Vulnerabilidades explotables hoy
367,922en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,687
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,397
- Alto9,645
- Medio5,598
- Bajo550
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-22270—3.4%
——1——CVE-2026-355685.7 MED3.4%
——1MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to 1.0.0, the java-sdk contains a DNS rebinding vulnerability. This vulnerability allows an attacker to access a locally or network-private java-sdk MCP server via a victims browser that is either local, or network adjacent. This allows an attacker to make any tool call to the server as if they were a locally running MCP connected AI agent. This vulnerability is fixed in 1.0.0.40dCVE-2022-32595—3.4%
——1——CVE-2024-21981—3.4%
——1——CVE-2025-11886—3.4%
——1——CVE-2025-20736—3.4%
——1——CVE-2020-11298—3.4%
——1——CVE-2023-39843—3.4%
——1——CVE-2024-53865—3.4%
——1——CVE-2020-0284—3.4%
——1——CVE-2025-31908—3.4%
——1——CVE-2023-30713—3.4%
——1——CVE-2025-66266—3.4%
——1——CVE-2024-21792—3.4%
——1——CVE-2023-20508—3.4%
——1——CVE-2026-35368—3.4%
——1——CVE-2024-23351—3.4%
——1——CVE-2026-29089—3.4%
——1——CVE-2026-45027—3.4%
——1——CVE-2024-20900—3.4%
——1——CVE-2022-50292—3.4%
——1——CVE-2025-26443—3.4%
——1——CVE-2026-770135.3 MED3.4%
——1The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not restrict which of its handler methods a request may invoke, and performs no capability or nonce check on them, allowing unauthenticated users to create WordPress user accounts and taxonomy terms.2dCVE-2024-48869—3.4%
——1——CVE-2026-709623.3 BAJ3.4%
——1Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).8dCVE-2026-763935.9 MED3.4%
——1In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by another user by sending a concurrent upload request for the same model name, causing the resulting model lookup entry to reference attacker-controlled content. The race condition is possible because Splunk AI Toolkit does not verify that the uploaded content belongs to the request that creates the model lookup entry. For more information see Troubleshoot the Splunk Machine Learning Toolkit (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/machine-learning-toolkit-user-guide/5.5.0/troubleshooting-mltk/troubleshoot-the-splunk-machine-learning-toolkit) in the Splunk documentation.7dCVE-2026-638437.8 ALT3.4%
——1In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring
JPEG rings do not support 64-bit user fence writes, reject CS
submissions with user fences.
(cherry picked from commit f05d0a4f21fc720116d6e238f23308b199891058)37dCVE-2023-30718—3.4%
——1——CVE-2026-606086.1 MED3.4%
——1Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Institutional Methodology Need Analysis). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise CS Financial Aid executes to compromise PeopleSoft Enterprise CS Financial Aid. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Financial Aid accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise CS Financial Aid accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).28dCVE-2025-31623—3.4%
——1——CVE-2025-8700—3.4%
——1——CVE-2025-58430—3.4%
——1——CVE-2025-24486—3.4%
——1——CVE-2026-26072—3.4%
——1——CVE-2026-711196.4 MED3.4%
——1Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).9dCVE-2026-44995—3.4%
——1——CVE-2025-31617—3.4%
——1——CVE-2023-53231—3.4%
——1——CVE-2019-2117—3.4%
——1——CVE-2025-8597—3.4%
——1——