Vulnerabilidades explotables hoy
367,165en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,685
Nuevos KEV · 24H0
Exploit Today ≥ 701,629
Distribución · última ventana
- Crítico2,263
- Alto9,269
- Medio5,274
- Bajo508
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-580937.0 ALT0.5%
——0The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty lock, the handler did not revalidate the state of the terminal, and could proceed to link a terminal that was concurrently being destroyed to the calling process' session.
An unprivileged local user can exploit this race condition to escalate privileges.4dCVE-2025-48526—0.5%
——0——CVE-2018-9372—0.5%
——0——CVE-2025-21470—0.5%
——0——CVE-2026-533235.5 MED0.5%
——0In the Linux kernel, the following vulnerability has been resolved:
net: dsa: remove redundant netdev_lock_ops() from conduit ethtool ops
DSA replaces the conduit (master) device's ethtool_ops with its own
wrappers that aggregate stats from both the conduit and DSA switch
ports. Taking the lock again inside the DSA wrappers causes a deadlock.
Stumbled upon this when booting qemu with fbnic and CONFIG_NET_DSA_LOOP=y
(which looks like some kind of testing device that auto-populates the ports
of eth0). `ethtool -i` is enough to deadlock. This means we have basically zero
coverage for DSA stuff with real ops locked devs.
Remove the redundant netdev_lock_ops()/netdev_unlock_ops() calls from
the DSA conduit ethtool wrappers.56dCVE-2023-21015—0.5%
——0——CVE-2026-0115—0.5%
——0——CVE-2026-207726.7 MED0.5%
——0Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.193 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.41dCVE-2024-45838—0.5%
——0——CVE-2023-20680—0.5%
——0——CVE-2025-30508—0.5%
——0——CVE-2025-54634—0.5%
——0——CVE-2025-21469—0.5%
——0——CVE-2026-23199—0.5%
——0——CVE-2024-27226—0.5%
——0——CVE-2026-23400—0.5%
——0——CVE-2023-21128—0.5%
——0——CVE-2022-20016—0.5%
——0——CVE-2024-42385—0.5%
——0——CVE-2023-21033—0.5%
——0——CVE-2026-735846.3 MED0.5%
——0A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to an arbitrary file. This can lead to privileged file corruption or a denial of service (DoS) on the system.6dCVE-2022-20611—0.5%
——0——CVE-2025-53185—0.5%
——0——CVE-2022-48247—0.5%
——0——CVE-2024-49842—0.5%
——0——CVE-2024-53841—0.5%
——0——CVE-2023-21374—0.5%
——0——CVE-2024-27231—0.5%
——0——CVE-2024-32908—0.5%
——0——CVE-2026-25602—0.5%
——0——CVE-2024-32906—0.5%
——0——CVE-2023-21016—0.5%
——0——CVE-2022-48369—0.5%
——0——CVE-2026-28711—0.5%
——0——CVE-2025-22427—0.5%
——0——CVE-2022-44419—0.5%
——0——CVE-2026-494217.1 ALT0.5%
——0The kernel function that implements unlinkat(2) and funlinkat(2) validated the AT_RESOLVE_BENEATH flag but failed to pass it through to the underlying path lookup. The flag was silently dropped, so path resolution was not actually restricted.
A process that uses AT_RESOLVE_BENEATH with unlinkat(2) or funlinkat(2) to confine path resolution can in fact resolve paths above the starting directory. A caller relying on this flag for path containment may delete files outside the intended directory tree.5dCVE-2026-467347.3 ALT0.5%
——0Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass.52dCVE-2023-21004—0.5%
——0——CVE-2026-28712—0.5%
——0——