Vulnerabilidades explotables hoy
367,284en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,274
- Alto9,334
- Medio5,332
- Bajo522
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2024-20309—1.0%
——0——CVE-2023-42684—1.0%
——0——CVE-2024-58044—1.0%
——0——CVE-2026-24931—1.0%
——0——CVE-2026-27518—1.0%
——0——CVE-2024-33055—1.0%
——0——CVE-2023-40117—1.0%
——0——CVE-2025-36411—1.0%
——0——CVE-2026-204915.5 MED1.0%
——0In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) / AUTO00851173 (Note: For MT2735, MT2737); Issue ID: MSV-7652.12dCVE-2023-43545—1.0%
——0——CVE-2021-22419—1.0%
——0——CVE-2026-52791—1.0%
——0fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branch preserves SUID and SGID mode bits in main.c during open(O_TRUNC) and truncate handling on a copied-up file, allowing a low-privileged process to leave the upper-layer file with mode 4777. This issue is fixed in version 1.17.33dCVE-2024-23377—1.0%
——0——CVE-2023-42729—1.0%
——0——CVE-2024-31323—1.0%
——0——CVE-2024-31313—1.0%
——0——CVE-2024-20107—1.0%
——0——CVE-2024-20093—1.0%
——0——CVE-2022-36844—1.0%
——0——CVE-2023-21184—1.0%
——0——CVE-2021-25472—1.0%
——0——CVE-2022-36843—1.0%
——0——CVE-2023-35659—1.0%
——0——CVE-2023-42679—1.0%
——0——CVE-2023-42682—1.0%
——0——CVE-2024-33061—1.0%
——0——CVE-2026-595678.8 ALT1.0%
——0Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context.3dCVE-2023-21336—1.0%
——0——CVE-2022-21792—1.0%
——0——CVE-2026-593263.3 BAJ1.0%
——0The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is configured. Corporate proxy URLs frequently embed Basic-auth credentials in the form http://user:pass@proxy:8080, and the language server writes this value to its log file without any redaction. Since language server log files are often attached to bug reports or are readable by other local users/processes, this can result in disclosure of proxy credentials.
Affected Spring Products and Versions:
Spring Tools for Eclipse: 5.2.0 and earlier
Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier32dCVE-2026-208015.6 MED1.0%
——0Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrations allows unprivileged users with local network access to view live video streams.
This issue affects all versions of Gallagher NxWitness VMS integration prior to 9.10.017 and Gallagher Hanwha VMS integration prior to 9.10.025.14dCVE-2025-35987—1.0%
——0Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives within Ring 0: Kernel may allow a denial of service. Authorized adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (low) impacts.19dCVE-2026-672675.5 MED1.0%
——0Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.10dCVE-2025-60791—1.0%
——0——CVE-2026-538327.7 ALT1.0%
——0OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge trusted-proxy identity headers. Attackers with access to the proxy-facing Gateway port can supply forged identity headers to assume operator identity and potentially escalate privileges.39dCVE-2024-21460—1.0%
——0——CVE-2025-31937—1.0%
——0——CVE-2026-41664—1.0%
——0——CVE-2025-0089—1.0%
——0——CVE-2022-32613—1.0%
——0——