Vulnerabilidades explotables hoy
367,284en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,274
- Alto9,334
- Medio5,332
- Bajo522
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2022-25652—1.3%
——0——CVE-2024-45578—1.3%
——0——CVE-2026-530995.5 MED1.3%
——0In the Linux kernel, the following vulnerability has been resolved:
bpf: Switch CONFIG_CFI_CLANG to CONFIG_CFI
This was renamed in commit 23ef9d439769 ("kcfi: Rename CONFIG_CFI_CLANG
to CONFIG_CFI") as it is now a compiler-agnostic option. Using the wrong
name results in the code getting compiled out. Meaning the CFI failures
for btf_dtor_kfunc_t would still trigger.41dCVE-2022-21752—1.3%
——0——CVE-2026-52721—1.3%
——0——CVE-2024-43046—1.3%
——0——CVE-2022-20087—1.3%
——0——CVE-2022-21753—1.3%
——0——CVE-2021-0554—1.3%
——0——CVE-2021-25484—1.3%
——0——CVE-2025-25058—1.3%
——0——CVE-2025-15038—1.3%
——0——CVE-2026-35603—1.3%
——0——CVE-2024-45564—1.3%
——0——CVE-2026-00563.3 BAJ1.3%
——0In setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.41dCVE-2021-0680—1.3%
——0——CVE-2025-58131—1.3%
——0——CVE-2026-289965.5 MED1.3%
——0A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to access sensitive user data.14dCVE-2026-6090—1.3%
——0——CVE-2024-34721—1.3%
——0——CVE-2024-45579—1.3%
——0——CVE-2026-68995.6 MED1.3%
——0Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It might allow connection between an OPC UA client and server using a revoked certificate.40dCVE-2024-56456—1.3%
——0——CVE-2026-47270—1.3%
——0——CVE-2026-178637.8 ALT1.3%
——0Inappropriate implementation in Browser in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)28dCVE-2019-25343—1.3%
——0——CVE-2021-23211—1.3%
——0——CVE-2026-642155.5 MED1.3%
——0In the Linux kernel, the following vulnerability has been resolved:
drm/msm/a6xx: Check kzalloc return in a8xx_hfi_send_perf_table
Check the return value of kzalloc() to prevent a NULL pointer
dereference on allocation failure.
Patchwork: https://patchwork.freedesktop.org/patch/721342/20dCVE-2023-535207.8 ALT1.3%
——0In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: Fix hci_suspend_sync crash
If hci_unregister_dev() frees the hci_dev object but hci_suspend_notifier
may still be accessing it, it can cause the program to crash.
Here's the call trace:
<4>[102152.653246] Call Trace:
<4>[102152.653254] hci_suspend_sync+0x109/0x301 [bluetooth]
<4>[102152.653259] hci_suspend_dev+0x78/0xcd [bluetooth]
<4>[102152.653263] hci_suspend_notifier+0x42/0x7a [bluetooth]
<4>[102152.653268] notifier_call_chain+0x43/0x6b
<4>[102152.653271] __blocking_notifier_call_chain+0x48/0x69
<4>[102152.653273] __pm_notifier_call_chain+0x22/0x39
<4>[102152.653276] pm_suspend+0x287/0x57c
<4>[102152.653278] state_store+0xae/0xe5
<4>[102152.653281] kernfs_fop_write+0x109/0x173
<4>[102152.653284] __vfs_write+0x16f/0x1a2
<4>[102152.653287] ? selinux_file_permission+0xca/0x16f
<4>[102152.653289] ? security_file_permission+0x36/0x109
<4>[102152.653291] vfs_write+0x114/0x21d
<4>[102152.653293] __x64_sys_write+0x7b/0xdb
<4>[102152.653296] do_syscall_64+0x59/0x194
<4>[102152.653299] entry_SYSCALL_64_after_hwframe+0x5c/0xc1
This patch holds the reference count of the hci_dev object while
processing it in hci_suspend_notifier to avoid potential crash
caused by the race condition.28dCVE-2026-281455.3 MED1.3%
——0Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State.
This issue affects MasterStudy LMS: from n/a through 3.7.39.19dCVE-2023-28571—1.3%
——0——CVE-2026-7257—1.3%
——0——CVE-2023-21256—1.3%
——0——CVE-2026-46685—1.3%
——0——CVE-2023-50301—1.3%
——0——CVE-2026-28689—1.3%
——0——CVE-2025-21026—1.3%
——0——CVE-2025-20995—1.3%
——0——CVE-2021-0547—1.3%
——0——CVE-2022-20095—1.3%
——0——