Vulnerabilidades explotables hoy
367,165en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,263
- Alto9,269
- Medio5,273
- Bajo508
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-16526.1 MED0.7%
——0A potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to corrupt memory and cause a Windows blue screen error.11dCVE-2026-23362—0.7%
——0——CVE-2023-20707—0.7%
——0——CVE-2026-31756—0.7%
——0——CVE-2026-210623.3 BAJ0.7%
——0Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.13dCVE-2023-21154—0.7%
——0——CVE-2023-20956—0.7%
——0——CVE-2023-32810—0.7%
——0——CVE-2022-20305—0.7%
——0——CVE-2025-24493—0.7%
——0——CVE-2021-39647—0.7%
——0——CVE-2026-31499—0.7%
——0——CVE-2025-22830—0.7%
——0——CVE-2026-648715.4 MED0.7%
——0Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not consistently require a valid token and cache-management permission.38dCVE-2023-20798—0.7%
——0——CVE-2026-26949—0.7%
——0——CVE-2023-42737—0.7%
——0——CVE-2023-20850—0.7%
——0——CVE-2022-20460—0.7%
——0——CVE-2024-23357—0.7%
——0——CVE-2024-47030—0.7%
——0——CVE-2022-38681—0.7%
——0——CVE-2026-8148—0.7%
——0——CVE-2026-234705.5 MED0.7%
——0In the Linux kernel, the following vulnerability has been resolved:
drm/imagination: Fix deadlock in soft reset sequence
The soft reset sequence is currently executed from the threaded IRQ
handler, hence it cannot call disable_irq() which internally waits
for IRQ handlers, i.e. itself, to complete.
Use disable_irq_nosync() during a soft reset instead.38dCVE-2023-20848—0.7%
——0——CVE-2026-0015—0.7%
——0——CVE-2022-33689—0.7%
——0——CVE-2026-43319—0.7%
——0——CVE-2024-21462—0.7%
——0——CVE-2026-335653.3 BAJ0.7%
——0in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.38dCVE-2026-162925.4 MED0.7%
——0The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. When guest uploads are enabled, the same action is reachable unauthenticated against any user's file.5dCVE-2023-21170—0.7%
——0——CVE-2025-7214—0.7%
——0——CVE-2023-21169—0.7%
——0——CVE-2021-39649—0.7%
——0——CVE-2023-21160—0.7%
——0——CVE-2023-21048—0.7%
——0——CVE-2023-20842—0.7%
——0——CVE-2023-21045—0.7%
——0——CVE-2023-20973—0.7%
——0——