Vulnerabilidades explotables hoy
367,134en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,255
- Alto9,255
- Medio5,260
- Bajo507
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2018-9439—0.3%
——0——CVE-2026-714177.3 ALT0.3%
——0Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/certificates/upload allowed a non-read-only user to create a duplicate row using another certificate body, authority_id, serial, or external_id without requiring permission on the underlying authority. PUT /api/1/certificates//revoke authorized the caller against only the selected Lemur row, so the creator of the duplicate bypassed CertificatePermission. The duplicate had no cert.endpoints, which also bypassed the safeguard that prevents revocation of deployed certificates. Issuer plugins then revoked the real CA-side certificate using certificate.body or external_id under the stored authority credentials. An attacker could therefore revoke arbitrary managed certificates and cause fleet-wide TLS denial of service. The fix rejects duplicate authority_id and serial identities, requires authority access on upload, and checks every matching row during revocation. This issue is fixed in version 1.9.3.13dCVE-2024-29783—0.3%
——0——CVE-2023-40654—0.3%
——0——CVE-2026-158115.8 MED0.3%
——0A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. This omission leaves raw encryption keys resident in memory after the associated structures are freed. A local attacker capable of leveraging memory disclosure techniques could exploit this flaw to retrieve the active encryption key, allowing them to decrypt cluster network communications or inject malicious packets to cause severe high-availability cluster instability.10dCVE-2025-20749—0.3%
——0——CVE-2025-20747—0.3%
——0——CVE-2022-48391—0.3%
——0——CVE-2026-00877.8 ALT0.3%
——0In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app link due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.40dCVE-2025-20774—0.3%
——0——CVE-2022-20082—0.3%
——0——CVE-2025-27074—0.3%
——0——CVE-2023-40108—0.3%
——0——CVE-2023-21350—0.3%
——0——CVE-2024-20036—0.3%
——0——CVE-2025-26462—0.3%
——0——CVE-2026-41971—0.3%
——0——CVE-2026-00457.8 ALT0.3%
——0In bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connection due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.40dCVE-2025-20777—0.3%
——0——CVE-2026-42408—0.3%
——0——CVE-2022-44434—0.3%
——0——CVE-2026-0295—0.3%
——0A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.
The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.13dCVE-2025-48554—0.3%
——0——CVE-2024-23713—0.3%
——0——CVE-2026-28544—0.3%
——0——CVE-2024-20075—0.3%
——0——CVE-2025-30064—0.3%
——0——CVE-2024-40669—0.3%
——0——CVE-2022-33703—0.3%
——0——CVE-2025-36906—0.3%
——0——CVE-2022-44424—0.3%
——0——CVE-2022-44423—0.3%
——0——CVE-2026-28758—0.3%
——0——CVE-2026-6066—0.3%
——0——CVE-2025-20803—0.3%
——0——CVE-2024-44098—0.3%
——0——CVE-2023-42653—0.3%
——0——CVE-2023-21366—0.3%
——0——CVE-2025-12439—0.3%
——0——CVE-2025-20776—0.3%
——0——