Vulnerabilidades explotables hoy
367,284en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,295
- Alto9,354
- Medio5,355
- Bajo528
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-43262—1.7%
——1——CVE-2026-23382—1.7%
——1——CVE-2026-43041—1.7%
——1——CVE-2026-29987.8 ALT1.7%
——1ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a crafted DLL file in the same directory as the program, thereby executing arbitrary code.35dCVE-2026-43457—1.7%
——1——CVE-2026-23267—1.7%
——1——CVE-2026-43105—1.7%
——1——CVE-2026-46103—1.7%
——1——CVE-2023-7265—1.7%
——1——CVE-2025-21071—1.7%
——1——CVE-2023-20774—1.7%
——1——CVE-2023-20768—1.7%
——1——CVE-2026-43270—1.7%
——1——CVE-2026-23256—1.7%
——1——CVE-2026-144795.5 MED1.7%
——1A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malicious actor may leverage this vulnerability to cause the NT AUTHORITY\SYSTEM service to terminate unexpectedly, resulting in a denial-of-service condition.5dCVE-2021-0535—1.7%
——1——CVE-2026-529215.5 MED1.7%
——1In the Linux kernel, the following vulnerability has been resolved:
netfilter: ipset: stop hash:* range iteration at end
The following hash set variants:
hash:ip,mark
hash:ip,port
hash:ip,port,ip
hash:ip,port,net
iterate IPv4 ranges with a 32-bit iterator.
The iterator must stop once the last address in the requested range has
been processed. Advancing it once more can move the traversal state past
the end of the request, so a later retry may continue from an unintended
position.
Handle the iterator increment explicitly at the end of the loop and stop
once the upper bound has been processed. This keeps the existing retry
behaviour intact for valid ranges while preventing traversal from
continuing past the original boundary.54dCVE-2026-23266—1.7%
——1——CVE-2026-31672—1.7%
——1——CVE-2026-23097—1.7%
——1——CVE-2026-31425—1.7%
——1——CVE-2026-64634—1.7%
——1A vulnerability allowing local privilege escalation to the Reporter service context.27dCVE-2026-43480—1.7%
——1——CVE-2022-20395—1.7%
——1——CVE-2026-43455—1.7%
——1——CVE-2026-43484—1.7%
——1——CVE-2026-529285.5 MED1.7%
——1In the Linux kernel, the following vulnerability has been resolved:
af_unix: Reject SIOCATMARK on non-stream sockets
SIOCATMARK reports whether the receive queue is at the urgent mark for
MSG_OOB.
In AF_UNIX, MSG_OOB is supported only for SOCK_STREAM sockets.
SOCK_DGRAM and SOCK_SEQPACKET reject MSG_OOB in sendmsg() and recvmsg(),
so they should not support SIOCATMARK either.
Return -EOPNOTSUPP for non-stream sockets before checking the receive
queue.55dCVE-2025-9408—1.7%
——1——CVE-2026-23120—1.7%
——1——CVE-2025-11790—1.7%
——1——CVE-2025-68083—1.7%
——1——CVE-2023-22315—1.7%
——1——CVE-2026-816866.2 MED1.7%
——1openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Properties.Set method performs neither a polkit authorization check nor value validation. Any local user on the system bus can call Set without authorization and set MaxConcurrentOperations (to 0/negative, causing the concurrency gate to refuse all subsequent operations, or to a huge value removing the limit) or the unbounded DefaultTimeout, resulting in a persistent denial of service of the root daemon. The D-Bus service exists only on the 1.4.x line and was removed in 1.5.x.3dCVE-2026-43340—1.7%
——1——CVE-2026-43264—1.7%
——1——CVE-2026-20447—1.7%
——1——CVE-2026-43277—1.7%
——1——CVE-2026-255996.3 MED1.7%
——1Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation on aggregated data, can lead to stored XSS that enables theft of cookies from the pump’s web control interface. Older Orca heat pump devices communicating with the Orca server over an
unencrypted and unauthenticated HTTP connection on a non-secure port specifically enable an
attacker to impersonate a legitimate device and inject malicious
payloads. This enables the insertion of harmful code directly
into the Orca user portal, potentially compromising user accounts,
exposing sensitive information, and allowing further unauthorized
actions within the portal.41dCVE-2026-529265.5 MED1.7%
——1In the Linux kernel, the following vulnerability has been resolved:
batman-adv: clear current gateway during teardown
batadv_gw_node_free() removes the gateway list entries during mesh teardown,
but it does not clear the currently selected gateway. This leaves stale
gateway state behind across cleanup and can break a later mesh recreation.
Clear bat_priv->gw.curr_gw before walking the gateway list so the selected
gateway reference is dropped as part of teardown.55dCVE-2017-18307—1.7%
——1——