Vulnerabilidades explotables hoy
367,284en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,274
- Alto9,334
- Medio5,332
- Bajo522
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2022-20451—1.2%
——0——CVE-2024-53289—1.2%
——0——CVE-2026-345967.0 ALT1.2%
——0Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a Time-of-Check-to-Time-of-Use (TOCTOU) race condition exists during addon installation. When a user installs an addon through the SandMan interface, UpdUtil.exe is spawned as SYSTEM by SbieSvc but stages files in the user-writable %TEMP%\sandboxie-updater directory. After UpdUtil verifies file hashes against the signed addon manifest, install.bat extracts files.cab and executes config.exe from its contents. Between hash verification and extraction, an unprivileged user can replace files.cab with a crafted cabinet containing a malicious executable, which is then run as SYSTEM. No UAC prompt is required.
This issue has been fixed in version 1.17.3.38dCVE-2026-437434.7 MED1.2%
——0A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.35dCVE-2025-20215—1.2%
——0——CVE-2026-455815.5 MED1.2%
——0fabric-chaincode-java is a Java based implementation of Hyperledger Fabric chaincode shim APIs. From version 2.3.1 to before version 2.5.10, when chaincode is deployed in chaincode-as-a-service mode with TLS enabled, the chaincode server INFO level logging includes the TLS private key password in plaintext. An attacker with access to the chaincode server logs could recover the TLS private key password. If the attacker can also obtain the TLS private key, they could impersonate the chaincode server. This issue has been patched in version 2.5.10.40dCVE-2020-0373—1.2%
——0——CVE-2026-45046—1.2%
——0——CVE-2026-240776.5 MED1.2%
——0Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.25dCVE-2023-21334—1.2%
——0——CVE-2018-9389—1.2%
——0——CVE-2025-68957—1.2%
——0——CVE-2024-32923—1.2%
——0——CVE-2024-0017—1.2%
——0——CVE-2026-6840—1.2%
——0——CVE-2026-86725.1 MED1.2%
——0Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default Usernames and Passwords.
This issue affects Avantra: before 25.3.0.39dCVE-2016-10408—1.1%
——0——CVE-2023-21396—1.2%
——0——CVE-2023-25188—1.2%
——0——CVE-2026-452025.5 MED1.2%
——0Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU memory leaks and possible kernel heap corruption.
Scenario caused by memory free paths not maintaining state data of upgraded higher order allocations. This could cause memory leak or double free event.4dCVE-2025-27572—1.2%
——0——CVE-2024-34664—1.2%
——0——CVE-2026-28267—1.2%
——0——CVE-2026-45787—1.2%
——0——CVE-2026-48925—1.2%
——0——CVE-2023-48406—1.2%
——0——CVE-2021-1000—1.2%
——0——CVE-2025-49154—1.2%
——0——CVE-2026-30935—1.2%
——0——CVE-2021-39774—1.2%
——0——CVE-2026-5365—1.2%
——0——CVE-2026-749685.4 MED1.2%
——0Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.11dCVE-2022-22291—1.2%
——0——CVE-2024-0022—1.2%
——0——CVE-2026-22080—1.2%
——0——CVE-2026-196175.5 MED1.2%
——0A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This vulnerability results in a Denial of Service (DoS) for affected systems.6hCVE-2025-54611—1.2%
——0——CVE-2025-68967—1.2%
——0——CVE-2026-3669—1.2%
——0——CVE-2026-769235.5 MED1.2%
——0Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service3d