Vulnerabilidades explotables hoy
367,284en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,687
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,295
- Alto9,357
- Medio5,357
- Bajo528
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2023-41090—2.6%
——1——CVE-2024-55582—2.6%
——1——CVE-2025-36573—2.6%
——1——CVE-2026-641015.5 MED2.6%
——1In the Linux kernel, the following vulnerability has been resolved:
fwctl: pds: Validate RPC input size before parsing
The fwctl core allocates the device-specific RPC input buffer with
fwctl_rpc.in_len and passes that buffer to the driver callback.
pdsfc_fw_rpc() casts the buffer to struct fwctl_rpc_pds and then calls
pdsfc_validate_rpc(), which reads fields from that structure before
checking that the input buffer is large enough to contain it. A short
in_len can make pds_fwctl read beyond the allocation.
Reject pds RPC buffers that are smaller than struct fwctl_rpc_pds before
parsing any pds-specific fields.21dCVE-2025-2503—2.6%
——1——CVE-2025-9711—2.6%
——1——CVE-2018-25273—2.6%
——1——CVE-2026-659477.3 ALT2.6%
——1Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.227dCVE-2024-0674—2.6%
——1——CVE-2025-20048—2.6%
——1——CVE-2026-26963—2.6%
——1——CVE-2026-46042—2.6%
——1——CVE-2026-3407—2.6%
——1——CVE-2026-43195—2.6%
——1——CVE-2025-12985—2.6%
——1——CVE-2022-50116—2.6%
——1——CVE-2026-43903—2.6%
——1——CVE-2023-25189—2.6%
——1——CVE-2024-10254—2.6%
——1——CVE-2024-47476—2.6%
——1——CVE-2025-46327—2.6%
——1——CVE-2026-709027.1 ALT2.6%
——1Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Data Relationship Management executes to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).8dCVE-2026-23076—2.6%
——1——CVE-2024-34586—2.6%
——1——CVE-2026-316807.8 ALT2.6%
——1In the Linux kernel, the following vulnerability has been resolved:
net: ipv6: flowlabel: defer exclusive option free until RCU teardown
`ip6fl_seq_show()` walks the global flowlabel hash under the seq-file
RCU read-side lock and prints `fl->opt->opt_nflen` when an option block
is present.
Exclusive flowlabels currently free `fl->opt` as soon as `fl->users`
drops to zero in `fl_release()`. However, the surrounding
`struct ip6_flowlabel` remains visible in the global hash table until
later garbage collection removes it and `fl_free_rcu()` finally tears it
down.
A concurrent `/proc/net/ip6_flowlabel` reader can therefore race that
early `kfree()` and dereference freed option state, triggering a crash
in `ip6fl_seq_show()`.
Fix this by keeping `fl->opt` alive until `fl_free_rcu()`. That matches
the lifetime already required for the enclosing flowlabel while readers
can still reach it under RCU.49dCVE-2020-10846—2.6%
——1——CVE-2025-6017—2.6%
——1——CVE-2026-23069—2.6%
——1——CVE-2025-30756—2.6%
——1——CVE-2026-151153.3 BAJ2.6%
——1Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.115 allowed a local attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)54dCVE-2025-21076—2.6%
——1——CVE-2021-0395—2.6%
——1——CVE-2017-11042—2.6%
——1——CVE-2026-43398—2.6%
——1——CVE-2025-64645—2.6%
——1——CVE-2025-71203—2.6%
——1——CVE-2024-39673—2.6%
——1——CVE-2025-21049—2.6%
——1——CVE-2024-8011—2.6%
——1——CVE-2026-19024—2.6%
——1NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.3.0 allows attackers to cause a denial of service via a dataset whose version 1 or 2 fill value message has the "defined" flag set together with a negative size field, which is not normalized to the library's "undefined" sentinel and reaches H5T_path_find with a NULL datatype.20h