34dCVE-2025-25218—3.5%
——1——CVE-2019-2050—3.5%
——1——CVE-2026-24191—3.5%
——1——CVE-2021-0567—3.5%
——1——CVE-2026-1344—3.5%
——1——CVE-2025-36243—3.5%
——1——CVE-2026-32460—3.4%
——1——CVE-2024-2207—3.4%
——1——CVE-2022-33905—3.4%
——1——CVE-2016-11041—3.4%
——1——CVE-2026-7397—3.4%
——1——CVE-2022-32646—3.4%
——1——CVE-2025-14615—3.4%
——1——CVE-2017-11085—3.4%
——1——CVE-2026-409527.8 ALT3.4%
——1CVE-2026-40952 is a privilege misconfiguration
in the Secure Access installer for the Windows client and server prior to
version 14.55. Attackers with local access to the client or server can use it
to elevate privileges to Administrator when Secure Access is installed in a
non-default location.48dCVE-2026-751427.8 ALT3.4%
——1FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with an excessive number of streams triggers the overflow during MPEG-PS muxing.6dCVE-2021-35084—3.4%
——1——CVE-2018-25289—3.4%
——1——CVE-2023-28658—3.4%
——1——CVE-2025-681957.1 ALT3.4%
——1In the Linux kernel, the following vulnerability has been resolved:
x86/CPU/AMD: Add missing terminator for zen5_rdseed_microcode
Running x86_match_min_microcode_rev() on a Zen5 CPU trips up KASAN for an out
of bounds access.34dCVE-2026-15030—3.4%
——1Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL request that bypasses the validation.
Refer to the ' Security Update for ASUS System Control Interface ' section on the ASUS Security Advisory for more information.49dCVE-2023-32547—3.4%
——1——CVE-2022-34325—3.4%
——1——CVE-2024-34655—3.4%
——1——