Vulnerabilidades explotables hoy
367,284en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,274
- Alto9,334
- Medio5,332
- Bajo522
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2025-25253—1.2%
——0——CVE-2026-21912—1.2%
——0——CVE-2022-20383—1.2%
——0——CVE-2023-35675—1.2%
——0——CVE-2024-43051—1.2%
——0——CVE-2026-487905.5 MED1.2%
——0Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `settings.json` using Viper's default `configPermissions` of `0o644`, leaving the credential file world-readable on standard Linux and macOS systems. Any other local UID on the host can read the file and recover the platform JWT, which grants full Turso platform access scoped to the user's organizations. Version 1.0.26 patches the issue.19dCVE-2023-34438—1.2%
——0——CVE-2025-449643.9 BAJ1.2%
——0A lack of SSL certificate validation in BlueStacks v5.20 allows attackers to execute a man-it-the-middle attack and obtain sensitive information.58dCVE-2022-20051—1.2%
——0——CVE-2024-23706—1.2%
——0——CVE-2023-21124—1.2%
——0——CVE-2023-48412—1.2%
——0——CVE-2024-20048—1.2%
——0——CVE-2021-0979—1.2%
——0——CVE-2026-22079—1.2%
——0——CVE-2022-20102—1.2%
——0——CVE-2026-45170—1.2%
——0——CVE-2022-20100—1.2%
——0——CVE-2023-21295—1.2%
——0——CVE-2025-399277.8 ALT1.2%
——0In the Linux kernel, the following vulnerability has been resolved:
ceph: fix race condition validating r_parent before applying state
Add validation to ensure the cached parent directory inode matches the
directory info in MDS replies. This prevents client-side race conditions
where concurrent operations (e.g. rename) cause r_parent to become stale
between request initiation and reply processing, which could lead to
applying state changes to incorrect directory inodes.
[ idryomov: folded a kerneldoc fixup and a follow-up fix from Alex to
move CEPH_CAP_PIN reference when r_parent is updated:
When the parent directory lock is not held, req->r_parent can become
stale and is updated to point to the correct inode. However, the
associated CEPH_CAP_PIN reference was not being adjusted. The
CEPH_CAP_PIN is a reference on an inode that is tracked for
accounting purposes. Moving this pin is important to keep the
accounting balanced. When the pin was not moved from the old parent
to the new one, it created two problems: The reference on the old,
stale parent was never released, causing a reference leak.
A reference for the new parent was never acquired, creating the risk
of a reference underflow later in ceph_mdsc_release_request(). This
patch corrects the logic by releasing the pin from the old parent and
acquiring it for the new parent when r_parent is switched. This
ensures reference accounting stays balanced. ]33dCVE-2021-0922—1.2%
——0——CVE-2026-446297.9 ALT1.2%
——0Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appliances (SV-100E and SV-300E series) and Synergis Softwire installed on Windows servers.3dCVE-2025-27577—1.2%
——0——CVE-2022-20092—1.2%
——0——CVE-2025-47371—1.2%
——0——CVE-2024-49830—1.2%
——0——CVE-2024-45583—1.2%
——0——CVE-2026-41332—1.2%
——0——CVE-2024-20892—1.2%
——0——CVE-2022-20104—1.2%
——0——CVE-2021-39689—1.2%
——0——CVE-2024-47290—1.2%
——0——CVE-2018-9383—1.2%
——0——CVE-2022-503397.8 ALT1.2%
——0In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: avoid hci_dev_test_and_set_flag() in mgmt_init_hdev()
syzbot is again reporting attempt to cancel uninitialized work
at mgmt_index_removed() [1], for setting of HCI_MGMT flag from
mgmt_init_hdev() from hci_mgmt_cmd() from hci_sock_sendmsg() can
race with testing of HCI_MGMT flag from mgmt_index_removed() from
hci_sock_bind() due to lack of serialization via hci_dev_lock().
Since mgmt_init_hdev() is called with mgmt_chan_list_lock held, we can
safely split hci_dev_test_and_set_flag() into hci_dev_test_flag() and
hci_dev_set_flag(). Thus, in order to close this race, set HCI_MGMT flag
after INIT_DELAYED_WORK() completed.
This is a local fix based on mgmt_chan_list_lock. Lack of serialization
via hci_dev_lock() might be causing different race conditions somewhere
else. But a global fix based on hci_dev_lock() should deserve a future
patch.27dCVE-2022-33685—1.2%
——0——CVE-2022-20415—1.2%
——0——CVE-2025-687497.8 ALT1.2%
——0In the Linux kernel, the following vulnerability has been resolved:
accel/ivpu: Fix race condition when unbinding BOs
Fix 'Memory manager not clean during takedown' warning that occurs
when ivpu_gem_bo_free() removes the BO from the BOs list before it
gets unmapped. Then file_priv_unbind() triggers a warning in
drm_mm_takedown() during context teardown.
Protect the unmapping sequence with bo_list_lock to ensure the BO is
always fully unmapped when removed from the list. This ensures the BO
is either fully unmapped at context teardown time or present on the
list and unmapped by file_priv_unbind().33dCVE-2021-39747—1.2%
——0——CVE-2025-21057—1.1%
——0——CVE-2026-210697.8 ALT1.2%
——0Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.12d