AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .9560 99.9 YES
AFFECTED Product Versions Fixed WordPress 6.9.0 – —
TIMELINE Jul 17 Reserved by CNA Jul 21 Added to CISA KEV, due Jul 24 Jul 21 Published (CNA: WPScan)
1477 CVEs published July 21, 2026: 310 critical, 658 high, 417 medium, 92 low; 4 in KEV; 26 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 1452 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 3189 | 5938 | 1304 | 2563 |
| KEV catalog size | 1670 | |||
102 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| microsoft | 639 | 1342 | 95 | 923 | 299 | 8 | 378 | 31 | 2.3 | 7.8 | .0039 | +420 |
| linux | 311 | 1229 | 178 | 975 | 57 | 0 | 27 | 3 | 0.2 | 7.8 | .0014 | +263 |
| red hat | 52 | 151 | 9 | 79 | 55 | 8 | 4 | 0 | 0.0 | 7.1 | .0029 | +17 |
| apple | 0 | 77 | 1 | 17 | 51 | 1 | 93 | 7 | 9.1 | 6.5 | .0037 | 0 |
| 22 | 31 | 6 | 20 | 1 | 1 | 73 | 5 | 16.1 | 8.8 | .0030 | +20 | |
| canonical | 3 | 3 | 0 | 2 | 1 | 0 | 0 | 0 | 0.0 | 7.8 | .0013 | +3 |
| android | 0 | 1 | 0 | 1 | 0 | 0 | 16 | 1 | 100.0 | 8.4 | .0171 | -1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 7 | 19 | 4 | 6 | 1 | 0 | 96 | 12 | 63.2 | 8.6 | .2459 | +5 |
| fortinet | 10 | 17 | 2 | 4 | 8 | 0 | 28 | 5 | 29.4 | 6.3 | .0051 | +9 |
| palo alto networks | 10 | 15 | 0 | 1 | 7 | 5 | 14 | 2 | 13.3 | 4.7 | .0028 | +7 |
| vmware | 7 | 7 | 1 | 6 | 0 | 0 | 21 | 0 | 0.0 | 8.7 | .0044 | +7 |
| f5 | 1 | 5 | 4 | 0 | 0 | 0 | 7 | 1 | 20.0 | 9.2 | .0402 | 0 |
| ivanti | 0 | 5 | 1 | 0 | 0 | 0 | 33 | 5 | 100.0 | 10.0 | .8152 | -1 |
| broadcom | 2 | 4 | 0 | 0 | 2 | 0 | 4 | 2 | 50.0 | 5.1 | .0877 | +2 |
| ubiquiti | 0 | 4 | 3 | 1 | 0 | 0 | 4 | 3 | 75.0 | 10.0 | .7455 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| mozilla | 66 | 71 | 42 | 25 | 4 | 0 | 13 | 0 | 0.0 | 9.1 | .0031 | +66 |
| apache | 16 | 48 | 14 | 26 | 8 | 0 | 40 | 1 | 2.1 | 7.5 | .0063 | +1 |
| docker | 0 | 3 | 0 | 1 | 2 | 0 | 1 | 0 | 0.0 | 5.7 | .0015 | -3 |
| wordpress | 2 | 2 | 1 | 0 | 1 | 0 | 5 | 2 | 100.0 | 7.9 | .8435 | +2 |
| gitlab | 0 | 2 | 0 | 0 | 0 | 0 | 4 | 2 | 100.0 | — | .4451 | 0 |
| github | 1 | 1 | 0 | 0 | 1 | 0 | 0 | 0 | 0.0 | 4.7 | .0017 | +1 |
| drupal | 0 | 1 | 1 | 0 | 0 | 0 | 5 | 1 | 100.0 | 9.8 | .8832 | 0 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 1098 | 1102 | 208 | 532 | 304 | 57 | 40 | 3 | 0.3 | 7.5 | .0031 | +1096 |
| ibm | 31 | 39 | 16 | 11 | 12 | 0 | 7 | 0 | 0.0 | 8.8 | .0029 | +31 |
| adobe | 16 | 27 | 9 | 10 | 4 | 0 | 75 | 4 | 14.8 | 8.6 | .0144 | +9 |
| solarwinds | 15 | 19 | 15 | 1 | 1 | 0 | 11 | 4 | 21.1 | 9.1 | .0044 | +14 |
| atlassian | 3 | 3 | 0 | 3 | 0 | 0 | 13 | 0 | 0.0 | 8.0 | .0026 | +3 |
| zohocorp | 2 | 2 | 0 | 1 | 1 | 0 | 0 | 0 | 0.0 | 5.7 | .0038 | +2 |
| progress | 1 | 1 | 0 | 1 | 0 | 0 | 9 | 0 | 0.0 | 8.7 | .0034 | +1 |
| sap | 0 | 0 | 0 | 0 | 0 | 0 | 12 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 7 | 8 | 0 | 0 | 6 | 1 | 26 | 1 | 12.5 | 5.5 | .0073 | +7 |
| rockwell automation | 1 | 1 | 1 | 0 | 0 | 0 | 0 | 0 | 0.0 | 9.2 | .0030 | +1 |
| hikvision | 0 | 1 | 0 | 0 | 0 | 0 | 2 | 1 | 100.0 | — | 1.0000 | 0 |
| siemens | 0 | 1 | 0 | 1 | 0 | 0 | 1 | 0 | 0.0 | 8.7 | .0032 | 0 |
| dahua | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| qnap | 0 | 0 | 0 | 0 | 0 | 0 | 8 | 0 | — | — | — | 0 |
| schneider electric | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| tp-link | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| surrealdb | 57 | 57 | 3 | 26 | 25 | 3 | 0 | 0 | 0.0 | 7.1 | .0025 | +57 |
| grafana | 6 | 39 | 2 | 13 | 21 | 3 | 0 | 0 | 0.0 | 6.5 | .0033 | +4 |
| open ises | 0 | 37 | 2 | 14 | 21 | 0 | 0 | 0 | 0.0 | 6.9 | .0021 | 0 |
| netty | 10 | 32 | 6 | 24 | 1 | 1 | 0 | 0 | 0.0 | 7.5 | .0051 | -4 |
| watchguard | 17 | 28 | 1 | 18 | 9 | 0 | 4 | 0 | 0.0 | 7.3 | .0026 | +17 |
| mervinpraison | 25 | 25 | 8 | 13 | 4 | 0 | 0 | 0 | 0.0 | 8.3 | .0028 | +25 |
| erlang | 6 | 24 | 0 | 10 | 11 | 3 | 1 | 0 | 0.0 | 6.6 | .0033 | -1 |
| egor | 23 | 23 | 7 | 1 | 4 | 11 | 0 | 0 | 0.0 | 4.0 | .0012 | +23 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-48282 | .9924 | 99.9 | — |
| CVE-2026-63030 | .9560 | 99.9 | 9.8 |
| CVE-2026-39808 | .9121 | 99.8 | — |
| CVE-2026-48908 | .8813 | 99.8 | 10.0 |
| CVE-2026-34910 | .8696 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-56290 | .8325 | 99.7 | 10.0 |
| CVE-2026-20230 | .8321 | 99.7 | 8.6 |
| CVE-2026-48939 | .8250 | 99.6 | 10.0 |
| CVE-2026-50522 | .7698 | 99.5 | 9.8 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-48908 | 10.0 | .8813 | KEV |
| CVE-2026-34910 | 10.0 | .8696 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-56290 | 10.0 | .8325 | KEV |
| CVE-2026-48939 | 10.0 | .8250 | KEV |
| CVE-2026-56291 | 10.0 | .7607 | KEV |
| CVE-2026-15409 | 10.0 | .7422 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-8985 | 10.0 | .0660 | |
| CVE-2026-44359 | 10.0 | .0100 |
| Vendor | CVEs |
|---|---|
| oracle | 1098 |
| microsoft | 639 |
| linux | 504 |
| red hat | 72 |
| mozilla | 66 |
| surrealdb | 57 |
| ibm | 39 |
| apple | 37 |
| mervinpraison | 25 |
| egor | 23 |
| Vendor | KEV |
|---|---|
| microsoft | 31 |
| cisco | 12 |
| apple | 7 |
| fortinet | 5 |
| 5 | |
| ivanti | 5 |
| adobe | 4 |
| langflow | 4 |
| solarwinds | 4 |
| synacor | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 11 |
| crates.io | 1 |
| npm | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4128 | Cisco | 0 |
| CVE-2021-27137 | DD-WRT | 0 |
| CVE-2023-4346 | KNX Association | 0 |
| CVE-2025-67038 | Lantronix | 0 |
| CVE-2026-0770 | Langflow | 0 |
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-25089 | Fortinet | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1707 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1707 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1707 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1707 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1707 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1707 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1707 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1707 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1707 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1707 |
EXPLOIT PUBLISHED — CVE-2023-4692 (grub). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2023-4693 (Red Hat Enterprise Linux 8). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-11816 (keras-team/keras). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-13142 (Unknown Social Login, Passkeys, Magic Link & Email OTP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16324 (Metasoft 美特软件 MetaCRM). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16372 (Mozilla Firefox). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-24779 (vllm-project vllm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-25048 (mlc-ai xgrammar). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-25960 (vllm-project vllm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-33236 (nltk). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47143 (capstone-engine capstone). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47178 (strukturag libheif). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47247 (strukturag libheif). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47251 (strukturag libheif). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47254 (strukturag libheif). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47671 (nhost cli). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47685 (fogproject). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47687 (fogproject). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47688 (fogproject). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47689 (fogproject). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47709 (strukturag libheif). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-49978 (cure53 DOMPurify). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54293 (nltk). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55831 (netty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55833 (netty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56816 (netty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56819 (netty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56820 (netty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58049 (FFmpeg). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-59197 (python-pillow Pillow). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-59204 (python-pillow Pillow). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-59732 (rclone). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63730 (hyperdxio hyperdx). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63731 (hyperdxio hyperdx). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63767 (kvcache-ai ktransformers). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63768 (calcom cal.diy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63769 (huginn). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63770 (glanceapp glance). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63771 (vrana adminer). Public exploit reference added.
RESCORED — CVE-2023-3640 (Red Hat Enterprise Linux 6). CVSS 7 → 7.8 (NVD).
RESCORED — CVE-2023-4692 (grub). CVSS 7.5 → 7.8 (NVD).
RESCORED — CVE-2023-4693 (Red Hat Enterprise Linux 8). CVSS 5.3 → 4.6 (NVD).
RESCORED — CVE-2026-16014 (code-projects Hospital Bed Management System). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-16075 (AstrBotDevs AstrBot). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16084 (Sipeed PicoClaw). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-16119 (nextlevelbuilder GoClaw). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16125 (zevorn rt-claw). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-16131 (itsourcecode Hospital Management System). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16155 (SourceCodester Class and Exam Timetabling System). CVSS 5.1 → 2 (NVD).
RESCORED — CVE-2026-16156 (SourceCodester Class and Exam Timetabling System). CVSS 5.1 → 2 (NVD).
RESCORED — CVE-2026-16198 (Sipeed PicoClaw). CVSS 6.3 → 2.9 (NVD).
RESCORED — CVE-2026-16204 (zevorn rt-claw). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16210 (newpanjing simpleui). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-16216 (geex-arts django-jet). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16223 (1Panel-dev CordysCRM). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16229 (itsourcecode Courier Management System). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16327 (D-Link DNS-320). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-22807 (vllm-project vllm). CVSS 8.8 → 9.8 (NVD).
RESCORED — CVE-2026-25960 (vllm-project vllm). CVSS 7.1 → 9.8 (NVD).
RESCORED — CVE-2026-50377 (Microsoft Windows 10 Version 1607). CVSS 5.5 → 7.8 (NVD).
RESCORED — CVE-2026-50485 (Microsoft Windows 10 Version 1607). CVSS 4.5 → 5.7 (NVD).
RESCORED — CVE-2026-50489 (Microsoft Windows 10 Version 1607). CVSS 8.8 → 7.8 (NVD).
RESCORED — CVE-2026-50500 (Microsoft Windows 10 Version 1607). CVSS 7.5 → 8.8 (NVD).
RESCORED — CVE-2026-56169 (Microsoft Windows Admin Center). CVSS 8.1 → 8.8 (NVD).
RESCORED — CVE-2026-7754 (IBM Langflow OSS). CVSS 7.7 → 6.5 (NVD).
ENRICHED — CVE-2026-46817 (Oracle E-Business Suite). Received CVSS 9.8 and CPE data from NVD.
1477 CVEs published. 25 box scores and 375 table rows below; the remaining 1077 continue on page 2 · page 3 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .9560 99.9 YES
AFFECTED Product Versions Fixed WordPress 6.9.0 – —
TIMELINE Jul 17 Reserved by CNA Jul 21 Added to CISA KEV, due Jul 24 Jul 21 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H N N 5.9 .7310 99.4 YES
AFFECTED Product Versions Fixed WordPress 6.8.0 – —
TIMELINE Jul 17 Reserved by CNA Jul 21 Added to CISA KEV, due Aug 4 Jul 21 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .5688 99.0 YES
AFFECTED Product Versions Fixed Langflow 1.4.2 – —
TIMELINE Jan 8 Reserved by CNA Jul 21 Added to CISA KEV, due Jul 24 Jul 21 Published (CNA: zdi)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H H H 8.1 .1649 96.7 YES
AFFECTED Product Versions Fixed DD-WRT unspecified —
TIMELINE Feb 10 Reserved by CNA Jul 21 Added to CISA KEV, due Jul 24 Jul 21 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0660 93.3 —
AFFECTED Product Versions Fixed MaxiCharger Single unspecified —
TIMELINE May 19 Reserved by CNA Jul 21 Published (CNA: CyberDanube)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 9.4 .0259 84.0 —
AFFECTED Product Versions Fixed Security Center unspecified Patch SC202607.1
TIMELINE Jul 20 Reserved by CNA Jul 21 Published (CNA: tenable)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.5 .0229 81.7 —
AFFECTED Product Versions Fixed MaxiCharger Single unspecified —
TIMELINE May 19 Reserved by CNA Jul 21 Published (CNA: CyberDanube)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0165 74.5 —
AFFECTED Product Versions Fixed EdgeConnect SD-WAN Gateway (ECOS) 9.4.0.0 – —
TIMELINE May 7 Reserved by CNA Jul 21 Published (CNA: hpe)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0144 71.0 —
AFFECTED Product Versions Fixed Security Center unspecified Patch SC202607.1
TIMELINE Jul 20 Reserved by CNA Jul 21 Published (CNA: tenable)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0128 67.6 —
AFFECTED Product Versions Fixed Serv-U 15.5.4 HF1 and below – —
TIMELINE Feb 26 Reserved by CNA Jul 21 Published (CNA: SolarWinds)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0106 61.6 —
AFFECTED Product Versions Fixed DNS-120 20260205 – — DNR-202L 20260205 – — DNS-315L 20260205 – — DNS-320 20260205 – — DNS-320L 20260205 – — DNS-320LW 20260205 – — DNS-321 20260205 – — DNR-322L 20260205 – — DNS-323 20260205 – — DNS-325 20260205 – — + 10 more
TIMELINE Jul 21 Reserved by CNA Jul 21 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N P L L L 1.3 .0100 60.1 —
AFFECTED Product Versions Fixed MiniCode-Python 0.1.0 – 0.1.0-rc1
TIMELINE Jul 21 Reserved by CNA Jul 21 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV A H N N U H H H 7.5 .0099 59.6 —
AFFECTED Product Versions Fixed Red Hat Enterprise Linux 8 unspecified 0:049-244.git20260529.el8_10 Red Hat Hardened Images unspecified 109-7.hum1 Red Hat Enterprise Linux 10 unspecified — Red Hat Enterprise Linux 6 unspecified — Red Hat Enterprise Linux 7 unspecified — Red Hat Enterprise Linux 9 unspecified — Red Hat OpenShift Container Platform 4 unspecified —
TIMELINE Jul 21 Reserved by CNA Jul 21 Published (CNA: redhat)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0095 58.3 —
AFFECTED Product Versions Fixed AX7501-B1 firmware <= 5.17(ABPC.7.2)C0 – —
TIMELINE Apr 24 Reserved by CNA Jul 21 Published (CNA: Zyxel)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0086 55.5 —
AFFECTED Product Versions Fixed FUXA >= 1.2.11, < 1.3.1 – —
TIMELINE May 4 Reserved by CNA Jul 21 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0084 54.8 —
AFFECTED Product Versions Fixed grav unspecified 2.0.7
TIMELINE Jul 21 Reserved by CNA Jul 21 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H H 9.1 .0080 53.7 —
AFFECTED Product Versions Fixed AIT-Core < 2.6.1 – —
TIMELINE May 19 Reserved by CNA Jul 21 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0078 52.9 —
AFFECTED Product Versions Fixed PraisonAI < 4.6.40 – —
TIMELINE May 19 Reserved by CNA Jul 21 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0077 52.5 —
AFFECTED Product Versions Fixed MaxiCharger Single unspecified —
TIMELINE May 19 Reserved by CNA Jul 21 Published (CNA: CyberDanube)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0073 51.2 —
AFFECTED Product Versions Fixed DNS-320 1.0.2 – —
TIMELINE Jul 20 Reserved by CNA Jul 21 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0073 51.2 —
AFFECTED Product Versions Fixed DNS-320 1.0.2 – —
TIMELINE Jul 20 Reserved by CNA Jul 21 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0073 51.2 —
AFFECTED Product Versions Fixed DNS-320 1.0.2 – —
TIMELINE Jul 21 Reserved by CNA Jul 21 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0067 48.8 —
AFFECTED Product Versions Fixed FUXA = 1.3.0 – —
TIMELINE May 4 Reserved by CNA Jul 21 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0066 48.6 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Mar 4 Reserved by CNA Jul 21 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0066 48.6 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Mar 4 Reserved by CNA Jul 21 Published (CNA: mitre)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-64606 | 9.8 | 47.5 | Apache Software Foundation | Apache Fory | CWE-502 | Apache Fory, Apache Fory: Class-registration bypass through an auto-admitted … |
| CVE-2026-16489 | 1.9 | 47.0 | n/a | jsforce | CWE-77 | jsforce SFDX Connection Registry sfdx.js _execCommand os command injection |
| CVE-2026-55851 | 8.7 | 46.4 | netty | netty | CWE-400 | Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder … |
| CVE-2026-56745 | 8.7 | 46.4 | netty | netty | CWE-400 | Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native M… |
| CVE-2026-47392 | 9.9 | 46.0 | MervinPraison | PraisonAI | CWE-184 | PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module l… |
| CVE-2026-1771 | 7.2 | 45.2 | oyatek | MapSVG – Vector maps, Image maps, Google Maps | CWE-20 | MapSVG <= 8.14.0 - Authenticated (Administrator+) Arbitrary File Upload via '… |
| CVE-2026-64824 | 9.3 | 44.8 | home-assistant | Home Assistant Core | CWE-22 | Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore |
| CVE-2026-65315 | 8.7 | 44.6 | Ollama | Ollama | CWE-789 | Ollama Remote Denial of Service via Attacker-Controlled Allocation in GGUF Me… |
| CVE-2026-28302 | 9.1 | 43.8 | SolarWinds | Serv-U | CWE-639 | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-63454 | 7.2 | 43.3 | Hewlett Packard Enterprise (HPE) | AOS-CX | CWE-22 | Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in … |
| CVE-2026-28304 | 9.1 | 43.3 | SolarWinds | Serv-U | CWE-284 | SolarWinds Serv-U Remote Code Execution Vulnerability |
| CVE-2026-28305 | 9.1 | 43.3 | SolarWinds | Serv-U | CWE-639 | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-28308 | 9.1 | 43.3 | SolarWinds | Serv-U | CWE-639 | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-64878 | 9.4 | 43.0 | Tenable, Inc. | Security Center | CWE-78 | Command Injection |
| CVE-2026-43946 | 7.7 | 43.0 | frangoteam | FUXA | CWE-863 | FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue |
| CVE-2026-16329 | 5.5 | 42.9 | D-Link | DNS-320 | CWE-284 | D-Link DNS-320 uploadify.php unrestricted upload |
| CVE-2026-16332 | 5.5 | 42.9 | D-Link | DNS-320 | CWE-284 | D-Link DNS-320 multi_uploadify.php unrestricted upload |
| CVE-2026-44880 | 8.8 | 42.2 | Hewlett Packard Enterprise (HPE) | AOS-CX | CWE-120 | Low-Privilege Authenticated Buffer Overflow Vulnerabilities lead to Remote Co… |
| CVE-2026-59843 | 6.5 | 42.1 | Red Hat | Red Hat Enterprise Linux 10 | CWE-835 | Libssh: libssh: denial of service via zero advertised channel packet size |
| CVE-2026-59844 | 6.5 | 42.1 | Red Hat | Red Hat Enterprise Linux 10 | CWE-789 | Libssh: libssh: denial of service via oversized sftp read length |
| CVE-2026-60198 | 9.8 | 41.9 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60205 | 9.8 | 41.9 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60292 | 9.8 | 41.9 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-56816 | 7.5 | 41.9 | netty | netty | CWE-400 | Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types |
| CVE-2026-8987 | 9.4 | 41.3 | Autel | MaxiCharger Single | CWE-122 | Authenticated Heap Overflow |
| CVE-2026-60200 | 9.8 | 41.0 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60202 | 9.8 | 41.0 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60204 | 9.8 | 41.0 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60291 | 9.8 | 41.0 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60294 | 9.8 | 41.0 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-50758 | 8.1 | 40.9 | n/a | n/a | CWE-79 | Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allo… |
| CVE-2026-30631 | 9.8 | 40.4 | n/a | n/a | CWE-78 | An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309a… |
| CVE-2026-60206 | 9.9 | 39.7 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60786 | 7.2 | 39.7 | Oracle Corporation | Oracle Receivables | CWE-284 | Vulnerability in the Oracle Receivables product of Oracle E-Business Suite (c… |
| CVE-2026-60900 | 7.2 | 39.7 | Oracle Corporation | Oracle HCM Configuration Workbench | CWE-269 | Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-B… |
| CVE-2026-60918 | 7.2 | 39.7 | Oracle Corporation | Oracle Shipping Execution | CWE-269 | Vulnerability in the Oracle Shipping Execution product of Oracle E-Business S… |
| CVE-2026-60925 | 7.2 | 39.7 | Oracle Corporation | Oracle Public Sector Payroll | CWE-269 | Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Busines… |
| CVE-2026-60926 | 7.2 | 39.7 | Oracle Corporation | Oracle Public Sector Payroll | CWE-284 | Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Busines… |
| CVE-2026-61006 | 7.2 | 39.7 | Oracle Corporation | Oracle Process Manufacturing Logistics | CWE-269 | Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle… |
| CVE-2026-61140 | 9.8 | 39.6 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-64825 | 9.0 | 39.5 | home-assistant | Home Assistant Core | CWE-22 | Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload |
| CVE-2026-65317 | 9.2 | 39.4 | Weaviate | Verba | CWE-918 | Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Ori… |
| CVE-2026-3183 | 7.1 | 39.4 | Zohocorp | ManageEngine ADSelfService Plus | CWE-290 | Multi Factor Auth Bypass |
| CVE-2026-64608 | 9.8 | 39.4 | Apache Software Foundation | Apache Fory | CWE-502 | Apache Fory: Heap type confusion and out-of-bounds read/write in C++ compatib… |
| CVE-2026-64609 | 9.1 | 39.1 | Apache Software Foundation | Apache Fory | CWE-125 | Apache Fory, Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy… |
| CVE-2026-60217 | 10.0 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60225 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60551 | 9.8 | 38.9 | Oracle Corporation | Oracle WebCenter Sites | CWE-200 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-47040 | 9.1 | 38.9 | Oracle Corporation | Oracle Net Services | CWE-306 | Vulnerability in the Oracle Net Services component of Oracle Database Server.… |
| CVE-2026-60358 | 10.0 | 38.9 | Oracle Corporation | Oracle Access Manager | CWE-284 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-60360 | 10.0 | 38.9 | Oracle Corporation | Oracle Unified Directory | CWE-306 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60379 | 10.0 | 38.9 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60389 | 10.0 | 38.9 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-35290 | 9.8 | 38.9 | Oracle Corporation | Oracle Application Testing Suite | CWE-284 | Vulnerability in Oracle Application Testing Suite. The supported version that… |
| CVE-2026-46876 | 9.8 | 38.9 | Oracle Corporation | Oracle Application Testing Suite | CWE-284 | Vulnerability in Oracle Application Testing Suite. The supported version that… |
| CVE-2026-46983 | 9.8 | 38.9 | Oracle Corporation | Oracle Retail Integration Bus | CWE-284 | Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail A… |
| CVE-2026-60173 | 9.8 | 38.9 | Oracle Corporation | Oracle BI Publisher | CWE-284 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-60197 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60209 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60210 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60212 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60215 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60216 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60219 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60224 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60226 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60227 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60228 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60229 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60230 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60234 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60236 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60240 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60242 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60247 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60253 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60254 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60256 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60257 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60258 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60259 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60262 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60272 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60274 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60275 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60280 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60285 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60286 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60287 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60288 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60289 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60290 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60296 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60297 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60298 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60299 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60300 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60302 | 9.8 | 38.9 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60355 | 9.8 | 38.9 | Oracle Corporation | Oracle Access Manager | CWE-306 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-60362 | 9.8 | 38.9 | Oracle Corporation | Oracle Unified Directory | CWE-306 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60375 | 9.8 | 38.9 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60376 | 9.8 | 38.9 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60378 | 9.8 | 38.9 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60384 | 9.8 | 38.9 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60385 | 9.8 | 38.9 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60386 | 9.8 | 38.9 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60442 | 9.8 | 38.9 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60532 | 9.8 | 38.9 | Oracle Corporation | Oracle Identity Manager Connector | CWE-269 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-60535 | 9.8 | 38.9 | Oracle Corporation | Oracle Identity Manager Connector | CWE-306 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-60538 | 9.8 | 38.9 | Oracle Corporation | Oracle SOA Suite | CWE-306 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co… |
| CVE-2026-60541 | 9.8 | 38.9 | Oracle Corporation | Oracle SOA Suite | CWE-284 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co… |
| CVE-2026-60555 | 9.8 | 38.9 | Oracle Corporation | Oracle WebCenter Sites | CWE-200 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-61065 | 9.8 | 38.9 | Oracle Corporation | Oracle Access Manager | CWE-287 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-61100 | 9.8 | 38.9 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-306 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-61129 | 9.8 | 38.9 | Oracle Corporation | Oracle Commerce Platform | CWE-287 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com… |
| CVE-2026-61131 | 9.8 | 38.9 | Oracle Corporation | Oracle Commerce Platform | CWE-284 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com… |
| CVE-2026-61145 | 9.8 | 38.9 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-61161 | 9.8 | 38.9 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-61167 | 9.8 | 38.9 | Oracle Corporation | Oracle Agile PLM | CWE-284 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-61178 | 9.8 | 38.9 | Oracle Corporation | Oracle Agile Product Lifecycle Management for Process | CWE-287 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process pr… |
| CVE-2026-61183 | 9.8 | 38.9 | Oracle Corporation | Oracle Agile Product Lifecycle Management for Process | CWE-287 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process pr… |
| CVE-2026-61196 | 9.8 | 38.9 | Oracle Corporation | Oracle Identity Manager | CWE-306 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-61233 | 9.8 | 38.9 | Oracle Corporation | PeopleSoft Enterprise FIN Common Objects Brazil | CWE-200 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product … |
| CVE-2026-61155 | 9.1 | 38.9 | Oracle Corporation | Oracle Commerce Guided Search Platform Services | CWE-284 | Vulnerability in the Oracle Commerce Guided Search Platform Services product … |
| CVE-2026-60529 | 7.2 | 38.4 | Oracle Corporation | Oracle WebLogic Server | CWE-284 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-50757 | 7.8 | 38.3 | n/a | n/a | CWE-22 | Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allow… |
| CVE-2026-47057 | 7.5 | 38.2 | Oracle Corporation | Oracle Java SE | CWE-400 | Vulnerability in Oracle Java SE (component: Scripting). Supported versions th… |
| CVE-2026-60180 | 7.5 | 38.2 | Oracle Corporation | MySQL Connectors | CWE-400 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Con… |
| CVE-2026-60208 | 9.1 | 38.1 | Oracle Corporation | Oracle WebLogic Server | CWE-400 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-50759 | 7.5 | 38.2 | n/a | n/a | CWE-306 | An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privi… |
| CVE-2026-60845 | 7.2 | 38.2 | Oracle Corporation | Oracle Mobile Application Server | CWE-284 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Bus… |
| CVE-2026-59144 | 9.8 | 38.0 | EGOR | Data::RingBuffer::Shared | CWE-121 | Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer o… |
| CVE-2026-61235 | 9.1 | 37.6 | Oracle Corporation | PeopleSoft Enterprise HCM Global Payroll Switzerland | CWE-284 | Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland pro… |
| CVE-2026-46954 | 7.2 | 37.6 | Oracle Corporation | Oracle Human Resources | CWE-284 | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suit… |
| CVE-2026-60153 | 7.2 | 37.6 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60345 | 7.2 | 37.6 | Oracle Corporation | Oracle JDeveloper | CWE-284 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (c… |
| CVE-2026-60466 | 7.2 | 37.6 | Oracle Corporation | WebCenter Content: Imaging | CWE-284 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd… |
| CVE-2026-60502 | 7.2 | 37.6 | Oracle Corporation | WebCenter Content: Imaging | CWE-284 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd… |
| CVE-2026-60519 | 7.2 | 37.6 | Oracle Corporation | Oracle Unified Directory | CWE-284 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60546 | 7.2 | 37.6 | Oracle Corporation | Oracle SOA Suite | CWE-269 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co… |
| CVE-2026-60576 | 7.2 | 37.6 | Oracle Corporation | Oracle Enterprise Command Center Framework | CWE-269 | Vulnerability in the Oracle Enterprise Command Center Framework product of Or… |
| CVE-2026-60645 | 7.2 | 37.6 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60828 | 7.2 | 37.6 | Oracle Corporation | Oracle Interaction Blending | CWE-284 | Vulnerability in the Oracle Interaction Blending product of Oracle E-Business… |
| CVE-2026-61025 | 7.2 | 37.6 | Oracle Corporation | Oracle iRecruitment | CWE-284 | Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (… |
| CVE-2026-61035 | 7.2 | 37.6 | Oracle Corporation | Oracle Financials for the Americas | CWE-284 | Vulnerability in the Oracle Financials for the Americas product of Oracle E-B… |
| CVE-2026-61039 | 7.2 | 37.6 | Oracle Corporation | Oracle Advanced Supply Chain Planning | CWE-284 | Vulnerability in the Oracle Advanced Supply Chain Planning product of Oracle … |
| CVE-2026-61068 | 7.2 | 37.5 | Oracle Corporation | PeopleSoft Enterprise FIN Billing Argentina | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Billing Argentina product of O… |
| CVE-2026-61094 | 7.2 | 37.6 | Oracle Corporation | MySQL Server | CWE-269 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-61107 | 7.2 | 37.6 | Oracle Corporation | Oracle Applications DBA | CWE-269 | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Sui… |
| CVE-2026-61115 | 7.2 | 37.6 | Oracle Corporation | Oracle Order Management | CWE-284 | Vulnerability in the Oracle Order Management product of Oracle E-Business Sui… |
| CVE-2026-61314 | 7.2 | 37.6 | Oracle Corporation | Oracle EDI Gateway | CWE-284 | Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (c… |
| CVE-2026-61336 | 7.2 | 37.6 | Oracle Corporation | Oracle Lease and Finance Management | CWE-269 | Vulnerability in the Oracle Lease and Finance Management product of Oracle E-… |
| CVE-2026-62466 | 7.2 | 37.6 | Oracle Corporation | Oracle Human Resources | CWE-284 | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suit… |
| CVE-2026-47018 | 7.5 | 37.4 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-400 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-60252 | 7.5 | 37.4 | Oracle Corporation | Oracle Coherence | CWE-400 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60301 | 7.5 | 37.4 | Oracle Corporation | Oracle Coherence | CWE-400 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60382 | 7.5 | 37.4 | Oracle Corporation | Service Delivery Platform | CWE-400 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-47247 | 7.5 | 37.2 | strukturag | libheif | CWE-200 | libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninit… |
| CVE-2026-56852 | 7.5 | 37.1 | golang.org/x/text | golang.org/x/text/unicode/norm | CWE-835 | Infinite loop on invalid input in golang.org/x/text |
| CVE-2026-28314 | 9.1 | 37.0 | SolarWinds | Serv-U | CWE-639 | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-61211 | 9.9 | 36.6 | Oracle Corporation | Oracle Database Server | CWE-284 | Vulnerability in the RDBMS component of Oracle Database Server. Supported ver… |
| CVE-2026-16363 | 9.8 | 36.3 | Mozilla | Firefox | CWE-682 | JIT miscompilation in the JavaScript: WebAssembly component |
| CVE-2026-16369 | 9.8 | 36.3 | Mozilla | Firefox | CWE-190 | Integer overflow in the JavaScript: WebAssembly component |
| CVE-2026-16389 | 9.8 | 36.3 | Mozilla | Firefox | CWE-190 | Incorrect boundary conditions, integer overflow in the Libraries component in… |
| CVE-2026-60678 | 8.8 | 36.0 | Oracle Corporation | Oracle General Ledger | CWE-269 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite… |
| CVE-2026-60789 | 8.8 | 36.0 | Oracle Corporation | Oracle Sales Offline | CWE-284 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite … |
| CVE-2026-60863 | 8.8 | 36.0 | Oracle Corporation | Oracle Advanced Pricing | CWE-269 | Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Sui… |
| CVE-2026-60872 | 8.8 | 36.0 | Oracle Corporation | Oracle Order Management | CWE-269 | Vulnerability in the Oracle Order Management product of Oracle E-Business Sui… |
| CVE-2026-60890 | 8.8 | 36.0 | Oracle Corporation | Oracle Payroll | CWE-269 | Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (compo… |
| CVE-2026-60897 | 8.8 | 36.0 | Oracle Corporation | Oracle Payroll | CWE-269 | Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (compo… |
| CVE-2026-60901 | 8.8 | 36.0 | Oracle Corporation | Oracle Project Intelligence | CWE-269 | Vulnerability in the Oracle Project Intelligence product of Oracle E-Business… |
| CVE-2026-60920 | 8.8 | 36.0 | Oracle Corporation | Oracle Customer Care | CWE-269 | Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite … |
| CVE-2026-60924 | 8.8 | 36.0 | Oracle Corporation | Oracle Public Sector Payroll | CWE-269 | Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Busines… |
| CVE-2026-60932 | 8.8 | 36.0 | Oracle Corporation | Oracle Labor Distribution | CWE-269 | Vulnerability in the Oracle Labor Distribution product of Oracle E-Business S… |
| CVE-2026-60952 | 8.8 | 36.0 | Oracle Corporation | Oracle Transportation Execution | CWE-269 | Vulnerability in the Oracle Transportation Execution product of Oracle E-Busi… |
| CVE-2026-60989 | 8.8 | 36.0 | Oracle Corporation | Oracle Advanced Collections | CWE-306 | Vulnerability in the Oracle Advanced Collections product of Oracle E-Business… |
| CVE-2026-61010 | 8.8 | 36.0 | Oracle Corporation | Oracle Process Manufacturing Systems | CWE-269 | Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E… |
| CVE-2026-60734 | 7.2 | 35.9 | Oracle Corporation | Oracle Trading Community | CWE-284 | Vulnerability in the Oracle Trading Community product of Oracle E-Business Su… |
| CVE-2026-47052 | 4.9 | 35.9 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60171 | 4.9 | 35.9 | Oracle Corporation | MySQL Cluster | CWE-400 | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Server… |
| CVE-2026-61144 | 4.9 | 35.9 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-8983 | 10.0 | 35.7 | Autel | MaxiCharger Single | CWE-798 | Backdoor Authentication Token |
| CVE-2026-47394 | 8.7 | 35.6 | MervinPraison | PraisonAI | CWE-22 | PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.… |
| CVE-2026-47667 | 7.5 | 35.5 | GreycLab | CImg | CWE-401 | CImg Library: Uncontrolled Memory Allocation and Memory Leak in `_load_analyz… |
| CVE-2026-50755 | 9.8 | 35.5 | n/a | n/a | CWE-290 | An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to ob… |
| CVE-2026-61203 | 9.4 | 35.4 | Oracle Corporation | PeopleSoft Enterprise FIN Expenses | CWE-269 | Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle Peo… |
| CVE-2026-61175 | 9.3 | 35.4 | Oracle Corporation | Oracle Product Lifecycle Analytics | CWE-200 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Sup… |
| CVE-2026-65318 | 9.2 | 35.4 | Weaviate | Verba | CWE-918 | Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket… |
| CVE-2026-60544 | 8.2 | 35.4 | Oracle Corporation | Oracle SOA Suite | CWE-306 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co… |
| CVE-2026-60080 | 7.3 | 35.4 | Apache Software Foundation | Apache Fory | CWE-416 | Apache Fory: Rust MetaString heap use-after-free |
| CVE-2026-60718 | 6.5 | 35.3 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-59842 | 5.3 | 35.0 | Red Hat | Red Hat Hardened Images | CWE-125 | Libssh: libssh: information disclosure via short gssapi curve25519 public key |
| CVE-2026-60293 | 8.6 | 34.9 | Oracle Corporation | Oracle WebLogic Server | CWE-200 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60556 | 8.6 | 34.9 | Oracle Corporation | Oracle WebCenter Sites | CWE-200 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-60167 | 7.5 | 34.9 | Oracle Corporation | Oracle Hospitality Simphony | CWE-200 | Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and B… |
| CVE-2026-60554 | 7.5 | 34.9 | Oracle Corporation | Oracle WebCenter Sites | CWE-200 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-61133 | 7.5 | 34.9 | Oracle Corporation | Oracle Commerce Platform | CWE-200 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com… |
| CVE-2026-61159 | 7.5 | 34.9 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-200 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-15957 | 8.7 | 34.8 | AWS | aws-sdk-rust | CWE-770 | Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserialize… |
| CVE-2026-59147 | 9.8 | 34.7 | EGOR | Data::DisjointSet::Shared | CWE-125 | Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds r… |
| CVE-2026-59145 | 9.1 | 34.7 | EGOR | Data::Intern::Shared | CWE-125 | Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds rea… |
| CVE-2026-60168 | 9.1 | 34.7 | Oracle Corporation | Oracle Hospitality Simphony | CWE-284 | Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and B… |
| CVE-2026-60223 | 7.5 | 34.7 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60207 | 8.8 | 34.5 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60343 | 8.8 | 34.5 | Oracle Corporation | Oracle WebLogic Server | CWE-284 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60689 | 7.5 | 34.5 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-306 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-44878 | 7.2 | 34.4 | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateway (ECOS) | CWE-377 | Authenticated Path Traversal allows Unauthorized Access in Web Interface |
| CVE-2026-16484 | 5.5 | 34.4 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System edit_subjecta.php sql injection |
| CVE-2026-28321 | 9.1 | 34.1 | SolarWinds | Serv-U | CWE-284 | SolarWinds Serv-U Broken Access Control Vulnerability |
| CVE-2026-16350 | 9.8 | 33.7 | Mozilla | Firefox | CWE-119 | Incorrect boundary conditions in the Audio/Video: cubeb component |
| CVE-2026-16353 | 9.8 | 33.7 | Mozilla | Firefox | CWE-416 | Invalid pointer in the DOM: Bindings (WebIDL) component |
| CVE-2026-16355 | 9.8 | 33.7 | Mozilla | Firefox | CWE-843 | JIT miscompilation in the JavaScript Engine: JIT component |
| CVE-2026-16357 | 9.8 | 33.7 | Mozilla | Firefox | CWE-119 | Incorrect boundary conditions in the Graphics component |
| CVE-2026-61176 | 6.7 | 33.8 | Oracle Corporation | Oracle Product Lifecycle Analytics | CWE-269 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Sup… |
| CVE-2026-60174 | 6.5 | 33.7 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60243 | 6.5 | 33.7 | Oracle Corporation | Oracle Coherence | CWE-400 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60404 | 6.5 | 33.7 | Oracle Corporation | TimesTen In-Memory Database | CWE-400 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen I… |
| CVE-2026-61093 | 6.5 | 33.7 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-61109 | 6.5 | 33.7 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-61194 | 6.5 | 33.7 | Oracle Corporation | Oracle Agile Engineering Data Management | CWE-400 | Vulnerability in the Oracle Agile Engineering Data Management product of Orac… |
| CVE-2026-61195 | 6.5 | 33.7 | Oracle Corporation | Oracle Agile Engineering Data Management | CWE-400 | Vulnerability in the Oracle Agile Engineering Data Management product of Orac… |
| CVE-2026-60542 | 9.9 | 33.5 | Oracle Corporation | Oracle Business Process Management Suite | CWE-284 | Vulnerability in the Oracle Business Process Management Suite product of Orac… |
| CVE-2026-60561 | 9.9 | 33.5 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-60565 | 9.9 | 33.5 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-47393 | 9.8 | 33.6 | MervinPraison | PraisonAI | CWE-306 | PraisonAI `deploy --type api` emits a Flask server with authentication disabl… |
| CVE-2026-60157 | 8.8 | 33.5 | Oracle Corporation | Oracle GoldenGate | CWE-284 | Vulnerability in Oracle GoldenGate (component: Service Manager). Supported ve… |
| CVE-2026-60175 | 8.8 | 33.5 | Oracle Corporation | Oracle Database Server | CWE-269 | Vulnerability in the RDBMS component of Oracle Database Server. Supported ver… |
| CVE-2026-60203 | 8.8 | 33.5 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60398 | 8.8 | 33.5 | Oracle Corporation | Oracle GoldenGate | CWE-306 | Vulnerability in Oracle GoldenGate (component: Oracle GoldenGate Microservice… |
| CVE-2026-60676 | 8.8 | 33.5 | Oracle Corporation | Oracle Applications Framework | CWE-284 | Vulnerability in the Oracle Applications Framework product of Oracle E-Busine… |
| CVE-2026-60692 | 8.8 | 33.5 | Oracle Corporation | Oracle Enterprise Asset Management | CWE-284 | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-B… |
| CVE-2026-60829 | 8.8 | 33.5 | Oracle Corporation | Oracle Advanced Outbound Telephony | CWE-284 | Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-B… |
| CVE-2026-61311 | 8.8 | 33.5 | Oracle Corporation | Oracle Product Hub | CWE-306 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c… |
| CVE-2026-61322 | 8.8 | 33.5 | Oracle Corporation | TeleSales | CWE-269 | Vulnerability in the TeleSales product of Oracle E-Business Suite (component:… |
| CVE-2026-60333 | 9.9 | 33.5 | Oracle Corporation | Oracle Access Manager | CWE-287 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-60361 | 9.9 | 33.4 | Oracle Corporation | Oracle Unified Directory | CWE-306 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60456 | 9.9 | 33.5 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60457 | 9.9 | 33.4 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60458 | 9.9 | 33.4 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-306 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60459 | 9.9 | 33.4 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60461 | 9.9 | 33.5 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-306 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60524 | 9.9 | 33.4 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60531 | 9.9 | 33.4 | Oracle Corporation | Oracle Identity Manager Connector | CWE-306 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-60537 | 9.9 | 33.4 | Oracle Corporation | Oracle Managed File Transfer | CWE-306 | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Mi… |
| CVE-2026-60547 | 9.9 | 33.4 | Oracle Corporation | Oracle Managed File Transfer | CWE-284 | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Mi… |
| CVE-2026-60552 | 9.9 | 33.4 | Oracle Corporation | Oracle WebCenter Sites | CWE-200 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-60627 | 9.9 | 33.4 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-306 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-60711 | 9.9 | 33.4 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-306 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-61041 | 9.9 | 33.4 | Oracle Corporation | Oracle Demantra Demand Management | CWE-284 | Vulnerability in the Oracle Demantra Demand Management product of Oracle Supp… |
| CVE-2026-61072 | 9.9 | 33.4 | Oracle Corporation | PeopleSoft Enterprise FIN Staffing Front Office Brazil | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office Brazil p… |
| CVE-2026-61076 | 9.9 | 33.5 | Oracle Corporation | PeopleSoft Enterprise HCM Talent Acquisition Manager | CWE-269 | Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager pro… |
| CVE-2026-61146 | 9.9 | 33.5 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-269 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-61209 | 9.9 | 33.4 | Oracle Corporation | PeopleSoft In-Memory Project Discovery | CWE-269 | Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle… |
| CVE-2026-46992 | 8.8 | 33.4 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-306 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-46995 | 8.8 | 33.5 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-269 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-47004 | 8.8 | 33.5 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-306 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-47031 | 8.8 | 33.5 | Oracle Corporation | Oracle Bills of Material | CWE-284 | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Su… |
| CVE-2026-60268 | 8.8 | 33.5 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60334 | 8.8 | 33.5 | Oracle Corporation | Oracle WebCenter Content | CWE-306 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60430 | 8.8 | 33.4 | Oracle Corporation | Oracle Unified Directory | CWE-284 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60465 | 8.8 | 33.4 | Oracle Corporation | WebCenter Content: Imaging | CWE-284 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd… |
| CVE-2026-60493 | 8.8 | 33.5 | Oracle Corporation | JD Edwards EnterpriseOne Human Resources Management | CWE-306 | Vulnerability in the JD Edwards EnterpriseOne Human Resources Management prod… |
| CVE-2026-60499 | 8.8 | 33.4 | Oracle Corporation | JD Edwards EnterpriseOne Solution Advisor | CWE-306 | Vulnerability in the JD Edwards EnterpriseOne Solution Advisor product of Ora… |
| CVE-2026-60503 | 8.8 | 33.5 | Oracle Corporation | WebCenter Content: Imaging | CWE-284 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd… |
| CVE-2026-60539 | 8.8 | 33.5 | Oracle Corporation | Oracle SOA Suite | CWE-306 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co… |
| CVE-2026-60545 | 8.8 | 33.5 | Oracle Corporation | Oracle Managed File Transfer | CWE-306 | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Mi… |
| CVE-2026-60549 | 8.8 | 33.4 | Oracle Corporation | Oracle Managed File Transfer | CWE-306 | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Mi… |
| CVE-2026-60583 | 8.8 | 33.5 | Oracle Corporation | Oracle Transportation Management | CWE-269 | Vulnerability in the Oracle Transportation Management product of Oracle Suppl… |
| CVE-2026-60594 | 8.8 | 33.5 | Oracle Corporation | PeopleSoft Enterprise CS Campus Community | CWE-284 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Ora… |
| CVE-2026-60602 | 8.8 | 33.4 | Oracle Corporation | PeopleSoft Enterprise CS Student Financials | CWE-306 | Vulnerability in the PeopleSoft Enterprise CS Student Financials product of O… |
| CVE-2026-60603 | 8.8 | 33.4 | Oracle Corporation | PeopleSoft Enterprise CS Student Records | CWE-20 | Vulnerability in the PeopleSoft Enterprise CS Student Records product of Orac… |
| CVE-2026-60618 | 8.8 | 33.5 | Oracle Corporation | JD Edwards EnterpriseOne Procurement and Subcontract Management | CWE-306 | Vulnerability in the JD Edwards EnterpriseOne Procurement and Subcontract Man… |
| CVE-2026-60655 | 8.8 | 33.5 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60656 | 8.8 | 33.4 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60738 | 8.8 | 33.4 | Oracle Corporation | Oracle Installed Base | CWE-284 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite… |
| CVE-2026-60783 | 8.8 | 33.5 | Oracle Corporation | Oracle iReceivables | CWE-284 | Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (… |
| CVE-2026-61098 | 8.8 | 33.5 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-269 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-61099 | 8.8 | 33.5 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-269 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-61110 | 8.8 | 33.4 | Oracle Corporation | Oracle Applications DBA | CWE-269 | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Sui… |
| CVE-2026-61121 | 8.8 | 33.4 | Oracle Corporation | Oracle HRMS (UK) | CWE-269 | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (com… |
| CVE-2026-61127 | 8.8 | 33.4 | Oracle Corporation | Oracle Communications Service Catalog and Design | CWE-269 | Vulnerability in the Oracle Communications Service Catalog and Design product… |
| CVE-2026-61149 | 8.8 | 33.5 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-269 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-61166 | 8.8 | 33.4 | Oracle Corporation | Oracle Agile PLM | CWE-284 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-61168 | 8.8 | 33.4 | Oracle Corporation | Oracle Agile PLM | CWE-269 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-61179 | 8.8 | 33.4 | Oracle Corporation | Oracle Agile Product Lifecycle Management for Process | CWE-269 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process pr… |
| CVE-2026-61180 | 8.8 | 33.5 | Oracle Corporation | Oracle Agile Product Lifecycle Management for Process | CWE-269 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process pr… |
| CVE-2026-61243 | 8.8 | 33.5 | Oracle Corporation | PeopleSoft Enterprise FIN Common Objects Argentina | CWE-269 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina produ… |
| CVE-2026-61289 | 8.8 | 33.4 | Oracle Corporation | Oracle Process Manufacturing Product Development | CWE-284 | Vulnerability in the Oracle Process Manufacturing Product Development product… |
| CVE-2026-61320 | 8.8 | 33.4 | Oracle Corporation | Oracle Payables | CWE-269 | Vulnerability in the Oracle Payables product of Oracle E-Business Suite (comp… |
| CVE-2026-62447 | 8.8 | 33.5 | Oracle Corporation | Oracle Trade Management | CWE-306 | Vulnerability in the Oracle Trade Management product of Oracle E-Business Sui… |
| CVE-2026-61160 | 8.1 | 33.4 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-20 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-60176 | 7.1 | 33.4 | Oracle Corporation | Oracle Payments | CWE-200 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (comp… |
| CVE-2026-13439 | 9.8 | 33.3 | hassantafreshi | Easy Form Builder by WhiteStudio – Drag & Drop Form Builder | CWE-269 | Easy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escala… |
| CVE-2026-28312 | 9.1 | 33.3 | SolarWinds | Serv-U | CWE-285 | SolarWinds Serv-U Privilege Escalation Vulnerability |
| CVE-2026-47143 | 5.9 | 33.0 | capstone-engine | capstone | CWE-476 | Capstone has a NULL Pointer Dereference with 3DNow! opcodes |
| CVE-2026-60145 | 4.9 | 33.0 | Oracle Corporation | MySQL Server | CWE-284 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60194 | 4.9 | 33.0 | Oracle Corporation | MySQL Server | CWE-284 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60195 | 4.9 | 33.0 | Oracle Corporation | MySQL Server | CWE-284 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60365 | 10.0 | 32.9 | Oracle Corporation | Oracle HTTP Server | CWE-306 | Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle F… |
| CVE-2026-60550 | 8.6 | 32.9 | Oracle Corporation | Oracle WebCenter Sites | CWE-200 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-61026 | 7.5 | 32.9 | Oracle Corporation | Oracle iRecruitment | CWE-284 | Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (… |
| CVE-2026-62521 | 7.5 | 32.9 | Oracle Corporation | Oracle HRMS (US) | CWE-284 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (com… |
| CVE-2026-60267 | 9.1 | 32.8 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60606 | 9.1 | 32.8 | Oracle Corporation | PeopleSoft Enterprise CC Common Application Objects | CWE-284 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects prod… |
| CVE-2026-60649 | 9.1 | 32.8 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-61059 | 9.1 | 32.8 | Oracle Corporation | PeopleSoft Enterprise SCM Order Management | CWE-284 | Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Or… |
| CVE-2026-61153 | 9.1 | 32.8 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-61156 | 9.1 | 32.8 | Oracle Corporation | Oracle Commerce Guided Search Platform Services | CWE-284 | Vulnerability in the Oracle Commerce Guided Search Platform Services product … |
| CVE-2026-61171 | 9.1 | 32.8 | Oracle Corporation | Oracle Agile PLM | CWE-284 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-61184 | 9.1 | 32.8 | Oracle Corporation | Oracle Agile Product Lifecycle Management for Process | CWE-284 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process pr… |
| CVE-2026-61197 | 9.1 | 32.8 | Oracle Corporation | Oracle Identity Manager | CWE-284 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-60356 | 8.6 | 32.8 | Oracle Corporation | Oracle Access Manager | CWE-306 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-60359 | 8.6 | 32.8 | Oracle Corporation | Oracle Unified Directory | CWE-306 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60536 | 8.6 | 32.8 | Oracle Corporation | Oracle Identity Manager Connector | CWE-284 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-60559 | 8.6 | 32.8 | Oracle Corporation | Oracle Access Manager | CWE-284 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-60170 | 7.5 | 32.8 | Oracle Corporation | Oracle Hospitality Simphony | CWE-284 | Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and B… |
| CVE-2026-60263 | 7.5 | 32.8 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60605 | 7.5 | 32.8 | Oracle Corporation | PeopleSoft Enterprise CS Student Records | CWE-306 | Vulnerability in the PeopleSoft Enterprise CS Student Records product of Orac… |
| CVE-2026-60622 | 7.5 | 32.8 | Oracle Corporation | Oracle JDeveloper | CWE-284 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (c… |
| CVE-2026-61073 | 7.5 | 32.8 | Oracle Corporation | PeopleSoft Enterprise FIN Common Objects Brazil | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product … |
| CVE-2026-61085 | 7.5 | 32.8 | Oracle Corporation | PeopleSoft Enterprise SCM Inventory | CWE-284 | Vulnerability in the PeopleSoft Enterprise SCM Inventory product of Oracle Pe… |
| CVE-2026-61086 | 7.5 | 32.8 | Oracle Corporation | PeopleSoft Enterprise SCM Order Management | CWE-284 | Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Or… |
| CVE-2026-61087 | 7.5 | 32.8 | Oracle Corporation | PeopleSoft Enterprise FIN Payables | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Payables product of Oracle Peo… |
| CVE-2026-61088 | 7.5 | 32.8 | Oracle Corporation | PeopleSoft Enterprise SCM Manufacturing | CWE-284 | Vulnerability in the PeopleSoft Enterprise SCM Manufacturing product of Oracl… |
| CVE-2026-61157 | 7.5 | 32.8 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-61158 | 7.5 | 32.8 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-61172 | 7.5 | 32.8 | Oracle Corporation | Oracle Agile PLM | CWE-284 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-60880 | 9.8 | 32.7 | Oracle Corporation | Oracle Work in Process | CWE-284 | Vulnerability in the Oracle Work in Process product of Oracle E-Business Suit… |
| CVE-2026-16351 | 9.8 | 32.6 | Mozilla | Firefox | CWE-416 | Sandbox escape due to use-after-free in the DOM: Navigation component |
| CVE-2026-16352 | 9.8 | 32.6 | Mozilla | Firefox | CWE-416 | Sandbox escape due to use-after-free in the Disability Access APIs component |
| CVE-2026-16356 | 9.8 | 32.6 | Mozilla | Firefox | CWE-416 | Sandbox escape due to use-after-free in the Disability Access APIs component |
| CVE-2026-61070 | 5.3 | 32.5 | Oracle Corporation | PeopleSoft Enterprise FIN Common Objects Argentina | CWE-400 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina produ… |
| CVE-2026-60923 | 7.7 | 32.4 | Oracle Corporation | Oracle Capacity | CWE-200 | Vulnerability in the Oracle Capacity product of Oracle E-Business Suite (comp… |
| CVE-2026-60199 | 9.8 | 32.1 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-16368 | 9.8 | 32.0 | Mozilla | Firefox | CWE-119 | Incorrect boundary conditions in the JavaScript: WebAssembly component |
| CVE-2026-16318 | 6.9 | 32.0 | Amazon | s2n-tls | CWE-401 | QUIC Transport Parameters Memory Leak During HelloRetryRequest in s2n-tls |
| CVE-2026-60719 | 9.9 | 31.8 | Oracle Corporation | Oracle BI Publisher | CWE-20 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-16377 | 9.8 | 31.8 | Mozilla | Firefox | CWE-693 | Mitigation bypass in the PDF Viewer component |
| CVE-2026-16383 | 9.8 | 31.8 | Mozilla | Firefox | CWE-693 | Mitigation bypass in the DOM: Networking component |
| CVE-2026-61186 | 9.4 | 31.8 | Oracle Corporation | Oracle Agile Engineering Data Management | CWE-284 | Vulnerability in the Oracle Agile Engineering Data Management product of Orac… |
| CVE-2026-60846 | 6.7 | 31.7 | Oracle Corporation | Oracle Mobile Application Server | CWE-284 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Bus… |
| CVE-2026-8982 | 10.0 | 31.6 | Autel | MaxiCharger Single | CWE-798 | Hard-coded / Backdoor Accounts |
| CVE-2026-60306 | 9.8 | 31.5 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60308 | 9.8 | 31.5 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-52469 | 9.8 | 31.4 | n/a | n/a | CWE-89 | SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to es… |
| CVE-2026-52470 | 9.8 | 31.4 | n/a | n/a | CWE-89 | SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to es… |
| CVE-2026-52472 | 9.8 | 31.4 | n/a | n/a | CWE-89 | SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to esca… |
| CVE-2026-60264 | 9.8 | 31.5 | Oracle Corporation | Oracle Coherence | CWE-200 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2016-20096 | 9.3 | 31.4 | Kunshi Network Technology Co., Ltd. | Linknat VOS3000 | CWE-89 | Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp |
| CVE-2026-65316 | 7.1 | 31.3 | xuxueli | xxl-job | CWE-639 | xxl-job Cross-Job-Group Log Disclosure via Missing Authorization Check in /jo… |
| CVE-2026-47397 | 7.1 | 31.3 | MervinPraison | PraisonAI | CWE-22 | PraisonAI has an Arbitrary File Write in Python API |
| CVE-2026-60941 | 8.7 | 31.1 | Oracle Corporation | Oracle Service Fulfillment Manager | CWE-269 | Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-B… |
| CVE-2026-60165 | 6.5 | 31.1 | Oracle Corporation | Oracle Cost Management | CWE-284 | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suit… |
| CVE-2026-60978 | 6.5 | 31.1 | Oracle Corporation | Oracle Scripting | CWE-284 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (com… |
| CVE-2026-60862 | 6.8 | 31.1 | Oracle Corporation | Oracle Order Management | CWE-284 | Vulnerability in the Oracle Order Management product of Oracle E-Business Sui… |
| CVE-2026-56746 | 6.5 | 31.1 | netty | netty | CWE-284 | Netty has a Security Control Bypass via CORS Short-Circuit Failure |
| CVE-2026-60433 | 6.5 | 31.1 | Oracle Corporation | Oracle Transportation Management | CWE-284 | Vulnerability in the Oracle Transportation Management product of Oracle Suppl… |
| CVE-2026-60843 | 6.5 | 31.1 | Oracle Corporation | Oracle Citizen Interaction Center | CWE-284 | Vulnerability in the Oracle Citizen Interaction Center product of Oracle E-Bu… |
| CVE-2026-47049 | 4.9 | 31.1 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | CWE-284 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-16382 | 9.8 | 30.9 | Mozilla | Firefox | CWE-693 | Mitigation bypass in the DOM: Service Workers component |
| CVE-2026-61309 | 7.5 | 30.8 | Oracle Corporation | Oracle In-Memory Cost Management for Discrete Industries | CWE-284 | Vulnerability in the Oracle In-Memory Cost Management for Discrete Industries… |
| CVE-2026-60192 | 8.1 | 30.8 | Oracle Corporation | MySQL Connectors | CWE-284 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Con… |
| CVE-2026-60548 | 7.7 | 30.7 | Oracle Corporation | Oracle SOA Suite | CWE-200 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co… |
| CVE-2026-61014 | 7.7 | 30.8 | Oracle Corporation | Oracle Inventory Management | CWE-200 | Vulnerability in the Oracle Inventory Management product of Oracle E-Business… |
| CVE-2026-61125 | 7.7 | 30.8 | Oracle Corporation | Oracle Configure to Order | CWE-200 | Vulnerability in the Oracle Configure to Order product of Oracle E-Business S… |
| CVE-2026-60609 | 6.5 | 30.7 | Oracle Corporation | PeopleSoft Enterprise CS Campus Community | CWE-200 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Ora… |
| CVE-2026-60673 | 6.5 | 30.7 | Oracle Corporation | Oracle BI Publisher | CWE-200 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-60835 | 6.5 | 30.8 | Oracle Corporation | Oracle Price Protection | CWE-200 | Vulnerability in the Oracle Price Protection product of Oracle E-Business Sui… |
| CVE-2026-61251 | 6.5 | 30.8 | Oracle Corporation | HRMS (Australia) | CWE-200 | Vulnerability in the HRMS (Australia) product of Oracle E-Business Suite (com… |
| CVE-2026-16367 | 10.0 | 30.7 | Mozilla | Firefox | CWE-119 | Sandbox escape due to invalid pointer in the Disability Access APIs component |
| CVE-2026-16388 | 9.8 | 30.7 | Mozilla | Firefox | CWE-693 | Sandbox escape in the DOM: Networking component |
| CVE-2026-61009 | 8.0 | 30.7 | Oracle Corporation | Oracle Process Manufacturing Logistics | CWE-284 | Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle… |
| CVE-2026-52474 | 7.5 | 30.6 | n/a | n/a | CWE-200 | An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive inf… |
| CVE-2026-61165 | 7.1 | 30.6 | Oracle Corporation | Oracle Commerce Guided Search Platform Services | CWE-200 | Vulnerability in the Oracle Commerce Guided Search Platform Services product … |
| CVE-2026-60892 | 6.6 | 30.7 | Oracle Corporation | Oracle HRMS (Norway) | CWE-284 | Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite … |
Results continue: ranks 401–1477.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-21 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.