Vulnerabilidades explotables hoy
367,165en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,263
- Alto9,268
- Medio5,273
- Bajo508
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2022-0317—0.8%
——0——CVE-2023-20989—0.8%
——0——CVE-2026-277746.7 MED0.8%
——0Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42902.38dCVE-2025-22430—0.8%
——0——CVE-2022-48238—0.8%
——0——CVE-2025-14612—0.8%
——0——CVE-2023-35679—0.8%
——0——CVE-2022-48373—0.8%
——0——CVE-2022-48240—0.8%
——0——CVE-2026-13198—0.8%
——0Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the event notification functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attacker to corrupt kernel heap and event-list state and disclose a small amount of adjacent kernel memory, resulting in kernel memory corruption and denial of service, by issuing concurrent crafted requests from multiple threads through the piControl character device.3dCVE-2026-43116—0.8%
——0——CVE-2023-21153—0.8%
——0——CVE-2026-31667—0.8%
——0——CVE-2023-21103—0.8%
——0——CVE-2025-64314—0.8%
——0——CVE-2022-47470—0.8%
——0——CVE-2025-13663—0.8%
——0——CVE-2023-35682—0.8%
——0——CVE-2023-42739—0.8%
——0——CVE-2023-35676—0.8%
——0——CVE-2022-47494—0.8%
——0——CVE-2026-25607—0.8%
——0Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzing how passwords with known values are encoded.
This issue was fixed in version 9.5.39dCVE-2023-21203—0.8%
——0——CVE-2023-42747—0.8%
——0——CVE-2023-21009—0.8%
——0——CVE-2022-38690—0.8%
——0——CVE-2026-232717.8 ALT0.8%
——0In the Linux kernel, the following vulnerability has been resolved:
perf: Fix __perf_event_overflow() vs perf_remove_from_context() race
Make sure that __perf_event_overflow() runs with IRQs disabled for all
possible callchains. Specifically the software events can end up running
it with only preemption disabled.
This opens up a race vs perf_event_exit_event() and friends that will go
and free various things the overflow path expects to be present, like
the BPF program.48dCVE-2022-47485—0.8%
——0——CVE-2026-146636.5 MED0.8%
——0Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed even with the wrong key. This in turn loses the modest protection from the Modification Detection Code (MDC). Affected functions are pgp_sym_encrypt, pgp_sym_decrypt, pgp_pub_encrypt, pgp_pub_decrypt, pgp_sym_encrypt_bytea, pgp_sym_decrypt_bytea, pgp_pub_encrypt_bytea, and pgp_pub_decrypt_bytea. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.2dCVE-2023-21050—0.8%
——0——CVE-2023-21008—0.8%
——0——CVE-2022-48374—0.8%
——0——CVE-2021-0734—0.8%
——0——CVE-2024-39575—0.8%
——0——CVE-2023-21158—0.8%
——0——CVE-2022-47488—0.8%
——0——CVE-2026-26096—0.8%
——0——CVE-2023-20981—0.8%
——0——CVE-2025-53696—0.8%
——0——CVE-2026-13197—0.8%
——0Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the configuration and process-image management functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attacker to trigger use-after-free and invalid pointer dereferences on kernel configuration objects, resulting in kernel memory corruption and denial of service, by issuing concurrent crafted requests through the piControl character device.3d