Vulnerabilidades explotables hoy
367,284en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,687
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,295
- Alto9,357
- Medio5,357
- Bajo528
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-531497.1 ALT2.6%
——1In the Linux kernel, the following vulnerability has been resolved:
thunderbolt: Bound root directory content to block size
__tb_property_parse_dir() does not check that content_offset +
content_len fits within block_len for the root directory case.
When rootdir->length equals or exceeds block_len - 2, the entry
loop reads past the allocated property block.
Add a bounds check after computing content_offset and content_len
to reject directories whose content extends past the block.57dCVE-2026-5397—2.6%
——1——CVE-2026-107244.8 MED2.6%
——1The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the connected source.42dCVE-2026-551654.8 MED2.6%
——1Lemur manages TLS certificate creation. Prior to 1.9.2, the JWT verifier in lemur/auth/service.py:130-137 used fetch_token_header to read header_data["alg"] from an unverified token and passed that attacker-controlled value to decode_with_multiple_secrets. PyJWT 2.x rejects alg=none with the configured key, so the flaw is a defense-in-depth gap rather than a direct authentication bypass in the shipped configuration. The unpinned algorithm can become exploitable after an asymmetric-signing migration through algorithm confusion, and it weakens algorithm-based anomaly detection because the token chooses the recorded value. A separate disclosure of LEMUR_TOKEN_SECRET would also permit forged HS256 tokens, although that disclosure is an independent prerequisite. The fix introduces the server-controlled LEMUR_TOKEN_ALGORITHMS allowlist and defaults it to HS256. This issue is fixed in version 1.9.2.14dCVE-2025-64304—2.6%
——1——CVE-2025-383147.3 ALT2.6%
——1In the Linux kernel, the following vulnerability has been resolved:
virtio-pci: Fix result size returned for the admin command completion
The result size returned by virtio_pci_admin_dev_parts_get() is 8 bytes
larger than the actual result data size. This occurs because the
result_sg_size field of the command is filled with the result length
from virtqueue_get_buf(), which includes both the data size and an
additional 8 bytes of status.
This oversized result size causes two issues:
1. The state transferred to the destination includes 8 bytes of extra
data at the end.
2. The allocated buffer in the kernel may be smaller than the returned
size, leading to failures when reading beyond the allocated size.
The commit fixes this by subtracting the status size from the result of
virtqueue_get_buf().
This fix has been tested through live migrations with virtio-net,
virtio-net-transitional, and virtio-blk devices.33dCVE-2025-6062—2.6%
——1——CVE-2025-57729—2.6%
——1——CVE-2021-479534.3 MED2.6%
——1OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by sending crafted requests to the account/password endpoint. Attackers can trick authenticated users into submitting hidden forms with new password values in the 'password' and 'confirm' parameters to hijack accounts.38dCVE-2026-84804.3 MED2.6%
——1A vulnerability was discovered on Stormshield Network Security 4.3.0 to 4.3.41 (included), 4.4.0 to 4.8.15 (included) , 5.0.2 EA to 5.0.5 (included)
A revoked client certificate can still be used to authenticate to the captive‑admin portal, allowing an attacker who possesses the revoked certificate to gain administrative access.62dCVE-2025-5936—2.6%
——1——CVE-2024-47588—2.6%
——1——CVE-2026-32054—2.6%
——1——CVE-2025-8512—2.6%
——1——CVE-2026-43437—2.6%
——1——CVE-2026-132086.5 MED2.6%
——1A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity (namespace/name) solely from the request body without validating it against the connection's origin. Each virt-launcher pod connects through a per-VMI pipe socket, but no identity tag is propagated from the pipe path to the server handlers. This allows a compromised virt-launcher process to send forged domain lifecycle events for any other VMI scheduled on the same node, causing virt-handler to erroneously update that VMI's state and disrupt its lifecycle management.57dCVE-2022-38659—2.6%
——1——CVE-2021-0617—2.6%
——1——CVE-2025-5930—2.6%
——1——CVE-2022-20213—2.6%
——1——CVE-2025-4592—2.6%
——1——CVE-2026-43179—2.6%
——1——CVE-2026-45174—2.6%
——1——CVE-2025-13453—2.6%
——1——CVE-2026-41342—2.6%
——1——CVE-2022-20215—2.6%
——1——CVE-2025-32890—2.6%
——1——CVE-2026-746037.1 ALT2.6%
——1In the Linux kernel, the following vulnerability has been resolved:
ptp: ocp: Fix board ID over-read
The EEPROM board ID is a fixed 13-byte field and is not guaranteed to
contain a NUL terminator. Passing it directly to
devlink_info_version_fixed_put() treats it as a C string and may read
beyond the field.
Format at most OCP_BOARD_ID_LEN bytes into the existing local buffer
before reporting the ID. Use a precision limit because the snprintf()
output size alone does not bound the source string scan.7dCVE-2021-35079—2.6%
——1——CVE-2026-43235—2.6%
——1——CVE-2021-39707—2.6%
——1——CVE-2021-25334—2.6%
——1——CVE-2021-0616—2.6%
——1——CVE-2022-50045—2.6%
——1——CVE-2022-42777—2.6%
——1——CVE-2019-10486—2.6%
——1——CVE-2021-0414—2.6%
——1——CVE-2026-1578—2.6%
——1——CVE-2025-6781—2.6%
——1——CVE-2021-39703—2.6%
——1——