Vulnerabilities exploitable today
372,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,274
- High8,391
- Medium6,468
- Low636
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-0314—23.4%
——7——CVE-2017-17176—23.4%
——7——CVE-2026-198344.7 MED23.4%
——7A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/customers/login-as-customer/ of the component Admin Customer Impersonation Feature. This manipulation of the argument ID causes authorization bypass. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."25dCVE-2023-45004—23.4%
——7——CVE-2025-43752—23.4%
——7——CVE-2026-81818—23.4%
——7Affected versions of Flowintel contain an authorization flaw in the administrative user-edit API.
The existing authorization check correctly prevented an organization administrator from editing users in another organization, but it did not prevent them from editing a full administrator within their own organization. As a result, an org admin could modify that full administrator account, including changing its password. The upstream commit explicitly describes the issue as:
“Org admin can change the password of a full admin in the same organization.”
The fix adds a higher-privilege boundary check:
if user_to_edit.is_admin(): return ... 403
so organization administrators can no longer modify full administrator accounts.
Version impacted >=3.3.014dCVE-2025-30954—23.4%
——7——CVE-2026-45339—23.4%
——7——CVE-2025-49325—23.4%
——7——CVE-2024-12062—23.4%
——7——CVE-2019-4140—23.4%
——7——CVE-2018-4046—23.4%
——7——CVE-2025-9708—23.4%
——7——CVE-2018-4033—23.4%
——7——CVE-2001-0378—23.4%
——7——CVE-2026-302506.1 MED23.4%
——7Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90 allows a remote attacker to execute arbitrary code2dCVE-2024-33764—23.4%
——7——CVE-2026-168488.8 HIG23.4%
——7IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of shell metacharacters in DHCP options.18dCVE-2026-163809.1 CRI23.4%
——7Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.49dCVE-2015-6369—23.4%
——7——CVE-2023-37225—23.4%
——7——CVE-2018-4034—23.4%
——7——CVE-2024-2726—23.4%
——7——CVE-2023-1544—23.4%
——7——CVE-2024-28028—23.4%
——7——CVE-2021-38119—23.4%
——7——CVE-2024-0317—23.4%
——7——CVE-2020-8352—23.4%
——7——CVE-2025-53675—23.4%
——7——CVE-2024-0318—23.4%
——7——CVE-2022-40291—23.4%
——7——CVE-2018-6265—23.4%
——7——CVE-2024-25854—23.4%
——7——CVE-2007-0668—23.4%
——7——CVE-2024-30380—23.4%
——7——CVE-2024-2445—23.4%
——7——CVE-2026-792694.3 MED23.4%
——7Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)11dCVE-2018-4047—23.4%
——7——CVE-2024-21727—23.4%
——7——CVE-2018-4041—23.4%
——7——