Vulnerabilidades explotables hoy
367,165en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,263
- Alto9,269
- Medio5,273
- Bajo508
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2022-47334—0.6%
——0——CVE-2023-20991—0.6%
——0——CVE-2023-20674—0.6%
——0——CVE-2026-47328—0.6%
——0——CVE-2021-0878—0.6%
——0——CVE-2026-21033—0.6%
——0——CVE-2023-35657—0.6%
——0——CVE-2026-43127—0.6%
——0——CVE-2022-22263—0.6%
——0——CVE-2023-20731—0.6%
——0——CVE-2023-20648—0.6%
——0——CVE-2026-16535.5 MED0.6%
——0A potential divide by zero vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to cause a Windows blue screen error.11dCVE-2025-36335—0.6%
——0——CVE-2023-20660—0.6%
——0——CVE-2026-23311—0.6%
——0——CVE-2025-36928—0.6%
——0——CVE-2026-711054.7 MED0.6%
——0Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 4.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).7dCVE-2023-20730—0.6%
——0——CVE-2023-20818—0.6%
——0——CVE-2023-20727—0.6%
——0——CVE-2026-180717.8 ALT0.6%
——0IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper privilege management.14dCVE-2021-0881—0.6%
——0——CVE-2022-30753—0.6%
——0——CVE-2023-40125—0.6%
——0——CVE-2026-53809—0.6%
——0——CVE-2026-21028—0.6%
——0——CVE-2026-687443.3 BAJ0.6%
——0A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process.13dCVE-2026-54327—0.6%
——0——CVE-2026-21022—0.6%
——0——CVE-2021-0565—0.6%
——0——CVE-2026-25908—0.6%
——0——CVE-2026-21026—0.6%
——0——CVE-2023-20677—0.6%
——0——CVE-2026-43404—0.6%
——0——CVE-2021-0879—0.6%
——0——CVE-2023-21014—0.6%
——0——CVE-2022-48236—0.6%
——0——CVE-2025-36927—0.6%
——0——CVE-2025-39915—0.6%
——0——CVE-2026-585658.8 ALT0.6%
——0Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.10d