Vulnerabilidades explotables hoy
367,284en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,274
- Alto9,334
- Medio5,332
- Bajo522
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2018-9384—1.1%
——0——CVE-2018-9405—1.1%
——0——CVE-2024-33053—1.1%
——0——CVE-2022-27832—1.1%
——0——CVE-2025-21441—1.1%
——0——CVE-2024-33039—1.1%
——0——CVE-2026-130024.4 MED1.1%
——0A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution for its clients.3hCVE-2026-252688.8 ALT1.1%
——0Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.55dCVE-2026-43942—1.1%
——0——CVE-2025-38217—1.1%
——0——CVE-2024-23368—1.1%
——0——CVE-2026-213797.8 ALT1.1%
——0Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.55dCVE-2026-493224.3 MED1.1%
——0Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the user-set unlock PIN by passively observing a single PIN authentication exchange. The Infotainment Digital Round display computes its response using a non-cryptographic operation rather than a cryptographic challenge-response, so the PIN is mathematically derivable from one captured exchange, defeating the motorcycle's primary user-authentication control. Specific protocol details have been withheld pending vendor remediation.41dCVE-2025-61970—1.1%
——0Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to create arbitrary code, potentially resulting in binary hijacking.19dCVE-2026-97416.5 MED1.1%
——0A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryption (CSFLE) results in literal values for encrypted fields within the $vectorSearch stage filter expressions to be sent to the server as plaintext instead of ciphertext.39dCVE-2025-3456—1.1%
——0——CVE-2026-711494.2 MED1.1%
——0Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 4.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L).11dCVE-2026-27105—1.1%
——0——CVE-2025-25051—1.1%
——0——CVE-2024-21465—1.1%
——0——CVE-2026-31700—1.1%
——0——CVE-2026-3671—1.1%
——0——CVE-2026-20760—1.1%
——0Improper handling of overlap between protected memory ranges in some microcode for some Intel(R) Processors within Ring 0: Hypervisor may allow an escalation of privilege. Authorized adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.19dCVE-2026-54679—1.1%
——0——CVE-2026-108033.6 BAJ1.1%
——0A flaw has been found in MLflow up to 3.10.0. This issue affects the function mlflow.data.digest_utils of the file mlflow/data/digest_utils.py of the component Dataset Digest Computation. This manipulation causes use of weak hash. It is possible to launch the attack on the local host. The attack is considered to have high complexity. The exploitability is assessed as difficult. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet.40dCVE-2024-45541—1.1%
——0——CVE-2022-20172—1.1%
——0——CVE-2024-45571—1.1%
——0——CVE-2025-20248—1.1%
——0——CVE-2025-21436—1.1%
——0——CVE-2026-3778—1.1%
——0——CVE-2025-21423—1.1%
——0——CVE-2022-20285—1.1%
——0——CVE-2025-21443—1.1%
——0——CVE-2024-49833—1.1%
——0——CVE-2022-20200—1.1%
——0——CVE-2023-43542—1.1%
——0——CVE-2025-21440—1.1%
——0——CVE-2026-277665.5 MED1.1%
——0in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak.38dCVE-2026-0035—1.1%
——0——