Vulnerabilidades explotables hoy
367,069en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,242
- Alto9,242
- Medio5,232
- Bajo501
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2024-0028—0.1%
——0——CVE-2025-59600—0.1%
——0——CVE-2025-47376—0.1%
——0——CVE-2026-00435.5 MED0.1%
——0In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.40dCVE-2025-31944—0.1%
——0——CVE-2026-3428—0.1%
——0——CVE-2026-815234.4 MED0.1%
——0A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied database identifier to be accepted without sanitization. The resulting impact is limited to incorrect schema selection, which may lead to limited disclosure or modification of information handled by the application.2dCVE-2024-49732—0.1%
——0——CVE-2024-9858—0.1%
——0——CVE-2024-21787—0.1%
——0——CVE-2024-47028—0.1%
——0——CVE-2025-471475.7 MED0.1%
——0Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a limited duration.
This issue affects Command Centre Mobile Client versions prior to 9.40.123.17dCVE-2026-168967.1 ALT0.1%
——0IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized access to files due to a time-of-check time-of-use (TOCTOU) race condition.14dCVE-2025-20781—0.1%
——0——CVE-2026-285807.8 ALT0.1%
——0In multiple functions, there is a possible desync in persistence due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.40dCVE-2025-27041—0.1%
——0——CVE-2026-28547—0.1%
——0——CVE-2025-47369—0.1%
——0——CVE-2026-23115—0.1%
——0——CVE-2025-20805—0.1%
——0——CVE-2026-252717.8 ALT0.1%
——0Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.55dCVE-2026-00967.8 ALT0.1%
——0In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.40dCVE-2025-47380—0.1%
——0——CVE-2025-27039—0.1%
——0——CVE-2025-20806—0.1%
——0——CVE-2026-252778.8 ALT0.1%
——0Memory corruption while using Strongbox due to buffer overflow.40dCVE-2025-20765—0.1%
——0——CVE-2025-31356—0.1%
——0Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: Hypervisor may allow an information disclosure. A system software adversary with a privileged user access combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without any user interaction. The potential vulnerability may impact the confidentiality (high), integrity (low) and no effect on availability. Subsequent system impacts include reduced confidentiality (low), integrity (low), and no effect on availability.18dCVE-2025-21485—0.1%
——0——CVE-2026-54055—0.1%
——0——CVE-2023-6728—0.1%
——0——CVE-2026-20429—0.1%
——0——CVE-2025-54422—0.1%
——0——CVE-2025-323487.8 ALT0.1%
——0In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.40dCVE-2023-3781—0.1%
——0——CVE-2026-00937.8 ALT0.1%
——0In multiple locations, there is a possible misleading UI due to obfuscation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.40dCVE-2026-11347—0.1%
——0——CVE-2025-485707.8 ALT0.1%
——0In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from the background due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.40dCVE-2025-47388—0.1%
——0——CVE-2021-0696—0.1%
——0——