Vulnerabilidades explotables hoy
367,284en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,274
- Alto9,334
- Medio5,332
- Bajo522
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2024-33044—1.1%
——0——CVE-2026-21010—1.1%
——0——CVE-2026-396035.4 MED1.1%
——0Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Photography grandphotography allows Cross Site Request Forgery.This issue affects Grand Photography: from n/a through <= 5.7.8.42dCVE-2025-68958—1.1%
——0——CVE-2023-31225—1.1%
——0——CVE-2026-25322—1.1%
——0——CVE-2026-28727—1.1%
——0——CVE-2026-32328—1.1%
——0——CVE-2026-02675.5 MED1.1%
——0An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can perform these actions even if the GlobalProtect app configuration would not normally permit them to do so.40dCVE-2025-380287.8 ALT1.1%
——0In the Linux kernel, the following vulnerability has been resolved:
NFS/localio: Fix a race in nfs_local_open_fh()
Once the clp->cl_uuid.lock has been dropped, another CPU could come in
and free the struct nfsd_file that was just added. To prevent that from
happening, take the RCU read lock before dropping the spin lock.33dCVE-2026-622907.3 ALT1.1%
——0cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing and using those certificates. From 1.18.0 until 1.19.6 and 1.20.3, Challenge resources under acme.cert-manager.io can be created directly by namespace users without admission validation tying the Challenge to an Order, owner reference, or Issuer-selected solver, allowing attacker-controlled Challenge.spec.solver values referencing a ClusterIssuer to bypass DNS01 solver selectors such as dnsZones, dnsNames, and matchLabels and cause cert-manager to use ClusterIssuer DNS credentials for attacker-selected provider settings and DNS names, including disclosure of X-Api-User and X-Api-Key headers for acme-dns. This issue is fixed in versions 1.19.6 and 1.20.3.32dCVE-2024-31314—1.1%
——0——CVE-2026-32655—1.1%
——0——CVE-2022-20002—1.1%
——0——CVE-2026-494233.3 BAJ1.1%
——0When building the iovec array for a received TLS 1.2 CBC record, ktls_ocf_tls_cbc_decrypt() incremented the iovec index for every mbuf in the chain, including mbufs that were skipped because they contained only TLS header bytes. This left uninitialized entries in the iovec array. The iovec array was allocated without zeroing.
A remote TLS peer can cause the kernel to read from uninitialized iovec entries during HMAC computation, resulting in a kernel panic. The peer must be able to control TCP segmentation such that the first mbuf of a CBC record contains only the 5-byte TLS record header.3hCVE-2021-39769—1.1%
——0——CVE-2021-1011—1.1%
——0——CVE-2026-40703—1.1%
——0——CVE-2024-40750—1.1%
——0——CVE-2022-25332—1.1%
——0——CVE-2022-20080—1.1%
——0——CVE-2021-25474—1.1%
——0——CVE-2024-23697—1.1%
——0——CVE-2025-4295—1.1%
——0——CVE-2022-20146—1.1%
——0——CVE-2020-11262—1.1%
——0——CVE-2024-23696—1.1%
——0——CVE-2026-35360—1.1%
——0——CVE-2024-27212—1.1%
——0——CVE-2023-20773—1.1%
——0——CVE-2017-20040—1.1%
——0——CVE-2025-69875—1.1%
——0——CVE-2021-1025—1.1%
——0——CVE-2021-39751—1.1%
——0——CVE-2026-4667—1.1%
——0——CVE-2026-138498.6 ALT1.1%
——0Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)61dCVE-2021-39748—1.1%
——0——CVE-2025-0077—1.1%
——0——CVE-2026-317617.8 ALT1.1%
——0In the Linux kernel, the following vulnerability has been resolved:
iio: gyro: mpu3050: Move iio_device_register() to correct location
iio_device_register() should be at the end of the probe function to
prevent race conditions.
Place iio_device_register() at the end of the probe function and place
iio_device_unregister() accordingly.48dCVE-2026-22676—1.1%
——0——