Vulnerabilidades explotables hoy
352,232en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,653
Nuevos KEV · 24H0
Exploit Today ≥ 701,590
Distribución · última ventana
- Crítico2,107
- Alto7,066
- Medio6,094
- Bajo575
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2024-25989—0.4%
——0——CVE-2025-37112—0.4%
——0——CVE-2025-36154—0.4%
——0——CVE-2025-66592—0.4%
——0——CVE-2024-29750—0.4%
——0——CVE-2023-30927—0.4%
——0——CVE-2024-53032—0.4%
——0——CVE-2025-54602—0.4%
——0——CVE-2023-30918—0.4%
——0——CVE-2026-641587.3 ALT0.4%
——0In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix write streaming disablement if fd open O_RDWR
In netfs_perform_write(), "write streaming" (the caching of dirty data in
dirty but !uptodate folios) is performed to avoid the need to read data
that is just going to get immediately overwritten. However, this is/will
be disabled in three circumstances: if the fd is open O_RDWR, if fscache is
in use (as we need to round out the blocks for DIO) or if content
encryption is enabled (again for rounding out purposes).
The idea behind disabling it if the fd is open O_RDWR is that we'd need to
flush the write-streaming page before we could read the data, particularly
through mmap. But netfs now fills in the gaps if ->read_folio() is called
on the page, so that is unnecessary. Further, this doesn't actually work
if a separate fd is open for reading.
Fix this by removing the check for O_RDWR, thereby allowing streaming
writes even when we might read.
This caused a number of problems with the generic/522 xfstest, but those
are now fixed.3dCVE-2023-21143—0.4%
——0——CVE-2026-112815.0 MED0.4%
——0Integer overflow in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted ETW event. (Chromium security severity: Low)13hCVE-2024-56191—0.4%
——0——CVE-2025-66593—0.4%
——0——CVE-2023-40112—0.4%
——0——CVE-2024-29739—0.4%
——0——CVE-2023-21231—0.4%
——0——CVE-2025-63729—0.4%
——0——CVE-2023-32834—0.4%
——0——CVE-2024-29782—0.4%
——0——CVE-2023-30941—0.4%
——0——CVE-2023-30926—0.4%
——0——CVE-2022-47326—0.4%
——0——CVE-2022-42755—0.4%
——0——CVE-2022-42754—0.4%
——0——CVE-2026-411166.3 MED0.4%
——0Dell Inventory Collector Client, versions prior to 13.8.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary File Write.12hCVE-2022-39132—0.4%
——0——CVE-2022-28794—0.4%
——0——CVE-2025-21472—0.4%
——0——CVE-2022-39120—0.4%
——0——CVE-2025-48588—0.4%
——0——CVE-2022-44429—0.4%
——0——CVE-2022-42760—0.4%
——0——CVE-2024-20032—0.4%
——0——CVE-2026-20417—0.4%
——0——CVE-2022-39122—0.4%
——0——CVE-2026-24922—0.4%
——0——CVE-2022-39121—0.4%
——0——CVE-2024-20105—0.4%
——0——CVE-2026-210343.3 BAJ0.4%
——0Improper export of android application components in Samsung Auto prior to version 3.1.2.61 in Android 15 and 3.2.0.38 in Android 16 allows local attacker to change audio configuration.23d