Vulnerabilidades explotables hoy
367,284en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,295
- Alto9,356
- Medio5,353
- Bajo528
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-31549—2.3%
——1——CVE-2022-25709—2.3%
——1——CVE-2022-33233—2.3%
——1——CVE-2022-20029—2.3%
——1——CVE-2025-12407—2.3%
——1——CVE-2026-23360—2.3%
——1——CVE-2026-31510—2.3%
——1——CVE-2022-20033—2.3%
——1——CVE-2026-41355—2.3%
——1——CVE-2025-38308—2.3%
——1——CVE-2022-33277—2.3%
——1——CVE-2026-43279—2.3%
——1——CVE-2016-200617.8 ALT2.3%
——1sheed AntiVirus 2.3 contains an unquoted service path vulnerability in the ShavProt service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can insert a malicious executable in the unquoted path and trigger service restart or system reboot to execute code with LocalSystem privileges.42dCVE-2025-45526—2.3%
——1——CVE-2026-400254.4 MED2.3%
——1The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where the wrapped_key_parser class follows attacker-controlled length fields without bounds checking, causing heap reads past the allocated buffer. An attacker can craft a malicious APFS disk image that triggers information disclosure or crashes when processed by any Sleuth Kit tool that parses APFS volumes.38dCVE-2022-40531—2.3%
——1——CVE-2026-31497—2.3%
——1——CVE-2023-40727—2.3%
——1——CVE-2022-25660—2.3%
——1——CVE-2026-232727.8 ALT2.3%
——1In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: unconditionally bump set->nelems before insertion
In case that the set is full, a new element gets published then removed
without waiting for the RCU grace period, while RCU reader can be
walking over it already.
To address this issue, add the element transaction even if set is full,
but toggle the set_full flag to report -ENFILE so the abort path safely
unwinds the set to its previous state.
As for element updates, decrement set->nelems to restore it.
A simpler fix is to call synchronize_rcu() in the error path.
However, with a large batch adding elements to already maxed-out set,
this could cause noticeable slowdown of such batches.59dCVE-2022-20048—2.3%
——1——CVE-2026-46108—2.3%
——1——CVE-2026-49396—2.3%
——1——CVE-2022-20035—2.3%
——1——CVE-2022-33278—2.3%
——1——CVE-2022-25711—2.3%
——1——CVE-2024-51346—2.3%
——1——CVE-2026-46083—2.3%
——1——CVE-2025-10650—2.3%
——1——CVE-2025-42992—2.3%
——1——CVE-2021-39652—2.3%
——1——CVE-2026-232845.5 MED2.3%
——1In the Linux kernel, the following vulnerability has been resolved:
net: ethernet: mtk_eth_soc: Reset prog ptr to old_prog in case of error in mtk_xdp_setup()
Reset eBPF program pointer to old_prog and do not decrease its ref-count
if mtk_open routine in mtk_xdp_setup() fails.49dCVE-2026-43242—2.3%
——1——CVE-2025-25216—2.3%
——1——CVE-2021-39676—2.3%
——1——CVE-2026-44612—2.3%
——1——CVE-2026-23061—2.3%
——1——CVE-2025-9614—2.3%
——1——CVE-2022-20203—2.3%
——1——CVE-2026-43428—2.3%
——1——