Vulnerabilidades explotables hoy
367,069en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,242
- Alto9,242
- Medio5,232
- Bajo501
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-114812.5 BAJ0.2%
——0A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.LookupByContentHash of the file indexer/chunker.go of the component Postgres Embedding Cache. Executing a manipulation of the argument content_hash can lead to use of weak hash. The attack needs to be launched locally. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.39dCVE-2023-38437—0.2%
——0——CVE-2026-499585.0 MED0.2%
——0Hermes WebUI before version 0.51.303 contains a time-of-check time-of-use (TOCTOU) race condition vulnerability in the git_discard function within api/workspace_git.py that allows attackers to delete files outside the configured workspace boundary by replacing a validated path component with a symlink after validation but before deletion. Attackers can substitute a workspace-controlled path component with a symlink pointing to an external directory between the safe_resolve_ws() validation step and the subsequent Path.unlink() or shutil.rmtree() deletion call, causing the delete operation to follow the symlink and remove arbitrary files outside the workspace.39dCVE-2022-48459—0.2%
——0——CVE-2026-84977.4 ALT0.2%
——0Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate.10dCVE-2025-26448—0.2%
——0——CVE-2022-48448—0.2%
——0——CVE-2026-148377.8 ALT0.2%
——0Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise.32dCVE-2025-36887—0.2%
——0——CVE-2025-13492—0.2%
——0——CVE-2025-36105—0.2%
——0——CVE-2023-38436—0.2%
——0——CVE-2022-47354—0.2%
——0——CVE-2025-58293—0.2%
——0——CVE-2022-47356—0.2%
——0——CVE-2023-40652—0.2%
——0——CVE-2023-52536—0.2%
——0——CVE-2023-38438—0.2%
——0——CVE-2023-48343—0.2%
——0——CVE-2024-39430—0.2%
——0——CVE-2024-20116—0.2%
——0——CVE-2026-28540—0.2%
——0——CVE-2025-48524—0.2%
——0——CVE-2024-34738—0.2%
——0——CVE-2023-40631—0.2%
——0——CVE-2025-22407—0.2%
——0——CVE-2023-52350—0.2%
——0——CVE-2018-9431—0.2%
——0——CVE-2023-48349—0.2%
——0——CVE-2023-48357—0.2%
——0——CVE-2023-21345—0.2%
——0——CVE-2024-29757—0.2%
——0——CVE-2022-47355—0.2%
——0——CVE-2023-48344—0.2%
——0——CVE-2025-22428—0.2%
——0——CVE-2023-48346—0.2%
——0——CVE-2024-56186—0.2%
——0——CVE-2023-33046—0.2%
——0——CVE-2024-43769—0.2%
——0——CVE-2025-0076—0.2%
——0——