Vulnerabilities exploitable today
356,426in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,661
New KEV · 24H0
Exploit Today ≥ 701,603
Distribution · last window
- Critical2,802
- High11,189
- Medium7,403
- Low703
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-0208—7.6%
——2——CVE-2026-536244.8 MED7.6%
——2Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/helmet.go never sets the Strict-Transport-Security response header even when HSTSMaxAge is configured because it checks c.Protocol() for https instead of c.Scheme(). This issue is fixed in version 3.4.0.23dCVE-2021-47038—7.6%
——2——CVE-2025-32555—7.6%
——2——CVE-2023-52785—7.6%
——2——CVE-2023-5643—7.6%
——2——CVE-2025-32575—7.6%
——2——CVE-2026-44561—7.6%
——2——CVE-2025-48507—7.6%
——2——CVE-2025-30560—7.6%
——2——CVE-2023-5973—7.6%
——2——CVE-2025-32623—7.6%
——2——CVE-2025-32498—7.6%
——2——CVE-2026-20668—7.6%
——2——CVE-2026-577605.3 MED7.6%
——2Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Sendcloud Shipping: from n/a through 1.0.29.36dCVE-2025-39530—7.6%
——2——CVE-2026-42872—7.6%
——2——CVE-2025-32559—7.6%
——2——CVE-2026-31869—7.6%
——2——CVE-2025-32597—7.6%
——2——CVE-2025-22119—7.6%
——2——CVE-2025-30561—7.6%
——2——CVE-2018-11960—7.6%
——2——CVE-2022-48675—7.6%
——2——CVE-2025-66496—7.6%
——2——CVE-2025-32610—7.6%
——2——CVE-2025-32501—7.6%
——2——CVE-2025-32500—7.6%
——2——CVE-2025-12124—7.6%
——2——CVE-2026-0747—7.6%
——2——CVE-2026-20004—7.6%
——2——CVE-2026-1438—7.6%
——2——CVE-2024-269607.0 HIG7.6%
——2In the Linux kernel, the following vulnerability has been resolved:
mm: swap: fix race between free_swap_and_cache() and swapoff()
There was previously a theoretical window where swapoff() could run and
teardown a swap_info_struct while a call to free_swap_and_cache() was
running in another thread. This could cause, amongst other bad
possibilities, swap_page_trans_huge_swapped() (called by
free_swap_and_cache()) to access the freed memory for swap_map.
This is a theoretical problem and I haven't been able to provoke it from a
test case. But there has been agreement based on code review that this is
possible (see link below).
Fix it by using get_swap_device()/put_swap_device(), which will stall
swapoff(). There was an extra check in _swap_info_get() to confirm that
the swap entry was not free. This isn't present in get_swap_device()
because it doesn't make sense in general due to the race between getting
the reference and swapoff. So I've added an equivalent check directly in
free_swap_and_cache().
Details of how to provoke one possible issue (thanks to David Hildenbrand
for deriving this):
--8<-----
__swap_entry_free() might be the last user and result in
"count == SWAP_HAS_CACHE".
swapoff->try_to_unuse() will stop as soon as soon as si->inuse_pages==0.
So the question is: could someone reclaim the folio and turn
si->inuse_pages==0, before we completed swap_page_trans_huge_swapped().
Imagine the following: 2 MiB folio in the swapcache. Only 2 subpages are
still references by swap entries.
Process 1 still references subpage 0 via swap entry.
Process 2 still references subpage 1 via swap entry.
Process 1 quits. Calls free_swap_and_cache().
-> count == SWAP_HAS_CACHE
[then, preempted in the hypervisor etc.]
Process 2 quits. Calls free_swap_and_cache().
-> count == SWAP_HAS_CACHE
Process 2 goes ahead, passes swap_page_trans_huge_swapped(), and calls
__try_to_reclaim_swap().
__try_to_reclaim_swap()->folio_free_swap()->delete_from_swap_cache()->
put_swap_folio()->free_swap_slot()->swapcache_free_entries()->
swap_entry_free()->swap_range_free()->
...
WRITE_ONCE(si->inuse_pages, si->inuse_pages - nr_entries);
What stops swapoff to succeed after process 2 reclaimed the swap cache
but before process1 finished its call to swap_page_trans_huge_swapped()?
--8<-----3dCVE-2025-32584—7.6%
——2——CVE-2026-577215.3 MED7.6%
——2Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects ApplyOnline: from n/a through 2.6.7.6.37dCVE-2025-32556—7.6%
——2——CVE-2023-49113—7.6%
——2——CVE-2024-58077—7.6%
——2——CVE-2026-330997.0 HIG7.6%
——2Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.13dCVE-2025-30769—7.6%
——2——