Vulnerabilidades explotables hoy
367,284en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,274
- Alto9,334
- Medio5,332
- Bajo522
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2025-53311—1.4%
——0——CVE-2025-53317—1.4%
——0——CVE-2024-39342—1.4%
——0——CVE-2025-35978—1.4%
——0——CVE-2025-58127—1.4%
——0——CVE-2025-38362—1.4%
——0——CVE-2026-497447.8 ALT1.4%
——0Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory.
Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation which escapes virtualization boundaries.19dCVE-2023-20711—1.4%
——0——CVE-2025-62628—1.4%
——0——CVE-2025-53312—1.4%
——0——CVE-2022-39854—1.4%
——0——CVE-2026-610795.8 MED1.4%
——0Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.2. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Oracle GoldenGate. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle GoldenGate accessible data as well as unauthorized update, insert or delete access to some of Oracle GoldenGate accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate. CVSS 3.1 Base Score 5.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:H).25dCVE-2024-5899—1.4%
——0——CVE-2023-21655—1.4%
——0——CVE-2023-33068—1.4%
——0——CVE-2026-690934.6 MED1.4%
——0Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs persistent Category Report configuration changes based on GET parameters (delete and copy). An attacker can trick an authenticated administrator into visiting a crafted URL to delete or duplicate Category Report configurations, affecting the integrity and availability of that module's configuration.28dCVE-2026-34855—1.4%
——0——CVE-2026-204765.5 MED1.4%
——0In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981532; Issue ID: MSV-7660.12dCVE-2025-48825—1.4%
——0——CVE-2021-39624—1.4%
——0——CVE-2025-54620—1.4%
——0——CVE-2023-32857—1.4%
——0——CVE-2023-48414—1.4%
——0——CVE-2023-48405—1.4%
——0——CVE-2023-43525—1.4%
——0——CVE-2026-24775—1.4%
——0——CVE-2021-0986—1.4%
——0——CVE-2026-3315—1.4%
——0——CVE-2025-53305—1.4%
——0——CVE-2023-32856—1.4%
——0——CVE-2023-21654—1.4%
——0——CVE-2017-9697—1.4%
——0——CVE-2024-20292—1.4%
——0——CVE-2026-497437.8 ALT1.4%
——0Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs.
During workload submission involving a fence exported by the GPU driver, the reference count of the underlying synchronisation primitive is not properly incremented. This can be exploited, by destroying the exported fence and prematurely release the underlying primitive, resulting in a potential use-after-free condition.19dCVE-2025-52772—1.4%
——0——CVE-2024-49837—1.4%
——0——CVE-2024-20144—1.4%
——0——CVE-2021-1006—1.4%
——0——CVE-2023-21636—1.4%
——0——CVE-2026-540998.8 ALT1.4%
——0A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-administrator privileges and enabling full cluster takeover.33d