Vulnerabilidades explotables hoy
350,257en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,647
Nuevos KEV · 24H0
Exploit Today ≥ 701,583
Distribución · última ventana
- Crítico1,426
- Alto4,742
- Medio3,931
- Bajo306
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-21030—0.7%
——0——CVE-2022-32635—0.7%
——0——CVE-2025-48646—0.7%
——0——CVE-2023-21380—0.7%
——0——CVE-2022-26436—0.7%
——0——CVE-2024-47027—0.7%
——0——CVE-2026-234634.7 MED0.7%
——0In the Linux kernel, the following vulnerability has been resolved:
soc: fsl: qbman: fix race condition in qman_destroy_fq
When QMAN_FQ_FLAG_DYNAMIC_FQID is set, there's a race condition between
fq_table[fq->idx] state and freeing/allocating from the pool and
WARN_ON(fq_table[fq->idx]) in qman_create_fq() gets triggered.
Indeed, we can have:
Thread A Thread B
qman_destroy_fq() qman_create_fq()
qman_release_fqid()
qman_shutdown_fq()
gen_pool_free()
-- At this point, the fqid is available again --
qman_alloc_fqid()
-- so, we can get the just-freed fqid in thread B --
fq->fqid = fqid;
fq->idx = fqid * 2;
WARN_ON(fq_table[fq->idx]);
fq_table[fq->idx] = fq;
fq_table[fq->idx] = NULL;
And adding some logs between qman_release_fqid() and
fq_table[fq->idx] = NULL makes the WARN_ON() trigger a lot more.
To prevent that, ensure that fq_table[fq->idx] is set to NULL before
gen_pool_free() is called by using smp_wmb().7dCVE-2025-48565—0.7%
——0——CVE-2026-561174.7 MED0.7%
——0dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handling within src/control.c that allows local unprivileged attackers to trigger memory corruption when privilege separation is disabled. Attackers can connect to the control socket and send a privileged command such as -x, causing control_recvdata() to free the client object while the same READ+HANGUP event subsequently reaches control_hangup() with the stale pointer, resulting in a use-after-free condition exploitable in deployments using --disable-privsep or where privsep initialization has failed with the control socket operating in mode 0666.7dCVE-2026-33787—0.7%
——0——CVE-2024-21462—0.7%
——0——CVE-2026-53820—0.7%
——0——CVE-2026-46017—0.7%
——0——CVE-2022-44421—0.7%
——0——CVE-2023-34971—0.7%
——0——CVE-2026-415152.5 BAJ0.7%
——0OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.9.0 and prior to version 4.11.0, the RSA-OAEP decryption implementation in the NXP CAAM crypto driver uses non-constant-time `memcmp()` for label hash verification and has multiple distinguishable error paths. This creates a Manger-style padding oracle that allows an attacker to recover RSA-OAEP plaintext with approximately 1000-2000 adaptive chosen ciphertext queries. Version 4.11.0 contains a patch. As a workaround, disable the NXP CAAM RSA driver with `CFG_CRYPTO_DRV_RSA=n`.14dCVE-2025-21060—0.7%
——0——CVE-2026-314664.7 MED0.7%
——0In the Linux kernel, the following vulnerability has been resolved:
mm/huge_memory: fix folio isn't locked in softleaf_to_folio()
On arm64 server, we found folio that get from migration entry isn't locked
in softleaf_to_folio(). This issue triggers when mTHP splitting and
zap_nonpresent_ptes() races, and the root cause is lack of memory barrier
in softleaf_to_folio(). The race is as follows:
CPU0 CPU1
deferred_split_scan() zap_nonpresent_ptes()
lock folio
split_folio()
unmap_folio()
change ptes to migration entries
__split_folio_to_order() softleaf_to_folio()
set flags(including PG_locked) for tail pages folio = pfn_folio(softleaf_to_pfn(entry))
smp_wmb() VM_WARN_ON_ONCE(!folio_test_locked(folio))
prep_compound_page() for tail pages
In __split_folio_to_order(), smp_wmb() guarantees page flags of tail pages
are visible before the tail page becomes non-compound. smp_wmb() should
be paired with smp_rmb() in softleaf_to_folio(), which is missed. As a
result, if zap_nonpresent_ptes() accesses migration entry that stores tail
pfn, softleaf_to_folio() may see the updated compound_head of tail page
before page->flags.
This issue will trigger VM_WARN_ON_ONCE() in pfn_swap_entry_folio()
because of the race between folio split and zap_nonpresent_ptes()
leading to a folio incorrectly undergoing modification without a folio
lock being held.
This is a BUG_ON() before commit 93976a20345b ("mm: eliminate further
swapops predicates"), which in merged in v6.19-rc1.
To fix it, add missing smp_rmb() if the softleaf entry is migration entry
in softleaf_to_folio() and softleaf_to_page().
[tujinjiang@huawei.com: update function name and comments]7dCVE-2026-21020—0.7%
——0——CVE-2025-7214—0.7%
——0——CVE-2026-26949—0.7%
——0——CVE-2026-33565—0.7%
——0——CVE-2025-46587—0.7%
——0——CVE-2025-46588—0.7%
——0——CVE-2022-33689—0.7%
——0——CVE-2025-47359—0.7%
——0——CVE-2023-21135—0.7%
——0——CVE-2022-20112—0.7%
——0——CVE-2023-20842—0.7%
——0——CVE-2022-42533—0.7%
——0——CVE-2023-20841—0.7%
——0——CVE-2026-40385—0.7%
——0——CVE-2026-22276—0.7%
——0——CVE-2025-48642—0.7%
——0——CVE-2026-440693.9 BAJ0.7%
——0An integer underflow in the volxlate function in Netatalk 3.0.0 through 4.4.2 allows a local privileged user to obtain limited information, modify limited data, or cause a minor service disruption via crafted volume translation input.15hCVE-2025-13665—0.7%
——0——CVE-2021-25481—0.7%
——0——CVE-2025-13668—0.7%
——0——CVE-2026-46388—0.7%
——0——CVE-2025-71074—0.7%
——0——