Vulnerabilidades explotables hoy
367,165en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,263
- Alto9,268
- Medio5,273
- Bajo508
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2023-42677—0.7%
——0——CVE-2023-20982—0.7%
——0——CVE-2025-20707—0.7%
——0——CVE-2026-175225.4 MED0.7%
——0The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its settings screens, and writes every submitted parameter into its own options, allowing attackers to make a logged in administrator overwrite arbitrary Newsletters WordPress plugin before 4.17 settings, including the credential protecting its API, via a Cross-Site Request Forgery attack.2dCVE-2023-42702—0.7%
——0——CVE-2023-42674—0.7%
——0——CVE-2024-20015—0.7%
——0——CVE-2022-27834—0.7%
——0——CVE-2023-21022—0.7%
——0——CVE-2023-42672—0.7%
——0——CVE-2026-22276—0.7%
——0——CVE-2026-6500—0.7%
——0——CVE-2023-42713—0.7%
——0——CVE-2025-115684.4 MED0.7%
——0A data corruption vulnerability has been identified in the luksmeta utility when used with the LUKS1 disk encryption format. An attacker with the necessary permissions can exploit this flaw by writing a large amount of metadata to an encrypted device. The utility fails to correctly validate the available space, causing the metadata to overwrite and corrupt the user's encrypted data. This action leads to a permanent loss of the stored information. Devices using the LUKS formats other than LUKS1 are not affected by this issue.10dCVE-2024-43084—0.7%
——0——CVE-2023-42709—0.7%
——0——CVE-2022-20341—0.7%
——0——CVE-2025-9970—0.7%
——0——CVE-2023-42697—0.7%
——0——CVE-2026-27415—0.7%
——0——CVE-2023-42711—0.7%
——0——CVE-2023-20993—0.7%
——0——CVE-2025-36154—0.7%
——0——CVE-2022-26429—0.7%
——0——CVE-2023-32812—0.7%
——0——CVE-2023-21276—0.7%
——0——CVE-2026-636235.5 MED0.7%
——0A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.17dCVE-2023-20970—0.7%
——0——CVE-2023-42698—0.7%
——0——CVE-2023-42700—0.7%
——0——CVE-2024-40661—0.7%
——0——CVE-2026-0122—0.7%
——0——CVE-2025-20005—0.7%
——0——CVE-2025-43914—0.7%
——0——CVE-2023-40111—0.7%
——0——CVE-2026-24986—0.7%
——0——CVE-2022-20241—0.7%
——0——CVE-2023-21011—0.7%
——0——CVE-2026-40951—0.7%
——0——CVE-2023-42710—0.7%
——0——