Vulnerabilidades explotables hoy
368,208en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,687
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,162
- Alto7,697
- Medio5,527
- Bajo546
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-179764.3 MED3.5%
——1Insufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted domain name. (Chromium security severity: Low)31dCVE-2022-31635—3.5%
——1——CVE-2022-43777—3.5%
——1——CVE-2022-31638—3.5%
——1——CVE-2025-25201—3.5%
——1——CVE-2026-46036—3.5%
——1——CVE-2018-25298—3.5%
——1——CVE-2024-46867—3.5%
——1——CVE-2026-348166.4 MED3.5%
——1Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the domain parameter to /manage/smtpscan/domainrouting/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.41dCVE-2026-6357—3.5%
——1——CVE-2023-50945—3.5%
——1——CVE-2025-70936—3.5%
——1——CVE-2017-14900—3.5%
——1——CVE-2020-35548—3.5%
——1——CVE-2025-38256—3.5%
——1——CVE-2023-540357.8 ALT3.5%
——1In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: fix underflow in chain reference counter
Set element addition error path decrements reference counter on chains
twice: once on element release and again via nft_data_release().
Then, d6b478666ffa ("netfilter: nf_tables: fix underflow in object
reference counter") incorrectly fixed this by removing the stateful
object reference count decrement.
Restore the stateful object decrement as in b91d90368837 ("netfilter:
nf_tables: fix leaking object reference count") and let
nft_data_release() decrement the chain reference counter, so this is
done only once.30dCVE-2026-348236.4 MED3.5%
——1Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/password/web/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.41dCVE-2026-28978—3.5%
——1——CVE-2017-14899—3.5%
——1——CVE-2026-8584—3.5%
——1——CVE-2019-9351—3.5%
——1——CVE-2019-9292—3.5%
——1——CVE-2025-21089—3.5%
——1——CVE-2017-14898—3.5%
——1——CVE-2017-13172—3.5%
——1——CVE-2026-89813.5 BAJ3.5%
——1The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to its block template code fields, allowing administrators on multisite installations (or single-site installs with DISALLOW_UNFILTERED_HTML defined) to inject arbitrary JavaScript that executes for any visitor of pages embedding the affected block.42dCVE-2017-11023—3.5%
——1——CVE-2026-36766—3.5%
——1——CVE-2017-13161—3.5%
——1——CVE-2017-9698—3.5%
——1——CVE-2017-11091—3.5%
——1——CVE-2026-43314—3.5%
——1——CVE-2026-21044—3.5%
——1——CVE-2017-0865—3.5%
——1——CVE-2026-348116.4 MED3.5%
——1Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/xtaccess.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.41dCVE-2026-631055.4 MED3.5%
——1ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated customers to inject malicious HTML payloads through the chat and support ticket messaging systems by exploiting unsanitized rendering via the v-html directive in Messages.vue, RightChatSidebar.vue, SupportTicketMessages.vue, and SupportTicketDetails.vue. Attackers can submit crafted message content that executes arbitrary JavaScript in the browser of any shop owner or administrator who views the message, enabling session cookie theft and account takeover.24dCVE-2026-531327.1 ALT3.5%
——1In the Linux kernel, the following vulnerability has been resolved:
vsock/virtio: fix potential unbounded skb queue
virtio_transport_inc_rx_pkt() checks vvs->rx_bytes + len > vvs->buf_alloc.
virtio_transport_recv_enqueue() skips coalescing for packets
with VIRTIO_VSOCK_SEQ_EOM.
If fed with packets with len == 0 and VIRTIO_VSOCK_SEQ_EOM,
a very large number of packets can be queued
because vvs->rx_bytes stays at 0.
Fix this by estimating the skb metadata size:
(Number of skbs in the queue) * SKB_TRUESIZE(0)59dCVE-2017-11003—3.5%
——1——CVE-2017-9700—3.5%
——1——CVE-2017-11024—3.5%
——1——