Vulnerabilidades explotables hoy
367,284en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,274
- Alto9,334
- Medio5,332
- Bajo522
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2024-45446—1.3%
——0——CVE-2026-26097—1.3%
——0——CVE-2025-21039—1.3%
——0——CVE-2021-0486—1.3%
——0——CVE-2026-3774—1.3%
——0——CVE-2022-30725—1.3%
——0——CVE-2021-0552—1.3%
——0——CVE-2021-479457.8 ALT1.3%
——0Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in the DVRWatchdog service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be executed with LocalSystem privileges when the service starts.38dCVE-2025-20650—1.3%
——0——CVE-2026-42191—1.3%
——0——CVE-2024-20503—1.3%
——0——CVE-2023-20983—1.3%
——0——CVE-2023-33283—1.3%
——0——CVE-2025-61713—1.3%
——0——CVE-2026-189545.5 MED1.3%
——0Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic.
To remediate this issue, users should upgrade to version 1.0.12 or later.21dCVE-2024-5465—1.3%
——0——CVE-2026-526863.7 BAJ1.3%
——0The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.39dCVE-2021-0572—1.3%
——0——CVE-2026-641527.8 ALT1.3%
——0In the Linux kernel, the following vulnerability has been resolved:
iommu: Handle unmap error when iommu_debug is enabled
Sashiko noticed a latent bug where the map error flow called iommu_unmap()
which calls iommu_debug_unmap_begin()/iommu_debug_unmap_end() however
since this is an error path the map flow never actually established the
original iommu_debug_map() it will malfunction.
Lift the unmap error handling into iommu_map_nosync() and reorder it so
the trace_map()/iommu_debug_map() records the partial mapping and then
immediately unmaps it. This avoid creating the unbalanced tracking and
provides saner tracing instead of a unmap unmatched to any map.14dCVE-2022-20536—1.3%
——0——CVE-2026-191927.8 ALT1.3%
——0A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe. Performing a manipulation results in improper access controls. The attack must be initiated from a local position. The exploit is now public and may be used.19dCVE-2024-51529—1.3%
——0——CVE-2025-36511—1.3%
——0——CVE-2026-11879—1.3%
——0——CVE-2022-30724—1.3%
——0——CVE-2025-62308—1.3%
——0——CVE-2024-45551—1.3%
——0——CVE-2023-32852—1.3%
——0——CVE-2025-10578—1.3%
——0——CVE-2026-25701—1.3%
——0——CVE-2025-32092—1.3%
——0——CVE-2026-49001—1.3%
——0——CVE-2023-7271—1.3%
——0——CVE-2022-25816—1.3%
——0——CVE-2025-61667—1.3%
——0——CVE-2021-39659—1.3%
——0——CVE-2025-14904—1.3%
——0——CVE-2025-20143—1.3%
——0——CVE-2025-52642—1.3%
——0——CVE-2026-02717.8 ALT1.3%
——0A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges.
This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.40d