Vulnerabilidades explotables hoy
367,284en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,295
- Alto9,354
- Medio5,355
- Bajo528
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-43262—1.7%
——1——CVE-2023-20761—1.7%
——1——CVE-2025-10865—1.7%
——1——CVE-2021-0389—1.7%
——1——CVE-2023-20760—1.7%
——1——CVE-2025-36058—1.7%
——1——CVE-2026-43269—1.7%
——1——CVE-2022-42758—1.7%
——1——CVE-2025-29938—1.7%
——1——CVE-2025-20082—1.7%
——1——CVE-2025-32088—1.7%
——1——CVE-2026-23096—1.7%
——1——CVE-2026-23125—1.7%
——1——CVE-2026-43472—1.7%
——1——CVE-2021-0382—1.7%
——1——CVE-2026-43043—1.7%
——1——CVE-2026-23258—1.7%
——1——CVE-2017-18306—1.7%
——1——CVE-2024-3082—1.7%
——1——CVE-2023-20767—1.7%
——1——CVE-2025-29935—1.7%
——1——CVE-2026-1713—1.7%
——1——CVE-2022-20547—1.7%
——1——CVE-2026-43473—1.7%
——1——CVE-2025-38520—1.6%
——0——CVE-2021-30162—1.6%
——0——CVE-2025-22849—1.6%
——0——CVE-2020-9128—1.6%
——0——CVE-2023-32860—1.6%
——0——CVE-2026-43107—1.6%
——0——CVE-2023-21049—1.6%
——0——CVE-2026-462615.5 MED1.6%
——0In the Linux kernel, the following vulnerability has been resolved:
spi: wpcm-fiu: Fix potential NULL pointer dereference in wpcm_fiu_probe()
platform_get_resource_byname() can return NULL, which would cause a crash
when passed the pointer to resource_size().
Move the fiu->memory_size assignment after the error check for
devm_ioremap_resource() to prevent the potential NULL pointer dereference.42dCVE-2026-23373—1.6%
——0——CVE-2026-592868.1 ALT1.6%
——0The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresource Integrity checks. An attacker can inject malicious code in those scripts and execute arbitrary code on the browser loading the GraphiQL page.
Spring for GraphQL 2.0.0 - 2.0.4
Spring for GraphQL 1.4.0 - 1.4.6
Spring for GraphQL 1.1.0 - 1.3.9
Spring for GraphQL 1.0.0 - 1.0.77hCVE-2026-398243.3 BAJ1.6%
——0NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.39dCVE-2022-20331—1.6%
——0——CVE-2026-70652—1.6%
——0libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr when a pipeline enlarges an incoming JPEG to a very large output before encoding a gain map through VipsForeignSaveUhdr. The undersized allocation can cause a heap buffer over-read that may disclose adjacent data or crash the process. This issue is fixed in version 8.18.3.10dCVE-2024-58252—1.6%
——0——CVE-2021-22340—1.6%
——0——CVE-2026-70654—1.6%
——0libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applications that define unusual custom libvips sources and use them to process untrusted uncompressed PPM images can trigger a max/min error in vips_source_read_to_memory in libvips/iofuncs/source.c. The function uses VIPS_MAX instead of VIPS_MIN when selecting the remaining read size, allowing up to 4032 bytes to be written beyond the allocated heap buffer and causing memory corruption or a process crash. This issue is fixed in version 8.18.3.11d