Vulnerabilidades explotables hoy
367,284en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,274
- Alto9,334
- Medio5,332
- Bajo522
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-22987—1.1%
——0——CVE-2026-3903—1.1%
——0——CVE-2026-42306—1.1%
——0——CVE-2025-49599—1.1%
——0——CVE-2025-126947.8 ALT1.1%
——0A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SYSTEM. This issue affects VPN Client for Windows: versions 6.11.3 and prior.40dCVE-2026-561357.4 ALT1.1%
——0In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id() in libntfs-3g/security.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by creating a file in a crafted directory.3dCVE-2025-53344—1.1%
——0——CVE-2024-58050—1.1%
——0——CVE-2021-39779—1.1%
——0——CVE-2024-58114—1.1%
——0——CVE-2022-23728—1.1%
——0——CVE-2022-30755—1.1%
——0——CVE-2021-25409—1.1%
——0——CVE-2026-19755—1.1%
——0NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing attacker-controlled command and NSBundlePath values.This issue affects NoSleep: 1.5.1.3dCVE-2021-39753—1.1%
——0——CVE-2022-20379—1.1%
——0——CVE-2024-38425—1.1%
——0——CVE-2022-20466—1.1%
——0——CVE-2025-14759—1.1%
——0——CVE-2021-25473—1.1%
——0——CVE-2026-65934—1.1%
——0——CVE-2026-653675.5 MED1.1%
——0A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5. An app may be able to cause unexpected system termination.4dCVE-2026-157796.1 MED1.1%
——0A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as their home directory (a common default for system accounts) can have this triggered not only by root, but by a non-root user holding a narrow sudo delegation to run commands as that account, causing ownership of / to change and resulting in severe denial of service (SSH, sudo, and package-manager failures). The change does not grant write access to / (which ships with restrictive 0555 permissions on RHEL), so the impact is availability loss rather than further privilege escalation.47dCVE-2025-27723—1.1%
——0——CVE-2026-23018—1.1%
——0——CVE-2026-279643.9 BAJ1.1%
——0FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-Site Scripting (XSS) vulnerability through the fsNick cookie parameter. The application reflects the cookie's value directly into the HTML without sanitization. The fsNick cookie is rendered into the DOM without encoding. While the server does reject the modified session and forces a logout, the HTML containing the payload reaches the browser first. This lets the script execute immediately upon load, effectively beating the redirect. This issue has been fixed in version 2025.8.38dCVE-2026-32420—1.1%
——0——CVE-2026-46239—1.1%
——0——CVE-2026-23232—1.1%
——0——CVE-2022-20314—1.1%
——0——CVE-2025-36510—1.1%
——0——CVE-2023-22382—1.1%
——0——CVE-2021-25362—1.1%
——0——CVE-2024-58046—1.1%
——0——CVE-2022-42500—1.1%
——0——CVE-2021-39770—1.1%
——0——CVE-2025-29937—1.1%
——0——CVE-2022-20119—1.1%
——0——CVE-2022-48431—1.1%
——0——CVE-2026-46222—1.1%
——0——