Vulnerabilidades explotables hoy
367,069en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,242
- Alto9,242
- Medio5,232
- Bajo501
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2023-20733—0.1%
——0——CVE-2022-48442—0.1%
——0——CVE-2023-21190—0.1%
——0——CVE-2025-20648—0.1%
——0——CVE-2024-45560—0.1%
——0——CVE-2025-47339—0.1%
——0——CVE-2025-20028—0.1%
——0——CVE-2025-20730—0.1%
——0——CVE-2018-9410—0.1%
——0——CVE-2025-58279—0.1%
——0——CVE-2025-21433—0.1%
——0——CVE-2026-108003.6 BAJ0.1%
——0A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_features of the file fastdeploy/multimodal/hasher.py of the component MultimodalHasher. Executing a manipulation can lead to use of weak hash. The attack requires local access. A high complexity level is associated with this attack. The exploitation is known to be difficult. This patch is called 374945747652a8d32965591c0c01a00c88b7067f. Applying a patch is advised to resolve this issue.40dCVE-2018-9421—0.1%
——0——CVE-2026-00866.8 MED0.1%
——0In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.40dCVE-2024-20112—0.1%
——0——CVE-2025-36935—0.1%
——0——CVE-2024-47041—0.1%
——0——CVE-2023-38447—0.1%
——0——CVE-2026-168026.5 MED0.1%
——0Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when no vault is selected.33dCVE-2024-39433—0.1%
——0——CVE-2025-10227—0.1%
——0——CVE-2025-36925—0.1%
——0——CVE-2025-36919—0.1%
——0——CVE-2025-20783—0.1%
——0——CVE-2026-21375—0.1%
——0——CVE-2026-261037.1 ALT0.1%
——0A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned udisks daemon to overwrite encryption metadata on block devices. This can permanently invalidate encryption keys and render encrypted volumes inaccessible. Successful exploitation results in a denial-of-service condition through irreversible data loss.47dCVE-2026-24082—0.1%
——0——CVE-2022-48441—0.1%
——0——CVE-2024-32930—0.1%
——0——CVE-2026-623816.6 MED0.1%
——0luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate with a 2040-bit RSA key. For a 255-byte signature, the BIT STRING allocation is computed from the DER length encoding of 255 bytes, but the payload written after prepending the unused-bits byte is 256 bytes, requiring one additional DER length octet. As a result the allocation is 259 bytes while the tag, length, unused-bits byte, and signature require 260 bytes, and the final memcpy writes one byte beyond the heap buffer. The overflow is reachable through the exported Lua interface via create_selfsigned(); whether it is remotely exploitable depends on the embedding application. The vulnerable code is present on the openwrt-18.06 through openwrt-25.12 release branches and is absent from master, where the luci-lib-px5g package has been removed rather than patched.7dCVE-2025-20785—0.1%
——0——CVE-2017-13309—0.1%
——0——CVE-2023-38461—0.1%
——0——CVE-2024-32914—0.1%
——0——CVE-2024-45565—0.1%
——0——CVE-2024-32910—0.1%
——0——CVE-2025-47343—0.1%
——0——CVE-2024-44093—0.1%
——0——CVE-2026-108133.6 BAJ0.1%
——0A flaw has been found in LMCache up to 0.4.6. This affects the function hex_hash_to_int16 of the file lmcache/integration/vllm/utils.py of the component KV Cache Handler. Executing a manipulation can lead to use of weak hash. The attack needs to be launched locally. The attack requires a high level of complexity. It is indicated that the exploitability is difficult. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.40dCVE-2024-49744—0.1%
——0——