Vulnerabilidades explotables hoy
367,284en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,274
- Alto9,334
- Medio5,332
- Bajo522
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2025-53315—1.4%
——0——CVE-2025-58125—1.4%
——0——CVE-2023-32282—1.4%
——0——CVE-2026-691086.0 MED1.4%
——0A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and plant malicious files as root, leading to full system compromise.3dCVE-2026-138447.8 ALT1.3%
——0Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)61dCVE-2026-447554.3 MED1.3%
——0SAP Business Objects Business Intelligence Platform does not sufficiently validate email sending parameters supplied by authenticated users, resulting in an email spoofing vulnerability.This vulnerability has a low impact on integrity and does not affect the confidentiality and availability of the application.40dCVE-2026-191917.8 ALT1.3%
——0A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe of the component DrivePoolService. Such manipulation leads to permission issues. The attack must be carried out locally. The exploit has been disclosed publicly and may be used.19dCVE-2025-14999—1.3%
——0——CVE-2024-36503—1.3%
——0——CVE-2023-21626—1.3%
——0——CVE-2025-21040—1.3%
——0——CVE-2022-20537—1.3%
——0——CVE-2025-31173—1.3%
——0——CVE-2024-11604—1.3%
——0——CVE-2026-46654—1.3%
——0Plonky3 is a toolkit for polynomial IOPs (PIOPs). Prior to versions 0.4.3 and 0.5.3, an attacker controlling prover-side observations can craft distinct transcripts that produce identical challenges, breaking the binding property of Fiat-Shamir. This issue has been patched in versions 0.4.3 and 0.5.3.40dCVE-2024-23737—1.3%
——0——CVE-2025-0759—1.3%
——0——CVE-2024-34720—1.3%
——0——CVE-2022-20533—1.3%
——0——CVE-2025-15584—1.3%
——0——CVE-2026-471654.1 MED1.3%
——0ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, the distributed pixel cache was originally designed to operate without a challenge–response authentication model. This has been changed in versions 6.9.13-48 and 7.1.2-23.40dCVE-2022-50379—1.3%
——0——CVE-2026-142397.1 ALT1.3%
——0The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label taken from a request parameter, and does not escape that label when echoing it on the filter admin page, allowing an unauthenticated attacker to trick a logged-in administrator into storing JavaScript that then executes in the admin area (stored Cross-Site Scripting via CSRF).27dCVE-2022-30723—1.3%
——0——CVE-2026-50602—1.3%
——0A security vulnerability has been identified in Planet9 due to incorrect file permissions assigned to an application executable used by the Planet9 background service. The service runs with SYSTEM privileges, while the affected executable grants excessive permissions to non-administrative users. As a result, an authenticated local user could potentially modify or replace the executable and execute arbitrary code with SYSTEM privileges when the service starts or the system is restarted.14dCVE-2020-0358—1.3%
——0——CVE-2026-144787.8 ALT1.3%
——0A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability.5dCVE-2025-54569—1.3%
——0——CVE-2022-21755—1.3%
——0——CVE-2023-33076—1.3%
——0——CVE-2022-27833—1.3%
——0——CVE-2025-29934—1.3%
——0——CVE-2024-43065—1.3%
——0——CVE-2020-0407—1.3%
——0——CVE-2026-599177.8 ALT1.3%
——0Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.14dCVE-2025-21029—1.3%
——0——CVE-2023-43530—1.3%
——0——CVE-2025-12755—1.3%
——0——CVE-2026-23175—1.3%
——0——CVE-2026-27183—1.3%
——0——