Vulnerabilidades explotables hoy
367,284en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,274
- Alto9,335
- Medio5,332
- Bajo522
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-23106—0.9%
——0——CVE-2022-26435—0.9%
——0——CVE-2024-25991—0.9%
——0——CVE-2026-20730—0.9%
——0——CVE-2022-21788—0.9%
——0——CVE-2026-463055.5 MED0.9%
——0In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: os_dep: avoid NULL pointer dereference in rtw_cbuf_alloc
The return value of kzalloc_flex() is used without
ensuring that the allocation succeeded, and the
pointer is dereferenced unconditionally.
Guard the access to the allocated structure to
avoid a potential NULL pointer dereference if the
allocation fails.39dCVE-2026-169654.3 MED0.9%
——0The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's active templates.5dCVE-2026-23218—0.9%
——0——CVE-2026-407157.8 ALT0.9%
——0Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.40dCVE-2026-46112—0.9%
——0——CVE-2023-21040—0.9%
——0——CVE-2025-54614—0.9%
——0——CVE-2023-21397—0.9%
——0——CVE-2022-20032—0.9%
——0——CVE-2026-706036.0 MED0.9%
——0Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1, shell.openPath() did not reject paths containing embedded null bytes. Apps that perform string-only validation of file paths, for example checking the file extension, before passing them to shell.openPath() could be bypassed, allowing an attacker-controlled path to open a different file than the one that passed validation. Apps are only affected if they pass paths derived from untrusted input to shell.openPath() and rely on string-based validation without a filesystem check. This issue is fixed in versions 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1.26dCVE-2023-21157—0.9%
——0——CVE-2023-48415—0.9%
——0——CVE-2026-23377—0.9%
——0——CVE-2022-25815—0.9%
——0——CVE-2026-33987—0.9%
——0——CVE-2026-23203—0.9%
——0——CVE-2023-21024—0.9%
——0——CVE-2024-33037—0.9%
——0——CVE-2022-26430—0.9%
——0——CVE-2026-196536.5 MED0.9%
——0IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to improper handling of memory page table configurations.6dCVE-2023-21388—0.9%
——0——CVE-2024-31336—0.9%
——0——CVE-2026-23117—0.9%
——0——CVE-2026-171956.5 MED0.9%
——0IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to an out-of-bounds write.6dCVE-2022-26431—0.9%
——0——CVE-2024-27244—0.9%
——0——CVE-2024-321104.3 MED0.9%
——0Cross-Site request forgery (CSRF) vulnerability in Magepeople inc. WpEvently allows Cross Site Request Forgery.
This issue affects WpEvently: from n/a through 4.1.2.39dCVE-2025-623383.3 BAJ0.9%
——0HCL BigFix Cloud Lifecycle Management is affected by lack of input validation. This low-level flaw allows unauthorized access and may lead to information exposure.40dCVE-2022-21791—0.9%
——0——CVE-2022-26433—0.9%
——0——CVE-2026-559788.4 ALT0.9%
——0An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an unrestricted kernel filter communication port and bypass CatchPulse's security policy enforcement.5dCVE-2026-5515—0.9%
——0——CVE-2026-285863.3 BAJ0.9%
——0In multiple functions of AppOpsService.java, there is a possible missing permission check due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.40dCVE-2026-23122—0.9%
——0——CVE-2026-559805.5 MED0.9%
——0A denial-of-service vulnerability in CatchPulse could allow an attacker to conduct a stack buffer overrun attack, leading to a denial-of-service condition.5d