Vulnerabilidades explotables hoy
367,069en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,242
- Alto9,242
- Medio5,232
- Bajo501
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2025-682437.0 ALT0.1%
——0In the Linux kernel, the following vulnerability has been resolved:
NFS: Check the TLS certificate fields in nfs_match_client()
If the TLS security policy is of type RPC_XPRTSEC_TLS_X509, then the
cert_serial and privkey_serial fields need to match as well since they
define the client's identity, as presented to the server.32dCVE-2026-41961—0.1%
——0——CVE-2026-329776.3 MED0.1%
——0OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that uses an unanchored container path during the final move operation. An attacker can exploit a time-of-check-time-of-use race condition by modifying parent paths inside the sandbox to redirect committed files outside the validated writable path within the container mount namespace.37dCVE-2026-28545—0.1%
——0——CVE-2026-20440—0.1%
——0——CVE-2026-41164—0.1%
——0——CVE-2026-419735.9 MED0.1%
——0Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability.39dCVE-2023-40648—0.1%
——0——CVE-2022-20256—0.1%
——0——CVE-2023-40646—0.1%
——0——CVE-2026-466934.1 MED0.1%
——0ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a magick -distribute-cache service can hijack a file descriptor in the server process when a race condition is met. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.39dCVE-2023-20826—0.1%
——0——CVE-2026-42489—0.1%
——0——CVE-2022-20371—0.1%
——0——CVE-2026-41520—0.1%
——0——CVE-2026-21373—0.1%
——0——CVE-2022-20097—0.1%
——0——CVE-2026-29084—0.1%
——0——CVE-2026-47334—0.1%
——0——CVE-2024-32899—0.1%
——0——CVE-2024-11624—0.1%
——0——CVE-2026-20428—0.1%
——0——CVE-2026-20707—0.1%
——0Hardware logic contains race conditions for some 3rd Gen Intel(R) Xeon(R) Scalable Processors within Ring 3: unprivileged software may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.18dCVE-2023-40643—0.1%
——0——CVE-2026-34866—0.1%
——0——CVE-2025-26445—0.1%
——0——CVE-2023-21466—0.1%
——0——CVE-2025-48617—0.1%
——0——CVE-2026-20426—0.1%
——0——CVE-2026-20444—0.1%
——0——CVE-2025-47325—0.1%
——0——CVE-2023-40647—0.1%
——0——CVE-2025-20795—0.1%
——0——CVE-2024-47018—0.1%
——0——CVE-2024-49737—0.1%
——0——CVE-2024-53835—0.1%
——0——CVE-2025-20778—0.1%
——0——CVE-2026-34859—0.1%
——0——CVE-2026-20425—0.1%
——0——CVE-2025-48568—0.1%
——0——