Vulnerabilities exploitable today
363,765in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,673
New KEV · 24H0
Exploit Today ≥ 701,611
Distribution · last window
- Critical2,923
- High12,261
- Medium7,478
- Low679
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-48378—0.4%
——0——CVE-2023-21309—0.4%
——0——CVE-2026-6842—0.4%
——0——CVE-2025-36898—0.4%
——0——CVE-2023-32819—0.4%
——0——CVE-2024-27218—0.4%
——0——CVE-2025-36905—0.4%
——0——CVE-2025-32326—0.4%
——0——CVE-2023-30941—0.4%
——0——CVE-2018-9403—0.4%
——0——CVE-2023-33907—0.4%
——0——CVE-2026-2638—0.4%
——0A vulnerability in the quarantine and restore workflow of the X-VPN macOS website versions 77.0 through 77.5 allow a local attacker to leverage a race condition and symlink manipulation to achieve privileged file corruption.29dCVE-2023-30938—0.4%
——0——CVE-2023-33906—0.4%
——0——CVE-2023-21364—0.4%
——0——CVE-2024-43764—0.4%
——0——CVE-2023-30921—0.4%
——0——CVE-2021-0533—0.4%
——0——CVE-2023-40112—0.4%
——0——CVE-2023-32834—0.4%
——0——CVE-2023-32836—0.4%
——0——CVE-2026-106816.5 MED0.4%
——0In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thread permission index from the global _thread_idx_map[] bitmap without holding lists_lock.
On SMP systems, two user-mode threads invoking the k_object_alloc(K_OBJ_THREAD) syscall concurrently can both observe the same low free bit, perform the same non-atomic RMW to clear it, and return the identical tidx.
The two newly created K_OBJ_THREAD objects are then assigned the same thread_id, so the two user threads alias a single bit position in every kernel object's perms[] bitfield: any subsequent grant of access on a kernel object to one thread is implicitly a grant to the other, defeating userspace ACL isolation. A secondary lost-update window between the unlocked &=~BIT() in alloc and the locked |= BIT() in thread_idx_free() can also leak entries from the thread-index pool.
The defect is reachable from any user-mode thread via the unrestricted __syscall k_object_alloc and is gated on CONFIG_USERSPACE, CONFIG_DYNAMIC_OBJECTS, and CONFIG_SMP. The flaw was introduced when the per-thread permission index was added in 2018 and is present in every release up to and including v4.4.0. Fixed by holding lists_lock across the bitmap RMW and the permissions clear (and inlining the obj_list traversal that previously took the lock itself).9dCVE-2023-32788—0.4%
——0——CVE-2023-30865—0.4%
——0——CVE-2023-30930—0.4%
——0——CVE-2026-64158—0.4%
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.2dCVE-2023-21143—0.4%
——0——CVE-2023-33912—0.4%
——0——CVE-2024-56191—0.4%
——0——CVE-2023-33881—0.4%
——0——CVE-2026-33697—0.4%
——0——CVE-2017-13227—0.4%
——0——CVE-2023-32824—0.4%
——0——CVE-2025-66329—0.4%
——0——CVE-2022-30727—0.4%
——0——CVE-2023-30923—0.4%
——0——CVE-2023-30937—0.4%
——0——CVE-2023-33908—0.4%
——0——CVE-2023-33909—0.4%
——0——CVE-2018-9378—0.4%
——0——