Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,329
- High8,527
- Medium6,840
- Low772
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2018-6630—32.7%
——10——CVE-2018-8990—32.7%
——10——CVE-2018-6208—32.7%
——10——CVE-2018-6781—32.7%
——10——CVE-2018-9047—32.7%
——10——CVE-2018-6774—32.7%
——10——CVE-2025-3669—32.7%
——10——CVE-2018-5220—32.7%
——10——CVE-2018-6783—32.7%
——10——CVE-2018-8988—32.7%
——10——CVE-2018-8997—32.7%
——10——CVE-2025-54878—32.7%
——10——CVE-2026-25790—32.7%
——10——CVE-2018-9051—32.7%
——10——CVE-2018-8999—32.7%
——10——CVE-2018-6778—32.7%
——10——CVE-2018-10647—32.7%
——10——CVE-2018-8874—32.7%
——10——CVE-2018-5080—32.7%
——10——CVE-2018-5217—32.7%
——10——CVE-2018-6625—32.7%
——10——CVE-2018-8894—32.7%
——10——CVE-2018-6780—32.7%
——10——CVE-2023-50713—32.7%
——10——CVE-2018-5086—32.7%
——10——CVE-2018-6782—32.7%
——10——CVE-2018-9048—32.7%
——10——CVE-2018-6788—32.7%
——10——CVE-2025-7966—32.7%
——10——CVE-2018-9046—32.7%
——10——CVE-2018-9043—32.7%
——10——CVE-2018-9052—32.7%
——10——CVE-2026-480146.5 MED32.7%
——10Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the order state transition features /api/_action/order/{orderId}/state/{transition} and similar transaction and delivery transition routes in src/Core/Checkout/Order/Api/OrderActionController.php do not declare PlatformRequest::ATTRIBUTE_ACL or perform an explicit privilege check, so AclAnnotationValidator exits when route ACL metadata is absent and low-privileged users without order:update, order_transaction:update, or order_delivery:update can trigger StateMachineRegistry::transition() writes in SYSTEM_SCOPE. This issue is fixed in versions 6.6.10.18 and 6.7.10.1.63dCVE-2018-9044—32.7%
——10——CVE-2018-6770—32.7%
——10——CVE-2018-6777—32.7%
——10——CVE-2026-171819.3 CRI32.7%
——10IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.33dCVE-2023-47229—32.7%
——10——CVE-2018-6209—32.7%
——10——CVE-2023-6811—32.7%
——10——