Vulnerabilidades explotables hoy
367,284en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,295
- Alto9,354
- Medio5,355
- Bajo528
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2025-0029—1.7%
——1——CVE-2026-41915—1.7%
——1——CVE-2026-33612—1.7%
——1——CVE-2026-204686.0 MED1.7%
——1In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00833804; Issue ID: MSV-6741.3dCVE-2025-21424—1.7%
——1——CVE-2026-632658.0 ALT1.7%
——1Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints - Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, matching component/item permissions and trusted server-generated form configuration. Authenticated lower-privileged users or CSRF attacks could invoke lookups or mutations outside their authorization.35dCVE-2021-0903—1.7%
——1——CVE-2024-45444—1.7%
——1——CVE-2025-14763—1.7%
——1——CVE-2024-43059—1.7%
——1——CVE-2022-39905—1.7%
——1——CVE-2025-68972—1.7%
——1——CVE-2021-0896—1.7%
——1——CVE-2026-24918—1.7%
——1——CVE-2021-0381—1.7%
——1——CVE-2022-0882—1.7%
——1——CVE-2022-48223—1.7%
——1——CVE-2024-0037—1.7%
——1——CVE-2021-25339—1.7%
——1——CVE-2026-24914—1.7%
——1——CVE-2022-20271—1.7%
——1——CVE-2024-51517—1.7%
——1——CVE-2023-52711—1.7%
——1——CVE-2024-34723—1.7%
——1——CVE-2023-52712—1.7%
——1——CVE-2025-31948—1.7%
——1——CVE-2021-0658—1.7%
——1——CVE-2024-43062—1.7%
——1——CVE-2026-25046—1.7%
——1——CVE-2024-8885—1.7%
——1——CVE-2025-48077—1.7%
——1——CVE-2024-31328—1.7%
——1——CVE-2021-39814—1.7%
——1——CVE-2026-35344—1.7%
——1——CVE-2025-62317—1.7%
——1——CVE-2026-95673.3 BAJ1.7%
——1A security flaw has been discovered in GPAC up to 2.4.0. Affected is the function MergeFragment of the file src/isomedia/isom_intern.c of the component MP4Box. The manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The patch is identified as 525bf1af642c30af04e4df5345e6d798c0a4d8a1. It is advisable to implement a patch to correct this issue.40dCVE-2026-40928—1.7%
——1——CVE-2025-13669—1.7%
——1——CVE-2022-21769—1.7%
——1——CVE-2023-40075—1.7%
——1——