Vulnerabilities exploitable today
369,447in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,638
Distribution · last window
- Critical2,103
- High7,551
- Medium5,627
- Low543
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-175824.9 MED21.0%
——6The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including, 9.1.7 via the qcld_sliderhero_duplicate() function. Slide data (description, title, btn, btn2, image_link, custom, etc.) is stored safely via $wpdb->update() with %s placeholders in the qchero_save_image AJAX handler, but when an administrator triggers the 'heroduplicateslider' task, qcld_sliderhero_duplicate() re-reads every slide column and concatenates the raw values directly into an INSERT VALUES tuple that is then executed with $wpdb->query() — with no $wpdb->prepare(), esc_sql(), or _real_escape_string in between. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.18dCVE-2026-255656.5 MED21.0%
——6WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read access rather than requiring write permission. This can allow users with read-only roles to perform card updates that should require write access.55dCVE-2024-20771—21.0%
——6——CVE-2025-60086—21.0%
——6——CVE-2019-13142—21.0%
——6——CVE-2024-12813—21.0%
——6——CVE-2025-36006—21.0%
——6——CVE-2025-63744—21.0%
——6——CVE-2025-144814.3 MED21.0%
——6The Yoast SEO plugin for WordPress is vulnerable to Insecure Direct Object References in all versions up to, and including, 26.5. This is due to insufficient authorization checks in the Meta Search REST API endpoint that fail to verify post ownership. This makes it possible for authenticated attackers, with Contributor-level access and above, to read sensitive SEO metadata from any post on the site via the 'post_id' parameter, including posts owned by other users, private posts, and draft posts.45dCVE-2025-59018—21.0%
——6——CVE-2026-607747.1 HIG21.0%
——6Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean [Incl. Advanced]). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data as well as unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).39dCVE-2026-353996.1 MED21.0%
——6WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, a stored XSS vulnerability allows an attacker to inject malicious scripts through a backup filename. This could lead to unauthorized execution of malicious code in the victim's browser, compromising session data or executing actions on behalf of the user. This vulnerability is fixed in 3.6.9.45dCVE-2023-49790—21.0%
——6——CVE-2021-47738—21.0%
——6——CVE-2026-33331—21.0%
——6——CVE-2026-141698.1 HIG21.0%
——6Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could result in complete administrative unavailability of the device.39dCVE-2022-35861—21.0%
——6——CVE-2026-82731—21.0%
——6URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allows an attacker who controls a path-parameter value to redirect a generated client's request, and the credentials attached to it, to an unintended route or an external origin.
The URL builders in lib/ash_typescript/typed_controller/codegen/route_renderer.ex replace each :param placeholder with a bare template interpolation and never call encodeURIComponent, so the value reaches executeTypedControllerRequest raw. A value containing ../ is normalised away by the fetch URL resolver and reaches a different route, while ? or # truncates the path and can smuggle or override query parameters. For a route whose path begins with a parameter, a value such as /evil.example.com/x yields the protocol-relative URL //evil.example.com/x, sending the request and the credentials from TypedControllerConfig to an attacker-controlled host. Nothing constrains the value at runtime: get_path_param_type/2 emits only a TypeScript type, which is erased.
The query-string path is unaffected, since URLSearchParams.set encodes its own values.
This issue affects ash_typescript: from 0.15.0 before 0.18.0.6dCVE-2026-706795.3 MED21.0%
——6Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).13dCVE-2026-29044—21.0%
——6——CVE-2026-657775.3 MED21.0%
——6Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.24dCVE-2024-46994—21.0%
——6——CVE-2025-31436—21.0%
——6——CVE-2026-322204.4 MED21.0%
——6Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.44dCVE-2023-45586—21.0%
——6——CVE-2026-33782—21.0%
——6——CVE-2020-18780—21.0%
——6——CVE-2024-13465—21.0%
——6——CVE-2025-30199—21.0%
——6——CVE-2023-31972—21.0%
——6——CVE-2025-58835—21.0%
——6——CVE-2026-26960—21.0%
——6——CVE-2026-139715.3 MED21.0%
——6Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)68dCVE-2025-2860—21.0%
——6——CVE-2023-2067—21.0%
——6——CVE-2025-71002—21.0%
——6——CVE-2019-13689—21.0%
——6——CVE-2020-3915—21.0%
——6——CVE-2025-40899—21.0%
——6——CVE-2025-31442—21.0%
——6——