Vulnerabilidades explotables hoy
367,284en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,295
- Alto9,354
- Medio5,355
- Bajo528
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2023-43550—1.4%
——0——CVE-2026-661515.5 MED1.4%
——0SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.3dCVE-2021-0987—1.4%
——0——CVE-2025-35972—1.4%
——0——CVE-2024-23374—1.4%
——0——CVE-2026-33243—1.4%
——0——CVE-2025-53947—1.4%
——0——CVE-2023-43513—1.4%
——0——CVE-2018-9486—1.4%
——0——CVE-2026-35249—1.4%
——0——CVE-2026-20666—1.4%
——0——CVE-2026-772357.3 ALT1.4%
——0Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local users to cause a use-after-free condition in secure-world memory via the SVC handler for secure context deallocation. To remediate this issue, users should upgrade to version 11.3.1 or later.4dCVE-2026-155515.5 MED1.4%
——0Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Overflow Buffers.
This issue affects .49dCVE-2026-20714—1.4%
——0——CVE-2021-0989—1.4%
——0——CVE-2023-33115—1.4%
——0——CVE-2023-28548—1.4%
——0——CVE-2023-28564—1.4%
——0——CVE-2026-681037.1 ALT1.4%
——0In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: reject mapping a reserved doorbell to a new queue
When creating an user-queue, the user space
provides a doorbell BO handle and an offset within
the bo to obtain a doorbell.
However current implementation using xa_store_irq()
to store a doorbell, which allows a later queue created
with the same BO and offset parameters to overwrite an
existing queue and doorbell mapping.
This can cause problems like misrouting fence IRQ
processing to a wrong queue, and mislead the cleanup
process of one queue erasing the mapping of another queue.
This commit fixes this issue by replacing xa_store_irq with
xa_insert_irq, which rejects mapping a reserved
doorbell to a newly created queue
(cherry picked from commit 6244eae22966350db52faf9c1369d3b2ffc5de4e)15dCVE-2026-633107.1 ALT1.4%
——0NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.6hCVE-2024-23379—1.4%
——0——CVE-2024-583502.9 BAJ1.4%
——0Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initialization order of the SleighArchitecture::translators and XmlArchitectureCapability singletons. Attackers can trigger an infinite loop or denial of service during shutdown by exploiting the unsafe destruction order that causes iteration over deallocated memory.48dCVE-2023-33035—1.4%
——0——CVE-2026-744197.3 ALT1.4%
——0In the Linux kernel, the following vulnerability has been resolved:
accel/amdxdna: Adjust size for copy_to_user()
The amount of data returned to user space should be limited by the buffer
size provided by the application. If the buffer is smaller than the data
size, return only the portion that fits instead of failing.15dCVE-2024-56451—1.4%
——0——CVE-2026-23195—1.4%
——0——CVE-2023-28558—1.4%
——0——CVE-2024-43058—1.4%
——0——CVE-2025-32038—1.4%
——0——CVE-2022-20321—1.4%
——0——CVE-2024-42032—1.4%
——0——CVE-2023-33059—1.4%
——0——CVE-2026-491325.4 MED1.4%
——0OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary HTML or JavaScript by embedding payloads in the certificate description field via the trust certificate API. The unsanitized description value is persisted and later rendered in the Dashboard Certificates widget through Certificates.js, which interpolates the raw value into HTML attribute and text content sinks without encoding, causing injected scripts to execute in the browser of any authenticated user who views the Dashboard, enabling session hijacking or credential theft.27dCVE-2023-43515—1.4%
——0——CVE-2023-33031—1.4%
——0——CVE-2026-73513.1 BAJ1.4%
——0Race in MHTML in Google Chrome prior to 147.0.7727.138 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: High)39dCVE-2023-53310—1.4%
——0——CVE-2026-26224—1.4%
——0——CVE-2024-23376—1.4%
——0——CVE-2025-48602—1.4%
——0——