Vulnerabilidades explotables hoy
367,284en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,274
- Alto9,334
- Medio5,332
- Bajo522
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2022-20354—1.4%
——0——CVE-2026-41398—1.4%
——0——CVE-2026-29521—1.4%
——0——CVE-2026-6412—1.4%
——0——CVE-2026-20917—1.4%
——0Exposure of sensitive information caused by incorrect data forwarding during transient execution for some Intel(R) Processors within Ring 0: Hypervisor and Kernel may allow information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.19dCVE-2022-20250—1.4%
——0——CVE-2025-48602—1.4%
——0——CVE-2025-24327—1.4%
——0——CVE-2023-28560—1.4%
——0——CVE-2022-33216—1.4%
——0——CVE-2023-33118—1.4%
——0——CVE-2023-33120—1.4%
——0——CVE-2023-28539—1.4%
——0——CVE-2025-38738—1.4%
——0——CVE-2025-32449—1.4%
——0——CVE-2023-33034—1.4%
——0——CVE-2026-456105.7 MED1.4%
——0WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/LoginControl/set.json.php accepts POST type=set2FA value=false, calls LoginControl::setUser2FA(User::getId(), false) on the session-authenticated user, and returns. There is no forbidIfIsUntrustedRequest() call, no isTokenValid() check, no X-CSRF-Token/SameSite enforcement, and no re-authentication step. A cross-origin page that the victim visits while logged into the AVideo dashboard issues the POST via a hidden form (or fetch without credentials:"omit") and disables the victim's 2FA in one request.42dCVE-2026-18751—1.4%
——0External control of file name or path vulnerability in Citrix WorkSpace App on MacOS.
This issue affects WorkSpace App: 2607.3dCVE-2026-21996—1.4%
——0——CVE-2024-580238.4 ALT1.4%
——0Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.39dCVE-2023-4327—1.4%
——0——CVE-2025-62497—1.4%
——0——CVE-2021-0983—1.4%
——0——CVE-2025-31647—1.4%
——0——CVE-2024-23376—1.4%
——0——CVE-2026-26224—1.4%
——0——CVE-2023-53310—1.4%
——0——CVE-2021-0990—1.4%
——0——CVE-2021-0995—1.4%
——0——CVE-2025-32001—1.4%
——0——CVE-2023-28557—1.4%
——0——CVE-2025-7007—1.4%
——0——CVE-2025-36568—1.4%
——0——CVE-2023-28546—1.4%
——0——CVE-2026-55373—1.4%
——0——CVE-2023-4328—1.4%
——0——CVE-2025-27246—1.4%
——0——CVE-2023-33018—1.4%
——0——CVE-2024-43066—1.4%
——0——CVE-2023-22384—1.4%
——0——