Vulnerabilidades explotables hoy
367,134en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,255
- Alto9,255
- Medio5,260
- Bajo507
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2023-21139—0.3%
——0——CVE-2025-27033—0.3%
——0——CVE-2023-52348—0.3%
——0——CVE-2025-58289—0.3%
——0——CVE-2022-48452—0.3%
——0——CVE-2018-9399—0.3%
——0——CVE-2018-9346—0.3%
——0——CVE-2025-20671—0.3%
——0——CVE-2018-9463—0.3%
——0——CVE-2025-27030—0.3%
——0——CVE-2022-44430—0.3%
——0——CVE-2018-9408—0.3%
——0——CVE-2022-47337—0.3%
——0——CVE-2025-27042—0.3%
——0——CVE-2025-21466—0.3%
——0——CVE-2022-47362—0.3%
——0——CVE-2022-44445—0.3%
——0——CVE-2025-224267.8 ALT0.3%
——0In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.40dCVE-2022-44428—0.3%
——0——CVE-2022-20071—0.3%
——0——CVE-2025-48643—0.3%
——0——CVE-2022-44443—0.3%
——0——CVE-2022-47335—0.3%
——0——CVE-2023-20838—0.3%
——0——CVE-2018-9395—0.3%
——0——CVE-2024-49731—0.3%
——0——CVE-2023-35667—0.3%
——0——CVE-2022-20155—0.3%
——0——CVE-2024-47032—0.3%
——0——CVE-2026-732832.5 BAJ0.3%
——0In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.20dCVE-2025-327454.2 MED0.3%
——0Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information tampering.39dCVE-2022-44435—0.3%
——0——CVE-2026-328484.7 MED0.3%
——0NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem that allows local attackers to trigger a double-free condition by concurrently issuing CIOCCRYPT operations on the same session identifier on SMP systems. Attackers can exploit mutable per-operation state embedded in the csession struct to corrupt kernel heap memory.48dCVE-2026-667827.8 ALT0.3%
——0A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long-lived broker service account (SA) bearer token within the Submariner Custom Resource (CR) specification. An attacker with access to the cluster's etcd database or through `kubectl get` commands could obtain this token. The possession of this token grants full control over the mesh network, enabling unauthorized management of network resources such as endpoints and secrets.11dCVE-2025-48604—0.3%
——0——CVE-2022-44439—0.3%
——0——CVE-2025-20772—0.3%
——0——CVE-2026-111588.6 ALT0.3%
——0Insufficient validation of untrusted input in Downloads in Google Chrome on Mac prior to 149.0.7827.53 allowed a local attacker to potentially perform a sandbox escape via a crafted AppleScript command. (Chromium security severity: Medium)39dCVE-2023-52347—0.3%
——0——CVE-2026-41704—0.3%
——0——