Vulnerabilidades explotables hoy
367,165en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,263
- Alto9,268
- Medio5,273
- Bajo508
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2022-20323—0.8%
——0——CVE-2023-42693—0.8%
——0——CVE-2026-315655.5 MED0.8%
——0In the Linux kernel, the following vulnerability has been resolved:
RDMA/irdma: Fix deadlock during netdev reset with active connections
Resolve deadlock that occurs when user executes netdev reset while RDMA
applications (e.g., rping) are active. The netdev reset causes ice
driver to remove irdma auxiliary driver, triggering device_delete and
subsequent client removal. During client removal, uverbs_client waits
for QP reference count to reach zero while cma_client holds the final
reference, creating circular dependency and indefinite wait in iWARP
mode. Skip QP reference count wait during device reset to prevent
deadlock.48dCVE-2025-40841—0.8%
——0——CVE-2024-43089—0.8%
——0——CVE-2025-38311—0.8%
——0——CVE-2021-46747—0.8%
——0Insufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker with an untrusted user space application to map sensitive SMN (System Management Network) apertures leading to a potential escalation of privileges.40dCVE-2025-68955—0.8%
——0——CVE-2024-0026—0.8%
——0——CVE-2025-486515.5 MED0.8%
——0In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.42dCVE-2025-48590—0.8%
——0——CVE-2025-54621—0.8%
——0——CVE-2022-20328—0.8%
——0——CVE-2023-21213—0.8%
——0——CVE-2026-765495.9 MED0.8%
——0The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could allow attackers to make a logged in admin restore an existing backup, reverting the site's database and files to an earlier state, via a crafted link.3dCVE-2023-21076—0.8%
——0——CVE-2023-42681—0.8%
——0——CVE-2023-42695—0.8%
——0——CVE-2023-42691—0.8%
——0——CVE-2025-68956—0.8%
——0——CVE-2023-21229—0.8%
——0——CVE-2025-54619—0.8%
——0——CVE-2025-21062—0.8%
——0——CVE-2026-28690—0.8%
——0——CVE-2022-22069—0.8%
——0——CVE-2018-9434—0.8%
——0——CVE-2025-39889—0.8%
——0——CVE-2026-41969—0.8%
——0——CVE-2023-20744—0.8%
——0——CVE-2026-56272—0.8%
——0——CVE-2023-42694—0.8%
——0——CVE-2023-21047—0.8%
——0——CVE-2024-33027—0.8%
——0——CVE-2025-48574—0.8%
——0——CVE-2026-31678—0.8%
——0——CVE-2023-42688—0.8%
——0——CVE-2026-557455.4 MED0.8%
——0Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/inc/pfs.editfolder.php, the folder update action ('a=update') updates folder metadata (title, description, public/gallery flags) without calling cot_check_xg to validate the anti-CSRF token.21dCVE-2023-40114—0.8%
——0——CVE-2024-53267—0.8%
——0——CVE-2023-42686—0.8%
——0——