Vulnerabilidades explotables hoy
367,922en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,687
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,397
- Alto9,645
- Medio5,598
- Bajo550
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-560853.3 BAJ3.3%
——1Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of uninitialized resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.55dCVE-2025-37110—3.3%
——1——CVE-2025-42927—3.3%
——1——CVE-2025-31971—3.3%
——1——CVE-2020-13842—3.3%
——1——CVE-2025-58818—3.3%
——1——CVE-2025-53219—3.3%
——1——CVE-2024-47258—3.3%
——1——CVE-2026-4530—3.3%
——1——CVE-2025-20975—3.3%
——1——CVE-2025-20733—3.3%
——1——CVE-2025-48517—3.3%
——1——CVE-2026-71865.4 MED3.3%
——1Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with dashboard editing permissions to store a URL with a dangerous URI scheme such as javascript: that executes scripts in other users' browsers when they view the dashboard.41dCVE-2023-20920—3.3%
——1——CVE-2025-53262—3.3%
——1——CVE-2025-48328—3.3%
——1——CVE-2025-20728—3.3%
——1——CVE-2025-68712—3.3%
——1——CVE-2026-5441—3.3%
——1——CVE-2026-46080—3.3%
——1——CVE-2022-32620—3.3%
——1——CVE-2026-465465.4 MED3.3%
——1Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.53.0, an authenticated user could supply specially crafted content in certain user-editable fields that, when surfaced in page metadata, caused visitors' browsers to navigate to an attacker-chosen URL. This issue has been patched in version 2.53.0.41dCVE-2026-45536—3.3%
——1——CVE-2026-03963.1 BAJ3.3%
——1An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via either DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI.39dCVE-2024-14025—3.3%
——1——CVE-2025-6390—3.3%
——1——CVE-2026-353917.5 ALT3.3%
——1Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the getClientIP() function in lib/admin/session.ts trusted the first (leftmost) entry of the X-Forwarded-For header, which is fully controlled by the client. An attacker could forge their source IP address to bypass IP-based rate limiting (enabling brute-force attacks against the admin login) or forge audit log entries (making malicious activity appear to originate from arbitrary IP addresses). This vulnerability is fixed in 1.4.11.39dCVE-2023-538047.8 ALT3.3%
——1In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix use-after-free bug of nilfs_root in nilfs_evict_inode()
During unmount process of nilfs2, nothing holds nilfs_root structure after
nilfs2 detaches its writer in nilfs_detach_log_writer(). However, since
nilfs_evict_inode() uses nilfs_root for some cleanup operations, it may
cause use-after-free read if inodes are left in "garbage_list" and
released by nilfs_dispose_list() at the end of nilfs_detach_log_writer().
Fix this issue by modifying nilfs_evict_inode() to only clear inode
without additional metadata changes that use nilfs_root if the file system
is degraded to read-only or the writer is detached.29dCVE-2026-08115.4 MED3.3%
——1The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9. This is due to missing or incorrect nonce validation on the 'vsz_cf7_save_setting_callback' function. This makes it possible for unauthenticated attackers to delete form entry via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.39dCVE-2025-20735—3.3%
——1——CVE-2026-31879—3.3%
——1——CVE-2023-540427.8 ALT3.3%
——1In the Linux kernel, the following vulnerability has been resolved:
powerpc/64s: Fix VAS mm use after free
The refcount on mm is dropped before the coprocessor is detached.29dCVE-2023-26593—3.3%
——1——CVE-2026-409737.0 ALT3.3%
——1A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack persists across application restarts, this may allow the attacker to read session information and hijack authenticated users or deploy a gadget chain and execute code as the application's user.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); predictable temp directory / `ApplicationTemp` ownership verification. Versions that are no longer supported are also affected per vendor advisory.39dCVE-2025-4582—3.3%
——1——CVE-2026-57292—3.3%
——1——CVE-2020-10842—3.3%
——1——CVE-2018-21082—3.3%
——1——CVE-2026-46609—3.3%
——1——CVE-2024-22432—3.3%
——1——