Vulnerabilidades explotables hoy
367,165en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,263
- Alto9,269
- Medio5,273
- Bajo508
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2023-20848—0.7%
——0——CVE-2022-38681—0.7%
——0——CVE-2026-8148—0.7%
——0——CVE-2025-13454—0.7%
——0——CVE-2026-167037.8 ALT0.7%
——0IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.11dCVE-2023-20956—0.7%
——0——CVE-2022-20305—0.7%
——0——CVE-2023-21154—0.7%
——0——CVE-2023-32810—0.7%
——0——CVE-2023-20973—0.7%
——0——CVE-2025-24493—0.7%
——0——CVE-2023-20842—0.7%
——0——CVE-2021-39647—0.7%
——0——CVE-2026-26949—0.7%
——0——CVE-2023-42737—0.7%
——0——CVE-2023-21194—0.7%
——0——CVE-2022-20460—0.7%
——0——CVE-2026-451822.2 BAJ0.7%
——0GrapheneOS before 2026050400 allows attackers to discover the real IP address of a VPN user as a consequence of a registerQuicConnectionClosePayload optimization, because an application can let system_server transmit UDP traffic on its behalf. This occurs when the "Block connections without VPN" and "Always-on VPN" settings are enabled.38dCVE-2023-20798—0.7%
——0——CVE-2025-7214—0.7%
——0——CVE-2026-162925.4 MED0.7%
——0The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. When guest uploads are enabled, the same action is reachable unauthenticated against any user's file.5dCVE-2026-335653.3 BAJ0.7%
——0in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.38dCVE-2026-43319—0.7%
——0——CVE-2022-33689—0.7%
——0——CVE-2026-46063—0.7%
——0——CVE-2023-32808—0.7%
——0——CVE-2024-21462—0.7%
——0——CVE-2026-31487—0.7%
——0——CVE-2022-20315—0.7%
——0——CVE-2023-21380—0.7%
——0——CVE-2026-687435.5 MED0.7%
——0A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.14dCVE-2023-35689—0.7%
——0——CVE-2021-39712—0.7%
——0——CVE-2026-150464.2 MED0.7%
——0The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that overwrites the store-migration connector's authentication token, allowing attackers to take over the connector token by tricking a logged-in administrator into clicking a crafted link (CSRF).10dCVE-2023-20840—0.7%
——0——CVE-2026-792867.4 ALT0.7%
——0Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a co-installed app. (Chromium security severity: Medium)4dCVE-2022-20459—0.7%
——0——CVE-2025-48640—0.7%
——0——CVE-2023-21150—0.7%
——0——CVE-2026-21020—0.7%
——0——