Vulnerabilidades explotables hoy
367,165en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,263
- Alto9,268
- Medio5,273
- Bajo508
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2021-0625—0.8%
——0——CVE-2022-20393—0.8%
——0——CVE-2025-47390—0.8%
——0——CVE-2026-1128—0.8%
——0——CVE-2026-281727.1 ALT0.8%
——0Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.19dCVE-2026-6053—0.8%
——0——CVE-2026-769204.7 MED0.8%
——03gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service3dCVE-2026-20881—0.8%
——0——CVE-2025-31940—0.8%
——0——CVE-2026-240877.2 ALT0.8%
——0Memory corruption while processing fastboot OEM commands.40dCVE-2023-33880—0.8%
——0——CVE-2024-47935—0.8%
——0——CVE-2026-502097.8 ALT0.8%
——0Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker.40dCVE-2023-21043—0.8%
——0——CVE-2026-768834.7 MED0.8%
——0Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service3dCVE-2026-75847—0.8%
——0Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of sensitive? attributes.
AshPaperTrail stores the values of tracked sensitive? attributes in the generated version resource's changes map, which is declared public? true and sensitive? false, so the values are returned by the version resource's default read action and printed in logs, inspect output, and error messages instead of being redacted. AshPaperTrail.Resource.Transformers.CreateVersionResource derives the changes map's sensitivity from the ignore_attributes list (the attributes excluded from changes) rather than from the tracked attributes actually stored in it, and ignore_attributes defaults to empty, so the flag is effectively always false.
This issue affects ash_paper_trail: from 0.1.1 before 0.7.0.2dCVE-2017-9708—0.8%
——0——CVE-2026-196944.7 MED0.8%
——0TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service3dCVE-2026-240927.2 ALT0.8%
——0Memory Corruption when processing fastboot commands to set display mode.40dCVE-2026-32456—0.8%
——0——CVE-2023-21341—0.8%
——0——CVE-2023-21042—0.8%
——0——CVE-2026-442756.3 MED0.8%
——0Dell/Alienware Purchased Apps, versions prior to 1.1.32.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary File Write39dCVE-2025-48531—0.8%
——0——CVE-2024-38283—0.8%
——0——CVE-2024-31127—0.8%
——0——CVE-2024-20084—0.8%
——0——CVE-2025-43918—0.8%
——0——CVE-2025-58305—0.8%
——0——CVE-2025-30518—0.8%
——0——CVE-2026-196954.7 MED0.8%
——0Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service3dCVE-2022-20093—0.8%
——0——CVE-2025-32467—0.8%
——0——CVE-2026-277887.8 ALT0.8%
——0Incorrect permission assignment for critical resource issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploited, a local authenticated attacker who can log in to the server where the affected product is installed may obtain SYSTEM privilege.40dCVE-2025-62623—0.8%
——0——CVE-2026-768894.7 MED0.8%
——0UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service3dCVE-2025-20119—0.8%
——0——CVE-2024-0171—0.8%
——0——CVE-2025-54619—0.8%
——0——CVE-2026-53818—0.8%
——0——