Vulnerabilidades explotables hoy
367,144en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,256
- Alto9,258
- Medio5,266
- Bajo507
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2022-21771—0.4%
——0——CVE-2024-20105—0.4%
——0——CVE-2026-180864.5 MED0.4%
——0IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denial of service due to improper bounds checking.12dCVE-2023-21364—0.4%
——0——CVE-2024-29738—0.4%
——0——CVE-2022-42771—0.4%
——0——CVE-2025-48562—0.4%
——0——CVE-2025-58295—0.4%
——0——CVE-2023-21318—0.4%
——0——CVE-2024-22009—0.4%
——0——CVE-2023-42750—0.4%
——0——CVE-2023-21316—0.4%
——0——CVE-2023-21297—0.4%
——0——CVE-2018-9378—0.4%
——0——CVE-2026-637007.8 ALT0.4%
——0Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.14dCVE-2025-71117—0.4%
——0——CVE-2023-21308—0.4%
——0——CVE-2022-21772—0.4%
——0——CVE-2025-48586—0.4%
——0——CVE-2026-57916—0.4%
——0proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it to the victim. When the victim opens the document in the application, the specified file will be executed (or webpage will be opened).
This issue was fixed in version 9.4.3.90.32dCVE-2026-43342—0.4%
——0——CVE-2025-48541—0.4%
——0——CVE-2023-30928—0.4%
——0——CVE-2023-21357—0.4%
——0——CVE-2025-30042—0.4%
——0——CVE-2026-61027.8 ALT0.4%
——0MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSI Center. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the NTIOLib_X64.sys driver. The issue results from insufficient validation of the origin of commands. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-28935.31dCVE-2025-64311—0.4%
——0——CVE-2025-66329—0.4%
——0——CVE-2023-21319—0.4%
——0——CVE-2026-556555.0 MED0.4%
——0A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.6dCVE-2023-38468—0.4%
——0——CVE-2023-40131—0.4%
——0——CVE-2023-28576—0.4%
——0——CVE-2023-21029—0.4%
——0——CVE-2024-34734—0.4%
——0——CVE-2023-20962—0.4%
——0——CVE-2023-21189—0.4%
——0——CVE-2023-21325—0.4%
——0——CVE-2024-29750—0.4%
——0——CVE-2023-21309—0.4%
——0——