Vulnerabilidades explotables hoy
367,069en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,242
- Alto9,242
- Medio5,232
- Bajo501
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-150604.7 MED0.2%
——0When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes, even privileged ones.
- versions older than v259 are not affected, unless unprivileged access is granted for the `register-machine` polkit action via a local, custom policy config file
- versions older than v258 are not affected
- unrelated to the systemd service manager (pid 1 or user session managers)
- systemd-machined is not typically installed by default, and is typically in an optional, separate package (e.g.: systemd-container)
- terminal-only or remote sessions (e.g.: ssh) are not affected21dCVE-2026-637026.3 MED0.2%
——0Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.14dCVE-2025-48558—0.2%
——0——CVE-2025-48597—0.2%
——0——CVE-2025-27040—0.2%
——0——CVE-2026-495006.0 MED0.2%
——0Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of Service and Elevation of Privileges.11dCVE-2023-38455—0.2%
——0——CVE-2026-111157.3 ALT0.2%
——0Use after free in Updater in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)39dCVE-2025-596136.7 MED0.1%
——0Memory Corruption when output buffer size is smaller than input buffer size during data copying operation.40dCVE-2025-48542—0.2%
——0——CVE-2023-38453—0.2%
——0——CVE-2023-42643—0.2%
——0——CVE-2025-27062—0.2%
——0——CVE-2025-20789—0.2%
——0——CVE-2026-419766.6 MED0.2%
——0Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vulnerability may affect service confidentiality.39dCVE-2026-41968—0.2%
——0——CVE-2025-47320—0.2%
——0——CVE-2023-42650—0.2%
——0——CVE-2026-213685.3 MED0.2%
——0Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.55dCVE-2025-52586—0.2%
——0——CVE-2025-26449—0.2%
——0——CVE-2024-20120—0.2%
——0——CVE-2025-32313—0.2%
——0——CVE-2023-42640—0.2%
——0——CVE-2023-38443—0.2%
——0——CVE-2024-39435—0.2%
——0——CVE-2023-42633—0.2%
——0——CVE-2026-110357.3 ALT0.2%
——0Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via a crafted XML file. (Chromium security severity: Medium)39dCVE-2023-38464—0.2%
——0——CVE-2026-21444—0.2%
——0——CVE-2025-486497.8 ALT0.2%
——0In multiple locations, there is a possible way to reset user-selected permissions selections due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.40dCVE-2024-27230—0.2%
——0——CVE-2024-47035—0.2%
——0——CVE-2023-38459—0.2%
——0——CVE-2024-20115—0.2%
——0——CVE-2025-22431—0.2%
——0——CVE-2023-38458—0.2%
——0——CVE-2023-42634—0.2%
——0——CVE-2023-21358—0.2%
——0——CVE-2026-28550—0.2%
——0——