| CVE-2026-46773 | 9.8 | 41.7 | Oracle Corporation | Oracle Unified Directory | CWE-284 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-46774 | 9.8 | 41.7 | Oracle Corporation | Oracle Unified Directory | CWE-284 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-46857 | 9.8 | 41.0 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-46859 | 9.8 | 41.0 | Oracle Corporation | Oracle Agile PLM | CWE-287 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-8442 | 8.1 | 40.6 | https://wpreviewslider.com/ | WP Review Slider Pro | CWE-22 | WP Review Slider Pro <= 12.6.8 - Authenticated (Subscriber+) Arbitrary File D… |
| CVE-2026-35270 | 9.1 | 40.3 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-12292 | 8.1 | 40.2 | Mozilla | Firefox | CWE-119 | Incorrect boundary conditions in the Web Audio component |
| CVE-2026-35292 | 10.0 | 39.6 | Oracle Corporation | WebLogic Server | CWE-306 | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com… |
| CVE-2026-35301 | 10.0 | 39.6 | Oracle Corporation | WebLogic Server | CWE-306 | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com… |
| CVE-2026-46798 | 10.0 | 39.6 | Oracle Corporation | Oracle WebCenter Sites | CWE-306 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-46800 | 10.0 | 39.6 | Oracle Corporation | Oracle WebCenter Sites | CWE-306 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-35286 | 9.8 | 39.5 | Oracle Corporation | Oracle WebCenter Content | CWE-306 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-35293 | 9.8 | 39.5 | Oracle Corporation | Oracle WebCenter Sites | CWE-306 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-35296 | 9.8 | 39.5 | Oracle Corporation | Oracle WebCenter Sites | CWE-306 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-35310 | 9.8 | 39.5 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-35319 | 9.8 | 39.5 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-46783 | 9.8 | 39.5 | Oracle Corporation | WebCenter Content: Imaging | CWE-306 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd… |
| CVE-2026-46797 | 9.8 | 39.5 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-46801 | 9.8 | 39.5 | Oracle Corporation | Oracle WebCenter Sites | CWE-306 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-46878 | 9.8 | 39.5 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-46879 | 9.8 | 39.5 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-306 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-46880 | 9.8 | 39.5 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-46890 | 9.8 | 39.6 | Oracle Corporation | Siebel Apps - Marketing | CWE-284 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co… |
| CVE-2026-46905 | 9.8 | 39.5 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-306 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-46909 | 9.8 | 39.5 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-46853 | 9.6 | 39.5 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-79 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-35280 | 9.9 | 39.5 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-35281 | 9.9 | 39.5 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-12225 | 8.7 | 39.4 | syracom AG | Secure Login (2FA) for Jira | CWE-288 | syracom Secure Login (2FA) for Confluence allows 2FA bypass via spoofed User-… |
| CVE-2026-12328 | 8.1 | 39.1 | Mozilla | Firefox | CWE-120 | Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbi… |
| CVE-2026-35307 | 10.0 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-35308 | 10.0 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-46803 | 10.0 | 38.9 | Oracle Corporation | Oracle WebCenter Portal | CWE-306 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-35304 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-46845 | 9.8 | 38.9 | Oracle Corporation | Oracle WebCenter Portal | CWE-306 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-46884 | 9.8 | 38.9 | Oracle Corporation | Siebel Apps - Marketing | CWE-284 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co… |
| CVE-2026-46887 | 9.8 | 38.9 | Oracle Corporation | Siebel Apps - Marketing | CWE-284 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co… |
| CVE-2026-46889 | 9.8 | 38.9 | Oracle Corporation | Siebel Apps - Marketing | CWE-284 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co… |
| CVE-2025-69177 | 8.1 | 39.0 | THEMELOGI | Roneous | CWE-98 | WordPress Roneous theme <= 2.1.5 - Local File Inclusion vulnerability |
| CVE-2026-46778 | 10.0 | 38.9 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-306 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-46781 | 10.0 | 38.9 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-306 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-35309 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-46766 | 9.8 | 38.9 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-46799 | 9.8 | 38.9 | Oracle Corporation | Oracle WebCenter Sites | CWE-306 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-46813 | 9.8 | 38.9 | Oracle Corporation | Oracle WebCenter Content | CWE-306 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-46860 | 9.8 | 38.9 | Oracle Corporation | MySQL Router | CWE-284 | Vulnerability in the MySQL Router product of Oracle MySQL (component: Router:… |
| CVE-2026-46881 | 9.8 | 38.9 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-46882 | 9.8 | 38.9 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-46883 | 9.8 | 38.9 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-46902 | 9.8 | 38.9 | Oracle Corporation | Oracle Enterprise Command Center Framework | CWE-284 | Vulnerability in the Oracle Enterprise Command Center Framework product of Or… |
| CVE-2026-46904 | 9.8 | 38.9 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-46856 | 9.6 | 38.9 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-79 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-10829 | 8.6 | 38.8 | Moxa | NPort W2150A-W4/W2250A-W4 Series | CWE-121 | A stack-based buffer overflow vulnerability has been found in the NPort W2150… |
| CVE-2026-8176 | 7.5 | 38.8 | latepoint | LatePoint – Calendar Booking Plugin for Appointments and Events | CWE-269 | LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administr… |
| CVE-2026-46863 | 7.5 | 38.7 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-12256 | 8.8 | 38.6 | ThemeFusion | Avada | CWE-502 | WordPress Avada theme <= 3.15.3 - PHP Object Injection vulnerability |
| CVE-2025-69131 | 7.5 | 38.5 | extendons | WordPress & WooCommerce Scraper Plugin, Import Data from Any Site | CWE-22 | WordPress WordPress & WooCommerce Scraper Plugin, Import Data from Any Site p… |
| CVE-2026-35298 | 9.1 | 38.2 | Oracle Corporation | WebLogic Server | CWE-284 | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com… |
| CVE-2026-46862 | 7.5 | 38.2 | Oracle Corporation | MySQL Router | CWE-400 | Vulnerability in the MySQL Router product of Oracle MySQL (component: Router:… |
| CVE-2026-46875 | 9.1 | 38.2 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-46896 | 9.1 | 38.2 | Oracle Corporation | Oracle Enterprise Command Center Framework | CWE-284 | Vulnerability in the Oracle Enterprise Command Center Framework product of Or… |
| CVE-2026-46945 | 9.1 | 38.2 | Oracle Corporation | Oracle iSupport | CWE-284 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (comp… |
| CVE-2026-46946 | 9.1 | 38.2 | Oracle Corporation | Oracle iSupport | CWE-284 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (comp… |
| CVE-2026-46851 | 8.1 | 38.0 | Oracle Corporation | PeopleSoft Enterprise CS Campus Community | CWE-94 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Ora… |
| CVE-2026-46944 | 9.1 | 37.6 | Oracle Corporation | Oracle iSupport | CWE-284 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (comp… |
| CVE-2026-35326 | 7.2 | 37.6 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-46769 | 7.2 | 37.6 | Oracle Corporation | Oracle Application Development Framework (ADF) | CWE-284 | Vulnerability in the Oracle Application Development Framework (ADF) product o… |
| CVE-2026-46867 | 7.2 | 37.6 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-269 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-46868 | 7.2 | 37.6 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-46922 | 7.2 | 37.6 | Oracle Corporation | Oracle HR Intelligence | CWE-269 | Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suit… |
| CVE-2026-46938 | 7.2 | 37.6 | Oracle Corporation | Oracle Cost Management | CWE-284 | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suit… |
| CVE-2026-46956 | 7.2 | 37.6 | Oracle Corporation | Oracle Property Manager | CWE-284 | Vulnerability in the Oracle Property Manager product of Oracle E-Business Sui… |
| CVE-2026-46960 | 7.2 | 37.6 | Oracle Corporation | Oracle Project Portfolio Analysis | CWE-284 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Bu… |
| CVE-2026-46969 | 7.2 | 37.6 | Oracle Corporation | Oracle Financials for EMEA | CWE-284 | Vulnerability in the Oracle Financials for EMEA product of Oracle E-Business … |
| CVE-2026-46970 | 7.2 | 37.6 | Oracle Corporation | Oracle HR Intelligence | CWE-269 | Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suit… |
| CVE-2024-24909 | 8.8 | 37.2 | Dell | OpenManage | CWE-77 | Dell OpenManage Integration with Microsoft Windows Admin Center contains a Re… |
| CVE-2026-46858 | 9.1 | 37.1 | Oracle Corporation | APM - Application Performance Management | CWE-284 | Vulnerability in the APM - Application Performance Management product of Orac… |
| CVE-2026-48777 | 9.3 | 37.1 | gtsteffaniak | filebrowser | CWE-22 | FileBrowser Quantum: Path Traversal in public share PATCH allows file ops out… |
| CVE-2026-46855 | 9.9 | 36.7 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-35265 | 8.8 | 36.7 | Oracle Corporation | Identity Manager | CWE-306 | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (co… |
| CVE-2026-35267 | 8.8 | 36.7 | Oracle Corporation | Identity Manager | CWE-306 | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (co… |
| CVE-2026-0647 | 8.8 | 36.2 | Rockwell Automation | FLEX I/O EtherNet/IP Adapters | CWE-306 | Rockwell Automation FLEX I/O Dual-port EtherNet/IP Adapters – Multiple Vulner… |
| CVE-2025-58924 | 8.1 | 36.3 | ThemeREX Group | Geya | CWE-98 | WordPress Geya theme <= 1.15 - Local File Inclusion vulnerability |
| CVE-2025-69105 | 8.1 | 36.3 | ThemeREX | Modernee | CWE-98 | WordPress Modernee theme <= 1.6.0 - Local File Inclusion vulnerability |
| CVE-2025-69107 | 8.1 | 36.3 | ThemeREX | Rosaleen | CWE-98 | WordPress Rosaleen theme <= 2.8 - Local File Inclusion vulnerability |
| CVE-2025-69109 | 8.1 | 36.3 | ThemeREX | Raider Spirit | CWE-98 | WordPress Raider Spirit theme <= 1.1.2 - Local File Inclusion vulnerability |
| CVE-2025-69112 | 8.1 | 36.3 | ThemeREX | Planty | CWE-98 | WordPress Planty theme <= 1.14.0 - Local File Inclusion vulnerability |
| CVE-2025-69113 | 8.1 | 36.3 | ThemeREX | Nexio | CWE-98 | WordPress Nexio theme <= 1.10.0 - Local File Inclusion vulnerability |
| CVE-2025-69114 | 8.1 | 36.3 | ThemeREX | MaxiNet | CWE-98 | WordPress MaxiNet theme <= 1.2.10 - Local File Inclusion vulnerability |
| CVE-2025-69116 | 8.1 | 36.3 | ThemeREX | Iona | CWE-98 | WordPress Iona theme <= 1.0.8 - Local File Inclusion vulnerability |
| CVE-2025-69119 | 8.1 | 36.3 | ThemeREX | Corbesier | CWE-98 | WordPress Corbesier theme <= 1.15.0 - Local File Inclusion vulnerability |
| CVE-2025-69121 | 8.1 | 36.3 | ThemeREX | Deliciosa | CWE-98 | WordPress Deliciosa theme <= 1.10.0 - Local File Inclusion vulnerability |
| CVE-2025-69124 | 8.1 | 36.3 | ThemeREX | Especio | CWE-98 | WordPress Especio theme <= 1.0 - Local File Inclusion vulnerability |
| CVE-2025-69136 | 8.1 | 36.2 | THEMELOGI | Wanium | CWE-98 | WordPress Wanium theme <= 1.9.8 - Local File Inclusion vulnerability |
| CVE-2025-69142 | 8.1 | 36.3 | ThemeREX | Abelle | CWE-98 | WordPress Abelle theme <= 1.22 - Local File Inclusion vulnerability |
| CVE-2025-69143 | 8.1 | 36.3 | ThemeREX | Mission | CWE-98 | WordPress Mission theme <= 1.22 - Local File Inclusion vulnerability |
| CVE-2025-69147 | 8.1 | 36.3 | ThemeREX | Putter | CWE-98 | WordPress Putter theme <= 1.17 - Local File Inclusion vulnerability |
| CVE-2025-69149 | 8.1 | 36.3 | ThemeREX | Top Dog | CWE-98 | WordPress Top Dog theme <= 1.0.5 - Local File Inclusion vulnerability |
| CVE-2025-69150 | 8.1 | 36.3 | ThemeREX | Medeus | CWE-98 | WordPress Medeus theme <= 1.14 - Local File Inclusion vulnerability |
| CVE-2025-69159 | 8.1 | 36.3 | ThemeREX | Printo | CWE-98 | WordPress Printo theme <= 1.11 - Local File Inclusion vulnerability |
| CVE-2025-69160 | 8.1 | 36.3 | ThemeREX | Gita | CWE-98 | WordPress Gita theme <= 1.11 - Local File Inclusion vulnerability |
| CVE-2025-69162 | 8.1 | 36.3 | ThemeREX | Grecko | CWE-98 | WordPress Grecko theme <= 5.17 - Local File Inclusion vulnerability |
| CVE-2025-69163 | 8.1 | 36.2 | ThemeREX | WineShop | CWE-98 | WordPress WineShop theme <= 3.17 - Local File Inclusion vulnerability |
| CVE-2025-69165 | 8.1 | 36.3 | ThemeREX | Choreo | CWE-98 | WordPress Choreo theme <= 1.6 - Local File Inclusion vulnerability |
| CVE-2025-69167 | 8.1 | 36.3 | ThemeREX | Eros | CWE-98 | WordPress Eros theme <= 1.3 - Local File Inclusion vulnerability |
| CVE-2025-69168 | 8.1 | 36.2 | ThemeREX | Spike | CWE-98 | WordPress Spike theme <= 1.2 - Local File Inclusion vulnerability |
| CVE-2025-69178 | 8.1 | 36.3 | CactusThemes | Truemag | CWE-98 | WordPress Truemag theme <= 4.3.14.2 - Local File Inclusion vulnerability |
| CVE-2026-46777 | 9.1 | 36.2 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-46794 | 9.9 | 36.0 | Oracle Corporation | Identity Manager Connector | CWE-269 | Vulnerability in the Identity Manager Connector product of Oracle Fusion Midd… |
| CVE-2026-46864 | 8.8 | 36.0 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-25470 | 10.0 | 35.7 | ACPT | ACPT (Pro) - Custom Post Types Plugin for WordPress | CWE-94 | WordPress ACPT (Pro) - Custom Post Types plugin for WordPress plugin <= 2.0.4… |
| CVE-2026-46784 | 9.1 | 35.5 | Oracle Corporation | WebCenter Content: Imaging | CWE-284 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd… |
| CVE-2025-60085 | 8.1 | 35.3 | ThemeREX Group | Learnify | CWE-98 | WordPress Learnify theme <= 1.15.0 - Local File Inclusion vulnerability |
| CVE-2026-34894 | 8.1 | 35.3 | WebGeniusLab | Integrio Core | CWE-98 | WordPress Integrio Core plugin < 1.2.8 - Local File Inclusion vulnerability |
| CVE-2026-39522 | 8.1 | 35.3 | Elated-Themes | Solene | CWE-98 | WordPress Solene theme <= 3.4 - Local File Inclusion vulnerability |
| CVE-2026-39549 | 8.1 | 35.3 | Elated-Themes | Aperitif | CWE-98 | WordPress Aperitif theme <= 1.5 - Local File Inclusion vulnerability |
| CVE-2026-39568 | 8.1 | 35.3 | Elated-Themes | Mr. SEO | CWE-98 | WordPress Mr. SEO theme <= 2.0 - Local File Inclusion vulnerability |
| CVE-2026-46789 | 9.6 | 34.7 | Oracle Corporation | Oracle WebCenter Content | CWE-306 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-35276 | 8.1 | 34.7 | Oracle Corporation | PeopleSoft Enterprise PT PeopleTools | CWE-306 | Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle P… |
| CVE-2026-46791 | 7.5 | 34.5 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-35283 | 9.9 | 34.2 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-35284 | 9.9 | 34.2 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-35285 | 9.9 | 34.2 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-35294 | 9.9 | 34.2 | Oracle Corporation | Identity Manager Connector | CWE-284 | Vulnerability in the Identity Manager Connector product of Oracle Fusion Midd… |
| CVE-2026-35313 | 9.9 | 34.2 | Oracle Corporation | Oracle Access Manager | CWE-284 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-35316 | 9.9 | 34.2 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-35321 | 9.9 | 34.2 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-35323 | 9.9 | 34.2 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-46832 | 9.9 | 34.3 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-46838 | 9.9 | 34.2 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-46847 | 9.9 | 34.2 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-46854 | 9.9 | 34.3 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-46895 | 9.9 | 34.3 | Oracle Corporation | Oracle Enterprise Command Center Framework | CWE-269 | Vulnerability in the Oracle Enterprise Command Center Framework product of Or… |
| CVE-2026-46907 | 9.9 | 34.2 | Oracle Corporation | JD Edwards EnterpriseOne Order Promising | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Order Promising product of Orac… |
| CVE-2026-46908 | 9.9 | 34.2 | Oracle Corporation | JD Edwards EnterpriseOne Accounts Payable | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product of Ora… |
| CVE-2026-46918 | 9.9 | 34.2 | Oracle Corporation | Oracle Process Manufacturing Product Development | CWE-284 | Vulnerability in the Oracle Process Manufacturing Product Development product… |
| CVE-2026-46933 | 9.9 | 34.2 | Oracle Corporation | Oracle Applications Manager | CWE-269 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business… |
| CVE-2026-35299 | 8.8 | 34.3 | Oracle Corporation | WebLogic Server | CWE-306 | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com… |
| CVE-2026-35303 | 8.8 | 34.3 | Oracle Corporation | WebLogic Server | CWE-306 | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com… |
| CVE-2026-35315 | 8.8 | 34.2 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-35317 | 8.8 | 34.2 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-35322 | 8.8 | 34.2 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-35325 | 8.8 | 34.2 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-46886 | 8.8 | 34.3 | Oracle Corporation | Siebel Apps - Marketing | CWE-284 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co… |
| CVE-2026-46929 | 8.8 | 34.2 | Oracle Corporation | Oracle Cost Management | CWE-269 | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suit… |
| CVE-2026-46931 | 8.8 | 34.2 | Oracle Corporation | Oracle Enterprise Asset Management | CWE-284 | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-B… |
| CVE-2026-46937 | 8.8 | 34.2 | Oracle Corporation | Oracle iSetup | CWE-269 | Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (compon… |
| CVE-2026-46940 | 8.8 | 34.2 | Oracle Corporation | Oracle Cost Management | CWE-269 | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suit… |
| CVE-2026-46942 | 8.8 | 34.2 | Oracle Corporation | Oracle Process Manufacturing Process Planning | CWE-269 | Vulnerability in the Oracle Process Manufacturing Process Planning product of… |
| CVE-2026-46947 | 8.8 | 34.2 | Oracle Corporation | Oracle Advanced Outbound Telephony | CWE-284 | Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-B… |
| CVE-2026-46950 | 8.8 | 34.2 | Oracle Corporation | Oracle Advanced Outbound Telephony | CWE-284 | Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-B… |
| CVE-2026-46951 | 8.8 | 34.2 | Oracle Corporation | Oracle Quality | CWE-269 | Vulnerability in the Oracle Quality product of Oracle E-Business Suite (compo… |
| CVE-2026-46961 | 8.8 | 34.2 | Oracle Corporation | Oracle Project Portfolio Analysis | CWE-269 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Bu… |
| CVE-2026-46965 | 8.8 | 34.2 | Oracle Corporation | Oracle Universal Work Queue | CWE-284 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business… |
| CVE-2026-46973 | 8.8 | 34.2 | Oracle Corporation | Oracle Outsourced Mfg for Discrete Industries | CWE-269 | Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of… |
| CVE-2026-12327 | 8.1 | 33.9 | Mozilla | Firefox | CWE-119 | Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firef… |
| CVE-2026-35289 | 8.1 | 33.9 | Oracle Corporation | PeopleSoft Enterprise PT PeopleTools | CWE-306 | Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle P… |
| CVE-2025-69103 | 7.5 | 33.9 | Utillz | Brikk | CWE-862 | WordPress Brikk theme <= 3.0.0 - Arbitrary Content Deletion vulnerability |
| CVE-2026-46809 | 9.1 | 33.7 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-46930 | 9.1 | 33.7 | Oracle Corporation | Oracle In-Memory Cost Management for Discrete Industries | CWE-284 | Vulnerability in the Oracle In-Memory Cost Management for Discrete Industries… |
| CVE-2026-46949 | 9.1 | 33.7 | Oracle Corporation | Oracle Advanced Outbound Telephony | CWE-284 | Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-B… |
| CVE-2026-46852 | 9.9 | 33.5 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-269 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-35311 | 8.8 | 33.5 | Oracle Corporation | WebLogic Server | CWE-284 | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com… |
| CVE-2026-46885 | 8.8 | 33.5 | Oracle Corporation | Siebel CRM Integration | CWE-269 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-46921 | 8.8 | 33.5 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-269 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-9507 | 5.1 | 33.6 | Enhancesoft | osTicket | CWE-38 | Session fixation vulnerability in Enhancesoft's osTicket |
| CVE-2026-35282 | 9.9 | 33.4 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-46765 | 9.9 | 33.5 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-46767 | 9.9 | 33.4 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-46779 | 9.9 | 33.4 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-46782 | 9.9 | 33.4 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-46792 | 9.9 | 33.4 | Oracle Corporation | Identity Manager Connector | CWE-284 | Vulnerability in the Identity Manager Connector product of Oracle Fusion Midd… |
| CVE-2026-46793 | 9.9 | 33.4 | Oracle Corporation | Identity Manager Connector | CWE-284 | Vulnerability in the Identity Manager Connector product of Oracle Fusion Midd… |
| CVE-2026-46802 | 9.9 | 33.4 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-46814 | 9.9 | 33.4 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-46844 | 9.9 | 33.5 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-46900 | 9.9 | 33.5 | Oracle Corporation | Oracle Enterprise Command Center Framework | CWE-269 | Vulnerability in the Oracle Enterprise Command Center Framework product of Or… |
| CVE-2026-46963 | 9.9 | 33.4 | Oracle Corporation | Oracle Universal Work Queue | CWE-284 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business… |
| CVE-2026-46964 | 9.9 | 33.4 | Oracle Corporation | Oracle Universal Work Queue | CWE-269 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business… |
| CVE-2026-35318 | 8.8 | 33.4 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-35324 | 8.8 | 33.4 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-46780 | 8.8 | 33.4 | Oracle Corporation | WebCenter Content: Imaging | CWE-306 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd… |
| CVE-2026-46903 | 8.8 | 33.5 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-269 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-46952 | 8.8 | 33.4 | Oracle Corporation | Oracle Quality | CWE-269 | Vulnerability in the Oracle Quality product of Oracle E-Business Suite (compo… |
| CVE-2026-46962 | 8.8 | 33.4 | Oracle Corporation | Oracle Project Portfolio Analysis | CWE-269 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Bu… |
| CVE-2026-46967 | 8.8 | 33.4 | Oracle Corporation | Oracle Public Sector Financials (International) | CWE-284 | Vulnerability in the Oracle Public Sector Financials (International) product … |
| CVE-2026-47277 | 6.5 | 33.0 | runtipi | runtipi | CWE-22 | Runtipi: Unauthenticated arbitrary file read through app-store logo symlinks |
| CVE-2026-46788 | 8.4 | 32.9 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-12290 | 8.1 | 32.9 | Mozilla | Firefox | CWE-119 | Memory safety bug fixed in Firefox 152 |
| CVE-2026-46892 | 9.1 | 32.8 | Oracle Corporation | JD Edwards EnterpriseOne Human Resources Management | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Human Resources Management prod… |
| CVE-2026-2381 | 6.5 | 32.8 | woocommerce | WooCommerce Stripe Payment Gateway | CWE-862 | WooCommerce Stripe Payment Gateway <= 10.7.0 - Missing Authorization to Unaut… |
| CVE-2026-12289 | 8.8 | 32.7 | Mozilla | Firefox | CWE-269 | Privilege escalation in the Graphics: WebRender component |
| CVE-2026-39557 | 8.1 | 32.6 | Elated-Themes | NeoBeat | CWE-502 | WordPress NeoBeat theme <= 1.7 - PHP Object Injection vulnerability |
| CVE-2026-12295 | 9.6 | 32.4 | Mozilla | Firefox | CWE-693 | Sandbox escape in the DOM: Navigation component |
| CVE-2026-12296 | 9.6 | 32.4 | Mozilla | Firefox | CWE-693 | Sandbox escape in the Security: Process Sandboxing component |
| CVE-2026-12297 | 9.6 | 32.4 | Mozilla | Firefox | CWE-119 | Sandbox escape due to incorrect boundary conditions in the Networking component |
| CVE-2026-46866 | 8.2 | 32.4 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-400 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-46795 | 9.3 | 32.2 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-46805 | 9.3 | 32.2 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-35259 | 8.8 | 32.1 | Oracle Corporation | WebLogic Server | CWE-601 | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com… |
| CVE-2026-35262 | 8.3 | 31.8 | Oracle Corporation | Oracle Data Integrator | CWE-284 | Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middlewa… |
| CVE-2026-12291 | 8.8 | 31.3 | Mozilla | Firefox | CWE-416 | Use-after-free in the Networking: HTTP component |
| CVE-2026-35274 | 8.2 | 30.7 | Oracle Corporation | PeopleSoft Enterprise PT PeopleTools | CWE-306 | Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle P… |
| CVE-2026-39529 | 9.8 | 30.6 | ThemeREX Group | Elementra | CWE-502 | WordPress Elementra theme <= 1.0.9 - PHP Object Injection vulnerability |
| CVE-2026-54194 | 9.8 | 30.6 | ThemeFusion | Fusion Builder | CWE-502 | WordPress Fusion Builder plugin <= 3.15.4 - PHP Object Injection vulnerability |
| CVE-2026-46849 | 8.1 | 30.6 | Oracle Corporation | PeopleSoft Enterprise CS Student Financials | CWE-284 | Vulnerability in the PeopleSoft Enterprise CS Student Financials product of O… |
| CVE-2026-35279 | 8.1 | 30.5 | Oracle Corporation | PeopleSoft Enterprise PT PeopleTools | CWE-306 | Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle P… |
| CVE-2026-46927 | 8.1 | 30.5 | Oracle Corporation | Oracle Receivables | CWE-284 | Vulnerability in the Oracle Receivables product of Oracle E-Business Suite (c… |
| CVE-2026-12305 | 7.5 | 30.5 | Mozilla | Firefox | CWE-119 | Memory safety bug fixed in Firefox 152 |
| CVE-2026-35320 | 9.0 | 30.5 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-39438 | 9.3 | 30.3 | Emraan Cheema | ListingPro | CWE-89 | WordPress ListingPro plugin <= 2.9.10 - SQL Injection vulnerability |
| CVE-2026-46776 | 8.6 | 30.2 | Oracle Corporation | Oracle Unified Directory | CWE-284 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-49113 | 8.5 | 30.2 | THEMECO | Cornerstone | CWE-94 | WordPress Cornerstone plugin < 7.8.8 - Arbitrary Code Execution vulnerability |
| CVE-2026-10640 | 7.1 | 30.1 | zephyrproject | zephyr | CWE-416 | Use-after-free reading `net_pkt` `iface` after send in IPv6 Neighbor Discover… |
| CVE-2026-46897 | 9.9 | 29.9 | Oracle Corporation | Oracle Enterprise Command Center Framework | CWE-284 | Vulnerability in the Oracle Enterprise Command Center Framework product of Or… |
| CVE-2026-46901 | 9.9 | 29.9 | Oracle Corporation | Oracle Enterprise Command Center Framework | CWE-269 | Vulnerability in the Oracle Enterprise Command Center Framework product of Or… |
| CVE-2026-12294 | 9.6 | 29.4 | Mozilla | Firefox | CWE-693 | Sandbox escape in the DOM: Workers component |
| CVE-2026-12326 | 8.1 | 29.4 | Mozilla | Firefox | CWE-119 | Memory safety bugs fixed in Firefox 152 and Thunderbird 152 |
| CVE-2026-35263 | 9.9 | 29.3 | Oracle Corporation | WebLogic Server | CWE-284 | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com… |
| CVE-2026-46919 | 9.8 | 29.3 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-284 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-46861 | 9.6 | 29.3 | Oracle Corporation | MySQL NDB Cluster | CWE-284 | Vulnerability in the MySQL NDB Cluster product of Oracle MySQL (component: Cl… |
| CVE-2026-46932 | 7.1 | 29.1 | Oracle Corporation | Oracle Enterprise Asset Management | CWE-284 | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-B… |
| CVE-2026-53776 | 9.3 | 28.8 | PerryTS | perry | CWE-613 | Perry < 0.5.1166 JWT Expiration Bypass via verify_decode |
| CVE-2026-46846 | 10.0 | 28.6 | Oracle Corporation | Oracle WebCenter Portal | CWE-306 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-44932 | 8.8 | 28.6 | SUSE | wicked | CWE-78 | indirect remote shell command injection via unsanitized DHCP options in wicked |
| CVE-2026-49772 | 9.3 | 28.5 | Liquid Web / StellarWP | The Events Calendar | CWE-89 | WordPress The Events Calendar plugin 6.15.12-6.16.2 - SQL Injection vulnerabi… |
| CVE-2026-46910 | 9.1 | 28.5 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-20 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-35269 | 7.5 | 28.5 | Oracle Corporation | Identity Manager | CWE-284 | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (co… |
| CVE-2026-35306 | 9.3 | 28.4 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-46796 | 8.0 | 28.4 | Oracle Corporation | Oracle WebCenter Sites | CWE-601 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-10638 | 7.5 | 28.3 | zephyrproject | zephyr | CWE-416 | Use-after-free in Zephyr ICMPv6 RX path when updating statistics after sendin… |
| CVE-2026-39433 | 6.5 | 28.3 | mojoomla | WPAMS | CWE-862 | WordPress WPAMS plugin < 49.5.3 - Arbitrary Content Deletion vulnerability |
| CVE-2026-46898 | 8.1 | 28.1 | Oracle Corporation | Oracle Enterprise Command Center Framework | CWE-284 | Vulnerability in the Oracle Enterprise Command Center Framework product of Or… |
| CVE-2026-35291 | 6.6 | 28.1 | Oracle Corporation | WebLogic Server | CWE-269 | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com… |
| CVE-2025-69118 | 8.1 | 27.9 | ThemeREX | CopyPress | CWE-98 | WordPress CopyPress theme <= 1.4.5 - Local File Inclusion vulnerability |
| CVE-2025-69125 | 8.1 | 27.9 | ThemeREX | Food Drop | CWE-98 | WordPress Food Drop theme <= 1.3 - Local File Inclusion vulnerability |
| CVE-2025-69141 | 8.1 | 27.9 | ThemeREX | Kelly Young | CWE-98 | WordPress Kelly Young theme <= 1.1.0 - Local File Inclusion vulnerability |
| CVE-2025-69146 | 8.1 | 27.9 | ThemeREX | Dom | CWE-98 | WordPress Dom theme <= 1.24 - Local File Inclusion vulnerability |
| CVE-2025-69176 | 8.1 | 27.9 | ThemeREX | ITactics | CWE-98 | WordPress ITactics theme <= 1.0 - Local File Inclusion vulnerability |
| CVE-2026-8444 | 8.8 | 27.7 | https://wpreviewslider.com/ | WP Review Slider Pro | CWE-89 | WP Review Slider Pro <= 12.6.8 - Authenticated (Subscriber+) SQL Injection vi… |
| CVE-2026-53853 | 7.6 | 27.7 | OpenClaw | OpenClaw | CWE-693 | OpenClaw < 2026.5.12 - Argument Pattern Bypass in Exec Allowlist via Linux an… |
| CVE-2026-27395 | 9.8 | 27.5 | Schiocco | Support Board | CWE-266 | WordPress Support Board plugin < 3.8.9 - Privilege Escalation vulnerability |
| CVE-2026-46899 | 9.6 | 27.4 | Oracle Corporation | Oracle Enterprise Command Center Framework | CWE-269 | Vulnerability in the Oracle Enterprise Command Center Framework product of Or… |
| CVE-2026-46939 | 8.1 | 27.4 | Oracle Corporation | Oracle Configure to Order | CWE-284 | Vulnerability in the Oracle Configure to Order product of Oracle E-Business S… |
| CVE-2026-0646 | 8.7 | 27.3 | Rockwell Automation | FLEX I/O EtherNet/IP Adapters | CWE-401 | Rockwell Automation FLEX I/O Dual-port EtherNet/IP Adapters – Multiple Vulner… |
| CVE-2026-46953 | 7.2 | 26.8 | Oracle Corporation | Oracle HRMS (UK) | CWE-269 | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (com… |
| CVE-2026-46976 | 7.2 | 26.8 | Oracle Corporation | Oracle Public Sector Payroll | CWE-284 | Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Busines… |
| CVE-2026-35305 | 9.3 | 26.7 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-34893 | 8.1 | 26.7 | WebGeniusLab | Thegov Core | CWE-98 | WordPress Thegov Core plugin < 2.0.23 - Local File Inclusion vulnerability |
| CVE-2026-34895 | 8.1 | 26.7 | WebGeniusLab | Softlab Core | CWE-98 | WordPress Softlab Core plugin < 1.2.11 - Local File Inclusion vulnerability |
| CVE-2026-39547 | 8.1 | 26.7 | Select-Themes | Getaway | CWE-98 | WordPress Getaway theme < 1.8 - Local File Inclusion vulnerability |
| CVE-2026-46906 | 9.6 | 26.7 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-46891 | 8.1 | 26.7 | Oracle Corporation | JD Edwards EnterpriseOne Accounts Payable | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product of Ora… |
| CVE-2026-46790 | 5.3 | 26.6 | Oracle Corporation | Oracle WebCenter Content | CWE-200 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-8443 | 8.8 | 26.4 | https://wpreviewslider.com/ | WP Review Slider Pro | CWE-89 | WP Review Slider Pro <= 12.6.8 - Authenticated (Subscriber+) SQL Injection vi… |
| CVE-2026-48616 | 9.3 | 26.1 | Rocket.Chat | Rocket.Chat | CWE-284 | Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.… |
| CVE-2026-46808 | 8.7 | 26.1 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-5149 | 6.5 | 25.6 | rometheme | RTMKit | CWE-863 | RTMKit <= 2.0.7 - Authenticated (Contributor+) Missing Authorization to Arbit… |
| CVE-2026-46804 | 8.7 | 25.4 | Oracle Corporation | Oracle WebCenter Content | CWE-269 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-48797 | 9.3 | 25.3 | mcp-tool-shop-org | backpropagate | CWE-358 | Backpropagate: backprop ui --auth and backprop ui --share do not enforce auth… |
| CVE-2026-35271 | 8.7 | 25.2 | Oracle Corporation | PeopleSoft Enterprise PT PeopleTools | CWE-284 | Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle P… |
| CVE-2026-46806 | 8.2 | 25.2 | Oracle Corporation | Oracle WebCenter Content | CWE-601 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-48745 | 9.3 | 25.1 | traccar | traccar-client | CWE-940 | Traccar Client: silent configuration hijack via unverified deep link redirect… |
| CVE-2026-6964 | 5.3 | 25.1 | j_3rk | Video Conferencing with Zoom | CWE-862 | Video Conferencing with Zoom <= 4.6.7 - Missing Authorization to Unauthentica… |
| CVE-2026-48782 | 6.8 | 25.0 | pydantic | pydantic-ai | CWE-918 | pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local N… |
| CVE-2026-40739 | 8.1 | 24.8 | Mikado-Themes | LuxeDrive | CWE-502 | WordPress LuxeDrive theme <= 1.4 - PHP Object Injection vulnerability |
| CVE-2026-40751 | 8.1 | 24.8 | Mikado-Themes | Ashtanga | CWE-502 | WordPress Ashtanga theme <= 1.2 - PHP Object Injection vulnerability |
| CVE-2026-40758 | 8.1 | 24.8 | Elated-Themes | Léonie | CWE-502 | WordPress Léonie theme <= 1.2.1 - PHP Object Injection vulnerability |
| CVE-2026-40759 | 8.1 | 24.8 | Mikado-Themes | Esmée | CWE-502 | WordPress Esmée theme <= 1.4 - PHP Object Injection vulnerability |
| CVE-2026-46915 | 8.5 | 24.5 | Oracle Corporation | Oracle Complex Maintenance, Repair and Overhaul | CWE-284 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product … |
| CVE-2026-7273 | 8.8 | 24.3 | Zyxel | GS1900-48HPv2 firmware | CWE-121 | A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS190… |
| CVE-2026-12329 | 5.3 | 24.1 | Mozilla | Firefox | CWE-119 | Memory safety bug fixed in Thunderbird ESR 140.12 |
| CVE-2026-49080 | 9.3 | 23.9 | TMS | wpDataTables | CWE-89 | WordPress wpDataTables plugin <= 7.3.6 - SQL Injection vulnerability |
| CVE-2026-46870 | 8.5 | 23.8 | Oracle Corporation | MySQL Shell | CWE-284 | Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell fo… |
| CVE-2026-35295 | 7.5 | 23.8 | Oracle Corporation | Oracle WebCenter Sites | CWE-306 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-46934 | 7.5 | 23.8 | Oracle Corporation | Oracle Complex Maintenance, Repair and Overhaul | CWE-269 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product … |
| CVE-2026-46935 | 7.5 | 23.8 | Oracle Corporation | Oracle Complex Maintenance, Repair and Overhaul | CWE-269 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product … |
| CVE-2026-46957 | 7.5 | 23.8 | Oracle Corporation | Oracle iSupplier Portal | CWE-284 | Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Sui… |
| CVE-2026-46966 | 7.5 | 23.8 | Oracle Corporation | Oracle Universal Work Queue | CWE-269 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business… |
| CVE-2026-10828 | 6.9 | 23.7 | Moxa | NPort W2150A-W4/W2250A-W4 Series | CWE-134 | A format string vulnerability has been found in the "alias" parameter of the … |
| CVE-2026-46916 | 8.8 | 23.4 | Oracle Corporation | Oracle Process Manufacturing Product Development | CWE-269 | Vulnerability in the Oracle Process Manufacturing Product Development product… |
| CVE-2026-46928 | 8.8 | 23.4 | Oracle Corporation | Oracle Spares Management | CWE-269 | Vulnerability in the Oracle Spares Management product of Oracle E-Business Su… |
| CVE-2026-39443 | 8.1 | 23.4 | PressLayouts | EmallShop | CWE-502 | WordPress EmallShop theme <= 2.4.21 - PHP Object Injection vulnerability |
| CVE-2026-39446 | 8.1 | 23.4 | PressLayouts | Kapee | CWE-502 | WordPress Kapee theme < 1.7.0 - PHP Object Injection vulnerability |
| CVE-2026-39539 | 8.1 | 23.4 | Edge-Themes | Alloggio - Hotel Booking | CWE-502 | WordPress Alloggio - Hotel Booking theme <= 2.1.2 - PHP Object Injection vuln… |
| CVE-2026-39554 | 8.1 | 23.4 | Elated-Themes | Fidalgo | CWE-502 | WordPress Fidalgo theme <= 1.2.2 - PHP Object Injection vulnerability |
| CVE-2026-39567 | 8.1 | 23.4 | Select-Themes | Santé | CWE-502 | WordPress Santé theme <= 1.5.1 - PHP Object Injection vulnerability |
| CVE-2026-10636 | 3.7 | 23.4 | zephyrproject | zephyr | CWE-416 | Use-after-free in Zephyr IPv4 IGMP send path (`igmp_send`) |
| CVE-2026-46978 | 10.0 | 23.3 | Oracle Corporation | Oracle Solaris | CWE-284 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Rem… |
| CVE-2026-35314 | 7.3 | 23.4 | Oracle Corporation | Oracle Access Manager | CWE-284 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-12298 | 5.4 | 23.2 | Mozilla | Firefox | CWE-125 | Memory safety bug fixed in Firefox 152 |
| CVE-2026-12299 | 5.4 | 23.2 | Mozilla | Firefox | CWE-843 | JIT miscompilation in the DOM: Core & HTML component |
| CVE-2026-35258 | 8.7 | 23.1 | Oracle Corporation | WebLogic Server | CWE-601 | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com… |
| CVE-2026-39490 | 7.5 | 23.1 | artbees | JupiterX Core | CWE-862 | WordPress JupiterX Core plugin <= 4.14.1 - Broken Access Control vulnerability |
| CVE-2026-12293 | 9.8 | 22.8 | Mozilla | Firefox | CWE-416 | Use-after-free in the Graphics: WebGPU component |
| CVE-2026-11317 | 8.7 | 22.7 | Rockwell Automation | CompactLogix, ControlLogix | CWE-404 | Rockwell Automation Logix 5370 and 5570 Controllers Vulnerable To Denial of S… |
| CVE-2026-46893 | 9.9 | 22.7 | Oracle Corporation | JD Edwards EnterpriseOne General Ledger | CWE-269 | Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracl… |
| CVE-2026-46972 | 8.8 | 22.7 | Oracle Corporation | Oracle Outsourced Mfg for Discrete Industries | CWE-269 | Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of… |
| CVE-2026-35302 | 8.3 | 22.7 | Oracle Corporation | WebLogic Server | CWE-601 | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com… |
| CVE-2026-10637 | 7.1 | 22.5 | zephyrproject | zephyr | CWE-416 | Use-after-free of `net_pkt` in IPv6 MLD send path triggerable by a link-local… |
| CVE-2025-69137 | 6.5 | 22.5 | Jthemes | Genemy | CWE-862 | WordPress Genemy theme <= 1.6.6 - Broken Access Control vulnerability |
| CVE-2026-12105 | 6.5 | 22.4 | Devolutions | Devolutions Server | CWE-862 | Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an a… |
| CVE-2026-9307 | 6.3 | 22.4 | Rockwell Automation | CompactLogix 5370 | CWE-497 | Rockwell Automation CompactLogix 5370 Controllers – Multiple Vulnerabilities |
| CVE-2026-10748 | 8.6 | 22.2 | Sonatype | Nexus Repository | CWE-502 | Nexus Repository 3 - Remote Code Execution via License Deserialization |
| CVE-2026-49057 | 7.5 | 22.2 | EyeCix Technologies | JobSearch | CWE-862 | WordPress JobSearch plugin <= 3.2.7 - Broken Access Control vulnerability |
| CVE-2026-46979 | 6.5 | 21.9 | Oracle Corporation | PeopleSoft Enterprise CS Campus Community | CWE-284 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Ora… |
| CVE-2026-10831 | 6.9 | 21.7 | Moxa | NPort 6000 Series | CWE-862 | Improper Authorization of Break Signal Commands in Devices |
| CVE-2026-46920 | 8.1 | 21.6 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-284 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2025-13036 | 9.2 | 21.4 | Rockwell Automation | FactoryTalk Historian SE | CWE-362 | Rockwell Automation FactoryTalk Historian Site Edition - Authentication Bypass |
| CVE-2026-12317 | 7.5 | 21.3 | Mozilla | Firefox | CWE-119 | Memory safety bug fixed in Firefox 152 |
| CVE-2026-0132 | 8.8 | 21.0 | Google | Android | CWE-122 | In Modem, there is a possible out of bounds write due to a heap buffer overfl… |
| CVE-2026-0149 | 8.8 | 21.0 | Google | Android | CWE-122 | In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap… |
| CVE-2026-12348 | 7.4 | 20.8 | The Browser Company of New York` | Arc Search | CWE-1021 | Address Bar Spoofing in Arc Search for Android (window.open race condition) |
| CVE-2026-46872 | 9.0 | 20.7 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-49774 | 9.9 | 20.4 | Filipe Nasc | RD Station | CWE-94 | WordPress RD Station plugin <= 5.6.0 - Remote Code Execution (RCE) vulnerability |
| CVE-2026-39581 | 8.5 | 20.3 | activity-log.com | WP Sessions Time Monitoring Full Automatic | CWE-89 | WordPress WP Sessions Time Monitoring Full Automatic plugin <= 1.1.4 - SQL In… |
| CVE-2026-0126 | 9.8 | 20.1 | Google | Android | CWE-787 | In WC-Radio, there is a possible out of bounds write due to a missing bounds … |
| CVE-2026-0139 | 8.8 | 20.1 | Google | Android | CWE-119 | In Modem, there is a possible out of bounds write due to a missing bounds che… |
| CVE-2026-0146 | 8.8 | 20.1 | Google | Android | CWE-120 | In mfc_core_get_dec_metadata_sei_nal of mfc_core_reg_api.c, there is a possib… |
| CVE-2026-0147 | 8.8 | 20.1 | Google | Android | CWE-120 | In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a … |
| CVE-2026-0148 | 8.8 | 20.1 | Google | Android | CWE-190 | In multiple functions of VideoRtpPayloadDecoderNode.cpp, there is a possible … |
| CVE-2026-53843 | 8.7 | 19.9 | OpenClaw | OpenClaw | CWE-613 | OpenClaw < 2026.5.26 - Node Token Revocation Bypass via Pairing-Scoped Device… |
| CVE-2026-40750 | 9.9 | 19.7 | themagnifico52 | Kids Online Store | CWE-434 | WordPress Kids Online Store theme <= 0.8.9 - Arbitrary File Upload vulnerability |
| CVE-2026-54197 | 6.5 | 19.7 | Wpmet | GetGenie | CWE-201 | WordPress GetGenie plugin <= 4.4.1 - Sensitive Data Exposure vulnerability |
| CVE-2026-46448 | 8.5 | 19.6 | OpenStack | Nova | CWE-669 | In OpenStack Nova before 33.0.2, the server create API does not strip certain… |
| CVE-2026-35261 | 6.5 | 19.6 | Oracle Corporation | Oracle Access Manager | CWE-287 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-46810 | 6.5 | 19.6 | Oracle Corporation | Identity Manager | CWE-284 | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (co… |
| CVE-2026-53866 | 7.6 | 19.3 | OpenClaw | OpenClaw | CWE-862 | OpenClaw < 2026.5.12 - Allowlist Bypass in Shell Inline-Command Parsing |
| CVE-2026-35327 | 7.6 | 19.2 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-39578 | 5.5 | 19.2 | Elated-Themes | Valiance | CWE-502 | WordPress Valiance theme <= 1.2 - PHP Object Injection vulnerability |
| CVE-2026-46911 | 9.6 | 18.9 | Oracle Corporation | JD Edwards EnterpriseOne Project Costing | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Project Costing product of Orac… |
| CVE-2026-46912 | 9.3 | 18.9 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-200 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-53849 | 8.6 | 18.9 | OpenClaw | OpenClaw | CWE-290 | OpenClaw < 2026.5.7 - Privilege Escalation via Mutable Discord Display Names … |
| CVE-2026-46925 | 8.3 | 18.5 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-284 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-12318 | 7.3 | 18.2 | Mozilla | Firefox | CWE-119 | Incorrect boundary conditions in the Libraries component in NSS |
| CVE-2026-46871 | 6.5 | 18.0 | Oracle Corporation | MySQL Shell | CWE-284 | Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell fo… |
| CVE-2026-12306 | 5.3 | 18.0 | Mozilla | Firefox | CWE-119 | Memory safety bug fixed in Firefox 152 |
| CVE-2026-12307 | 5.3 | 18.0 | Mozilla | Firefox | CWE-119 | Memory safety bug fixed in Firefox 152 |
| CVE-2026-12308 | 5.3 | 18.0 | Mozilla | Firefox | CWE-119 | Memory safety bug fixed in Firefox 152 |
| CVE-2026-12117 | 4.3 | 18.0 | Devolutions | Devolutions Server | CWE-200 | Improper access control in the social login connection endpoint in Devolution… |
| CVE-2026-53855 | 7.6 | 17.9 | OpenClaw | OpenClaw | CWE-184 | OpenClaw < 2026.4.2 - Shell Positional Parameters Bypass in Inline-Eval Checks |
| CVE-2026-54190 | 6.5 | 17.7 | Awesomemotive | Envira Photo Gallery | CWE-862 | WordPress Envira Photo Gallery plugin <= 1.12.5 - Broken Access Control vulne… |
| CVE-2026-0127 | 6.5 | 17.0 | Google | Android | CWE-125 | In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is … |
| CVE-2026-0136 | 6.5 | 17.0 | Google | Android | CWE-120 | In Modem, there is a possible out of bounds read due to a missing bounds chec… |
| CVE-2026-0144 | 6.5 | 17.0 | Google | Android | CWE-120 | In writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety is… |
| CVE-2026-12310 | 7.5 | 16.8 | Mozilla | Firefox | CWE-119 | Memory safety bug fixed in Firefox 152 |
| CVE-2026-12312 | 7.5 | 16.8 | Mozilla | Firefox | CWE-119 | Memory safety bug fixed in Firefox 152 |
| CVE-2026-12314 | 7.5 | 16.8 | Mozilla | Firefox | CWE-119 | Memory safety bug fixed in Firefox 152 |
| CVE-2026-12300 | 5.3 | 16.9 | Mozilla | Firefox | CWE-119 | Memory safety bug fixed in Firefox 152 |
| CVE-2026-12301 | 5.3 | 16.9 | Mozilla | Firefox | CWE-119 | Memory safety bug fixed in Firefox 152 |
| CVE-2026-12315 | 9.1 | 16.7 | Mozilla | Firefox | CWE-693 | Mitigation bypass in the DOM: Security component |
| CVE-2026-39580 | 8.1 | 16.6 | Select-Themes | Micdrop | CWE-502 | WordPress Micdrop theme <= 1.3.1 - PHP Object Injection vulnerability |
| CVE-2026-40736 | 8.1 | 16.6 | Edge-Themes | Laurits | CWE-502 | WordPress Laurits theme <= 1.5.1 - PHP Object Injection vulnerability |
| CVE-2026-40754 | 8.1 | 16.6 | Elated-Themes | Roisin | CWE-502 | WordPress Roisin theme <= 1.4 - PHP Object Injection vulnerability |
| CVE-2026-40755 | 8.1 | 16.6 | Mikado-Themes | TechLink | CWE-502 | WordPress TechLink theme <= 1.3 - PHP Object Injection vulnerability |
| CVE-2026-40760 | 8.1 | 16.6 | Edge-Themes | Behold | CWE-502 | WordPress Behold theme <= 1.5 - PHP Object Injection vulnerability |
| CVE-2026-40761 | 8.1 | 16.6 | Edge-Themes | Valeska | CWE-502 | WordPress Valeska theme <= 1.2.2 - PHP Object Injection vulnerability |
| CVE-2026-53861 | 5.3 | 16.5 | OpenClaw | OpenClaw | CWE-184 | OpenClaw < 2026.5.6 - Allowlist Bypass via Combined POSIX Inline Flags on macOS |
| CVE-2026-12302 | 6.5 | 16.3 | Mozilla | Firefox | CWE-693 | Mitigation bypass in the DOM: Security component |
| CVE-2026-48788 | 8.2 | 16.3 | umputun | remark42 | CWE-79 | Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing |
| CVE-2026-46958 | 7.5 | 16.3 | Oracle Corporation | Oracle Subledger Accounting | CWE-269 | Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business… |
| CVE-2026-46959 | 7.5 | 16.3 | Oracle Corporation | Oracle Subledger Accounting | CWE-269 | Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business… |
| CVE-2026-46971 | 7.5 | 16.3 | Oracle Corporation | Oracle HR Intelligence | CWE-269 | Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suit… |
| CVE-2026-1767 | 8.1 | 16.1 | Red Hat | Red Hat Enterprise Linux 10 | CWE-805 | Localsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer ove… |
| CVE-2026-53864 | 7.6 | 16.1 | OpenClaw | OpenClaw | CWE-184 | OpenClaw < 2026.5.26 - Insufficient Environment Variable Sanitization in Node… |
| CVE-2026-12316 | 9.1 | 16.0 | Mozilla | Firefox | CWE-693 | Mitigation bypass in the DOM: Security component |
| CVE-2026-46812 | 6.1 | 16.0 | Oracle Corporation | Oracle Access Manager | CWE-284 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-53854 | 6.0 | 16.0 | OpenClaw | OpenClaw | CWE-863 | OpenClaw < 2026.4.25 - Privilege Escalation via ownerAllowFrom Wildcard Inher… |
| CVE-2026-52715 | 9.3 | 15.7 | Eyal Fitoussi | GEO my WordPress | CWE-89 | WordPress GEO my WordPress plugin <= 4.5.5 - SQL Injection vulnerability |
| CVE-2026-10825 | 7.1 | 15.3 | Moxa | NPort 6000-G2 Series | CWE-1287 | Improper JSON Input Validation in WebSocket API Leads to Denial of Service |
| CVE-2025-69104 | 7.1 | 14.9 | jkdevstudio | Qreatix | CWE-79 | WordPress Qreatix theme <= 1.9.4 - Cross Site Scripting (XSS) vulnerability |
| CVE-2025-14272 | 8.3 | 14.6 | Rockwell Automation | FactoryTalk Analytics PavilionX | CWE-862 | Rockwell Automation FactoryTalk Analytics PavilionX |
| CVE-2026-12309 | 6.5 | 14.7 | Mozilla | Firefox | CWE-119 | Memory safety bug fixed in Firefox 152 |
| CVE-2026-39574 | 9.3 | 14.6 | RealMag777 | InPost Gallery | CWE-89 | WordPress InPost Gallery plugin <= 2.1.4.6 - SQL Injection vulnerability |
| CVE-2026-11890 | 4.3 | 14.5 | Devolutions | Devolutions Server | CWE-882 | Improper access control in PAM account discovery results in Devolutions Serve… |