Vulnerabilidades explotables hoy
367,028en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,258
- Alto9,252
- Medio5,224
- Bajo500
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2023-35988——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused3dCVE-2026-51282——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.31dCVE-2026-252607.8 ALT0.0%
——0Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.39dCVE-2021-48004——
——0Rejected reason: This CVE ID has been rejected.3dCVE-2021-48005——
——0Rejected reason: This CVE ID has been rejected.3dCVE-2022-51001——
——0Rejected reason: This CVE ID has been rejected.3dCVE-2022-51002——
——0Rejected reason: This CVE ID has been rejected.3dCVE-2023-35135——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused3dCVE-2023-32287——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused3dCVE-2026-56873——
——0Rejected reason: reserved but not needed12dCVE-2023-35190——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused3dCVE-2026-28534——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.20dCVE-2023-49605——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused3dCVE-2026-826387.5 ALT—
——0jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable hostnames mapping to private addresses to retrieve cloud metadata and internal service content.14hCVE-2026-29024——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.20dCVE-2026-9611——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.31dCVE-2026-167426.7 MED0.0%
——0systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user21dCVE-2026-6889——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.31dCVE-2026-56875——
——0Rejected reason: reserved but not needed9dCVE-2026-826367.9 ALT—
——0Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is used to process an error message that may have shell metacharacters. This occurs in core-admin-linux/file-copy-vm/qfile-dom0-agent.c.14hCVE-2023-46709——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused3dCVE-2026-11950——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.60dCVE-2026-825456.3 MED—
——0A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/sup_searchfrm.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.13hCVE-2026-62164——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-60087. Reason: This candidate is a duplicate of CVE-2026-60087. Notes: All CVE users should reference CVE-2026-60087 instead of this candidate.46dCVE-2026-48533——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.39dCVE-2026-77454——
——0Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as exists/2 over a relationship that declares both a limit (or from_many?) and a parent(...)-referencing filter or sort.
AshSql.Join.related_query/3 skips the caller-supplied exists predicate for such relationships and delegates it to limit_from_many/5. When the relationship's own filter or sort references parent(...), limit_from_many/5 takes a branch that drops both the limit and the predicate, emitting a bare correlated EXISTS with no predicate. The check then matches any record that has any related row. Most severely, when the expression backs a policy (for example authorize_if expr(exists(memberships, user_id == ^actor(:id)))), the actor-scoping condition disappears and the policy passes for any actor with any related row.
This issue affects ash_sql: from 0.4.1 before 0.7.1.16hCVE-2026-826466.1 MED—
——0WWBN AVideo contains an unauthenticated reflected cross-site scripting vulnerability in the url2Embed.json.php endpoint that allows attackers to inject malicious scripts by supplying URLs with HTML metacharacters. Attackers can mint an encrypted evideo payload containing unescaped markup, then deliver it as a legitimate-looking link on the site's own domain to execute JavaScript in victims' sessions and steal cookies or CSRF tokens.13hCVE-2026-826514.9 MED—
——0SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*path and /repo/diff/*path endpoints in kernel/server/serve.go. These routes require admin authentication but construct file paths independently, so an authenticated administrator can retrieve historical snapshots of sensitive files that the guard is meant to block, including data/.siyuan/publishAccess.json (plaintext publish-mode passwords) and files under data/templates/.13hCVE-2026-51240——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.31dCVE-2026-35028——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.20dCVE-2026-826525.3 MED—
——0SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible content through these three listing mechanisms despite admin configuration marking content unlisted.13hCVE-2026-826584.3 MED—
——0Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read another user's future role memberships. Attackers can bypass profile-level authorization by directly calling the reload_future_memberships endpoint with a victim's user UUID to disclose sensitive membership information.13hCVE-2025-32084——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused19dCVE-2026-50238——
——0Rejected reason: Red Hat Product Security has concluded that this CVE is not required. The reported issue has been classified as a regular bug and will be addressed through the standard bug-fixing process.59dCVE-2026-28999——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.20dCVE-2025-66322—0.0%
——0——CVE-2026-825406.3 MED—
——0A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/cust_searchfrm.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.16hCVE-2026-69099——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.9dCVE-2025-27570——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused19dCVE-2023-42778——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused3d