Vulnerabilidades explotables hoy
367,284en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,295
- Alto9,354
- Medio5,355
- Bajo528
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2021-39773—1.4%
——0——CVE-2024-32014—1.4%
——0——CVE-2026-42190—1.4%
——0——CVE-2021-39761—1.4%
——0——CVE-2026-22537—1.4%
——0——CVE-2021-0966—1.4%
——0——CVE-2023-21173—1.4%
——0——CVE-2021-25468—1.4%
——0——CVE-2026-534644.0 MED1.4%
——0ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, when providing invalid options to the wand option parser a small memory leak will occur. This issue has been patched in version 7.1.2-25.40dCVE-2021-1012—1.4%
——0——CVE-2024-23382—1.4%
——0——CVE-2025-21059—1.4%
——0——CVE-2025-48598—1.4%
——0——CVE-2022-25821—1.4%
——0——CVE-2023-32853—1.4%
——0——CVE-2026-645107.0 ALT1.4%
——0In the Linux kernel, the following vulnerability has been resolved:
ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup
If acpi_nfit_init() fails after adding the acpi_desc object to the
acpi_descs list, that object is never removed from that list because
the acpi_nfit_shutdown() devm action is not added for the NFIT device
in that case. Next, the acpi_nfit_init() failure causes
acpi_nfit_probe() to fail, the acpi_desc object is freed, and a
dangling pointer is left behind in the acpi_descs. Any subsequent
ACPI Machine Check Exception will trigger nfit_handle_mce() which
iterates over acpi_descs and so a use-after-free will occur.
Moreover, if acpi_nfit_probe() returns 0 after installing a notify
handler for the NFIT device and without allocating the acpi_desc
object and setting the NFIT device's driver data pointer, the
acpi_desc object will be allocated by acpi_nfit_update_notify()
and acpi_nfit_init() will be called to initialize it. Regardless
of whether or not acpi_nfit_init() fails in that case, the
acpi_nfit_shutdown() devm action is not added for the NFIT device
and acpi_desc is never removed from the acpi_descs list. If the
acpi_desc object is freed subsequently on driver removal, any
subsequent ACPI MCE will lead to a use-after-free like in the
previous case.
To address the first issue mentioned above, make acpi_nfit_probe()
call acpi_nfit_shutdown() directly on acpi_nfit_init() failures and
to address the other one, add a remove callback to the driver and
make it call acpi_nfit_shutdown(). Also, since it is now possible to
pass NULL to acpi_nfit_shutdown() or the acpi_desc object passed to it
may not have been initialized, add checks against NULL for acpi_desc and
its nvdimm_bus field to that function and make acpi_nfit_unregister()
clear the latter after unregistering the NVDIMM bus.15dCVE-2021-1013—1.4%
——0——CVE-2022-20297—1.4%
——0——CVE-2021-1026—1.4%
——0——CVE-2021-39775—1.4%
——0——CVE-2025-7841—1.4%
——0——CVE-2021-39791—1.4%
——0——CVE-2026-152135.3 MED1.4%
——0The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-transfer settlement callback: an unauthenticated request can flip an order from unpaid to settled purely from an order number and a status flag, with no signature, amount, or origin check. Because these are pay-later methods, an attacker can mark their own unpaid order as settled and obtain fulfilment without paying.5dCVE-2023-32863—1.4%
——0——CVE-2026-186067.8 ALT1.4%
——0A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program Files (x86)\Razer\RzUpdateEngineService\RzUpdateService.exe of the component Named Pipe Handler. Executing a manipulation of the argument lpThreadParameter can lead to improper privilege management. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.19dCVE-2024-23381—1.4%
——0——CVE-2024-34729—1.4%
——0——CVE-2026-193735.3 MED1.4%
——0A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeRequest of the file src/index.ts of the component BaseConfigSchema. Executing a manipulation of the argument apiUrl can lead to server-side request forgery. It is possible to launch the attack on the local host. The project was informed of the problem early through an issue report but has not responded yet.19dCVE-2024-49834—1.4%
——0——CVE-2022-20286—1.4%
——0——CVE-2021-39631—1.4%
——0——CVE-2022-42766—1.4%
——0——CVE-2024-33028—1.4%
——0——CVE-2025-48511—1.4%
——0——CVE-2022-20185—1.4%
——0——CVE-2026-585546.6 MED1.4%
——0Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.47dCVE-2025-48502—1.4%
——0——CVE-2024-56414—1.4%
——0——CVE-2021-39745—1.4%
——0——CVE-2023-28546—1.4%
——0——