Vulnerabilidades explotables hoy
367,284en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,274
- Alto9,334
- Medio5,332
- Bajo522
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2024-40658—1.2%
——0——CVE-2025-48512—1.2%
——0——CVE-2024-20058—1.2%
——0——CVE-2025-156216.0 MED1.2%
——0Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication10dCVE-2025-62346—1.2%
——0——CVE-2023-32878—1.2%
——0——CVE-2026-35359—1.2%
——0——CVE-2025-26428—1.2%
——0——CVE-2024-23698—1.2%
——0——CVE-2026-41155—1.2%
——0——CVE-2026-44411—1.2%
——0——CVE-2026-12502—1.2%
——0Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to reset the password of any LARM user (including the `larmapp` service account) via the `set-passwd` subcommand.35dCVE-2023-21122—1.2%
——0——CVE-2024-51516—1.2%
——0——CVE-2022-20258—1.2%
——0——CVE-2025-46593—1.2%
——0——CVE-2022-26091—1.2%
——0——CVE-2024-20833—1.2%
——0——CVE-2025-54547—1.2%
——0——CVE-2021-25358—1.2%
——0——CVE-2023-21115—1.2%
——0——CVE-2026-790865.1 MED1.2%
——0Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)3dCVE-2022-21787—1.2%
——0——CVE-2026-26102—1.2%
——0——CVE-2022-21780—1.2%
——0——CVE-2024-48519—1.2%
——0——CVE-2025-33193—1.2%
——0——CVE-2025-9810—1.2%
——0——CVE-2022-21781—1.2%
——0——CVE-2025-31054—1.2%
——0——CVE-2025-58280—1.2%
——0——CVE-2026-187392.5 BAJ1.2%
——0A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.4hCVE-2021-25359—1.2%
——0——CVE-2025-15376—1.2%
——0——CVE-2022-20152—1.2%
——0——CVE-2024-45540—1.2%
——0——CVE-2026-272215.5 MED1.2%
——0Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to spoof the identity of a signer. Exploitation of this issue requires user interaction.4dCVE-2026-107832.5 BAJ1.2%
——0A security flaw has been discovered in gradio-app gradio 6.14.0. This affects the function save_audio_to_cache of the component Audio Cache Key Handler. Performing a manipulation results in use of weak hash. The attack must be initiated from a local position. The attack is considered to have high complexity. It is indicated that the exploitability is difficult. The exploit has been released to the public and may be used for attacks. The patch is named 13394. To fix this issue, it is recommended to deploy a patch.40dCVE-2022-21779—1.2%
——0——CVE-2022-26090—1.2%
——0——