Vulnerabilidades explotables hoy
367,284en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,274
- Alto9,334
- Medio5,332
- Bajo522
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2025-3456—1.1%
——0——CVE-2025-61970—1.1%
——0Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to create arbitrary code, potentially resulting in binary hijacking.19dCVE-2026-213797.8 ALT1.1%
——0Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.55dCVE-2025-38217—1.1%
——0——CVE-2026-108033.6 BAJ1.1%
——0A flaw has been found in MLflow up to 3.10.0. This issue affects the function mlflow.data.digest_utils of the file mlflow/data/digest_utils.py of the component Dataset Digest Computation. This manipulation causes use of weak hash. It is possible to launch the attack on the local host. The attack is considered to have high complexity. The exploitability is assessed as difficult. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet.40dCVE-2022-20172—1.1%
——0——CVE-2024-45541—1.1%
——0——CVE-2024-0052—1.1%
——0——CVE-2024-38419—1.1%
——0——CVE-2026-826476.1 MED1.1%
——0WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrators to send mail from the site's contact address by bypassing origin checks and captcha validation. Attackers can craft a malicious web page that, when visited by an authenticated admin, sends emails with attacker-controlled subject and body to arbitrary recipients, passing SPF/DKIM/DMARC validation for phishing and brand impersonation attacks.4hCVE-2024-23711—1.1%
——0——CVE-2024-38420—1.1%
——0——CVE-2024-23368—1.1%
——0——CVE-2026-97416.5 MED1.1%
——0A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryption (CSFLE) results in literal values for encrypted fields within the $vectorSearch stage filter expressions to be sent to the server as plaintext instead of ciphertext.39dCVE-2024-38415—1.1%
——0——CVE-2022-20285—1.1%
——0——CVE-2024-38422—1.1%
——0——CVE-2018-9405—1.1%
——0——CVE-2022-27832—1.1%
——0——CVE-2026-493224.3 MED1.1%
——0Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the user-set unlock PIN by passively observing a single PIN authentication exchange. The Infotainment Digital Round display computes its response using a non-cryptographic operation rather than a cryptographic challenge-response, so the PIN is mathematically derivable from one captured exchange, defeating the motorcycle's primary user-authentication control. Specific protocol details have been withheld pending vendor remediation.41dCVE-2024-33053—1.1%
——0——CVE-2026-3778—1.1%
——0——CVE-2024-45571—1.1%
——0——CVE-2025-21423—1.1%
——0——CVE-2026-210786.5 MED1.0%
——0Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to spoof device identity.12dCVE-2022-22269—1.0%
——0——CVE-2025-45376—1.0%
——0——CVE-2026-769574.9 MED1.0%
——0libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.11dCVE-2026-204565.5 MED1.0%
——0In wlan STA driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480851; Issue ID: MSV-6338.41dCVE-2022-22267—1.0%
——0——CVE-2026-43344—1.0%
——0——CVE-2025-54608—1.0%
——0——CVE-2026-775855.3 MED1.0%
——0The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result, the value may be interpreted as a command-line option by the underlying SSH process.3dCVE-2022-36852—1.0%
——0——CVE-2025-36612—1.0%
——0——CVE-2023-44121—1.0%
——0——CVE-2023-42751—1.0%
——0——CVE-2022-36858—1.0%
——0——CVE-2023-42683—1.0%
——0——CVE-2026-735856.3 MED1.0%
——0A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an attacker can redirect privileged writes to an arbitrary file during script execution in a privileged context. This can lead to the overwrite of root-owned files, potentially disrupting system services or operation. Exploitation is conditional on the script running with elevated privileges and may be mitigated by sticky-directory symlink protections.6d