boxscore/security
Tuesday, July 21, 2026 · all times UTC← 2026-07-20 · archive · 2026-07-22 →

1477 CVEs published July 21, 2026: 310 critical, 658 high, 417 medium, 92 low; 4 in KEV; 26 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 1452 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published3189593813042563
KEV catalog size1670

102 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
microsoft6391342959232998378312.37.8.0039+420
linux31112291789755702730.27.8.0014+263
red hat52151979558400.07.1.0029+17
apple0771175119379.16.5.00370
google22316201173516.18.8.0030+20
canonical330210000.07.8.0013+3
android010100161100.08.4.0171-1
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco7194610961263.28.6.2459+5
fortinet1017248028529.46.3.0051+9
palo alto networks1015017514213.34.7.0028+7
vmware7716002100.08.7.0044+7
f51540007120.09.2.04020
ivanti051000335100.010.0.8152-1
broadcom2400204250.05.1.0877+2
ubiquiti0431004375.010.0.74550
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
mozilla66714225401300.09.1.0031+66
apache16481426804012.17.5.0063+1
docker030120100.05.7.0015-3
wordpress22101052100.07.9.8435+2
gitlab02000042100.0.44510
github110010000.04.7.0017+1
drupal01100051100.09.8.88320
jenkins000000600
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle10981102208532304574030.37.5.0031+1096
ibm31391611120700.08.8.0029+31
adobe16279104075414.88.6.0144+9
solarwinds15191511011421.19.1.0044+14
atlassian3303001300.08.0.0026+3
zohocorp220110000.05.7.0038+2
progress110100900.08.7.0034+1
sap0000001200
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link78006126112.55.5.0073+7
rockwell automation111000000.09.2.0030+1
hikvision01000021100.01.00000
siemens010100100.08.7.00320
dahua000000200
qnap000000800
schneider electric000000100
tp-link000000600
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
surrealdb5757326253000.07.1.0025+57
grafana639213213000.06.5.0033+4
open ises037214210000.06.9.00210
netty103262411000.07.5.0051-4
watchguard172811890400.07.3.0026+17
mervinpraison252581340000.08.3.0028+25
erlang624010113100.06.6.0033-1
egor232371411000.04.0.0012+23

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-48282.992499.9
CVE-2026-63030.956099.99.8
CVE-2026-39808.912199.8
CVE-2026-48908.881399.810.0
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-56290.832599.710.0
CVE-2026-20230.832199.78.6
CVE-2026-48939.825099.610.0
CVE-2026-50522.769899.59.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4890810.0.8813KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-1540910.0.7422KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-898510.0.0660
CVE-2026-4435910.0.0100
Most disclosures (vendor)
VendorCVEs
oracle1098
microsoft639
linux504
red hat72
mozilla66
surrealdb57
ibm39
apple37
mervinpraison25
egor23
Most KEV additions (YTD)
VendorKEV
microsoft31
cisco12
apple7
fortinet5
google5
ivanti5
adobe4
langflow4
solarwinds4
synacor4
Most-affected ecosystems
EcosystemAdvisories
Maven11
crates.io1
npm1
Fastest to KEV
CVEVendorDays
CVE-2008-4128Cisco0
CVE-2021-27137DD-WRT0
CVE-2023-4346KNX Association0
CVE-2025-67038Lantronix0
CVE-2026-0770Langflow0
CVE-2026-12569PTC0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-20230Cisco0
CVE-2026-25089Fortinet0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171707
CVE-2021-27102Accellion2021-11-171707
CVE-2021-27101Accellion2021-11-171707
CVE-2021-27103Accellion2021-11-171707
CVE-2021-21017Adobe2021-11-171707
CVE-2021-28550Adobe2021-11-171707
CVE-2021-42013Apache2021-11-171707
CVE-2021-41773Apache2021-11-171707
CVE-2021-30858Apple2021-11-171707
CVE-2021-30860Apple2021-11-171707

Transactions

EXPLOIT PUBLISHEDCVE-2023-4692 (grub). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2023-4693 (Red Hat Enterprise Linux 8). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-11816 (keras-team/keras). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-13142 (Unknown Social Login, Passkeys, Magic Link & Email OTP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16324 (Metasoft 美特软件 MetaCRM). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16372 (Mozilla Firefox). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-24779 (vllm-project vllm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-25048 (mlc-ai xgrammar). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-25960 (vllm-project vllm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-33236 (nltk). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47143 (capstone-engine capstone). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47178 (strukturag libheif). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47247 (strukturag libheif). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47251 (strukturag libheif). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47254 (strukturag libheif). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47671 (nhost cli). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47685 (fogproject). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47687 (fogproject). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47688 (fogproject). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47689 (fogproject). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47709 (strukturag libheif). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49978 (cure53 DOMPurify). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54293 (nltk). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55831 (netty). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55833 (netty). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56816 (netty). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56819 (netty). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56820 (netty). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-58049 (FFmpeg). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59197 (python-pillow Pillow). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59204 (python-pillow Pillow). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59732 (rclone). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-63730 (hyperdxio hyperdx). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-63731 (hyperdxio hyperdx). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-63767 (kvcache-ai ktransformers). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-63768 (calcom cal.diy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-63769 (huginn). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-63770 (glanceapp glance). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-63771 (vrana adminer). Public exploit reference added.

RESCOREDCVE-2023-3640 (Red Hat Enterprise Linux 6). CVSS 7 → 7.8 (NVD).

RESCOREDCVE-2023-4692 (grub). CVSS 7.5 → 7.8 (NVD).

RESCOREDCVE-2023-4693 (Red Hat Enterprise Linux 8). CVSS 5.3 → 4.6 (NVD).

RESCOREDCVE-2026-16014 (code-projects Hospital Bed Management System). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-16075 (AstrBotDevs AstrBot). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16084 (Sipeed PicoClaw). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-16119 (nextlevelbuilder GoClaw). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16125 (zevorn rt-claw). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-16131 (itsourcecode Hospital Management System). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16155 (SourceCodester Class and Exam Timetabling System). CVSS 5.1 → 2 (NVD).

RESCOREDCVE-2026-16156 (SourceCodester Class and Exam Timetabling System). CVSS 5.1 → 2 (NVD).

RESCOREDCVE-2026-16198 (Sipeed PicoClaw). CVSS 6.3 → 2.9 (NVD).

RESCOREDCVE-2026-16204 (zevorn rt-claw). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16210 (newpanjing simpleui). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-16216 (geex-arts django-jet). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16223 (1Panel-dev CordysCRM). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16229 (itsourcecode Courier Management System). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16327 (D-Link DNS-320). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-22807 (vllm-project vllm). CVSS 8.8 → 9.8 (NVD).

RESCOREDCVE-2026-25960 (vllm-project vllm). CVSS 7.1 → 9.8 (NVD).

RESCOREDCVE-2026-50377 (Microsoft Windows 10 Version 1607). CVSS 5.5 → 7.8 (NVD).

RESCOREDCVE-2026-50485 (Microsoft Windows 10 Version 1607). CVSS 4.5 → 5.7 (NVD).

RESCOREDCVE-2026-50489 (Microsoft Windows 10 Version 1607). CVSS 8.8 → 7.8 (NVD).

RESCOREDCVE-2026-50500 (Microsoft Windows 10 Version 1607). CVSS 7.5 → 8.8 (NVD).

RESCOREDCVE-2026-56169 (Microsoft Windows Admin Center). CVSS 8.1 → 8.8 (NVD).

RESCOREDCVE-2026-7754 (IBM Langflow OSS). CVSS 7.7 → 6.5 (NVD).

ENRICHEDCVE-2026-46817 (Oracle E-Business Suite). Received CVSS 9.8 and CPE data from NVD.

Yesterday's Results

1477 CVEs published. 25 box scores and 375 table rows below; the remaining 1077 continue on page 2 · page 3 — every CVE is listed, nothing truncated.

WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .9560   99.9   YES
AFFECTED
  Product    Versions  Fixed
  WordPress  6.9.0 –   —
TIMELINE
  Jul 17  Reserved by CNA
  Jul 21  Added to CISA KEV, due Jul 24
  Jul 21  Published (CNA: WPScan)
CWE-436 · CNA: WPScan · 3 references · NVD status: Analyzed · KEV due July 24, 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  N  N    5.9   .7310   99.4   YES
AFFECTED
  Product    Versions  Fixed
  WordPress  6.8.0 –   —
TIMELINE
  Jul 17  Reserved by CNA
  Jul 21  Added to CISA KEV, due Aug 4
  Jul 21  Published (CNA: WPScan)
CWE-89 · CNA: WPScan · 3 references · NVD status: Analyzed · KEV due August 4, 2026
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .5688   99.0   YES
AFFECTED
  Product   Versions  Fixed
  Langflow  1.4.2 –   —
TIMELINE
  Jan 8   Reserved by CNA
  Jul 21  Added to CISA KEV, due Jul 24
  Jul 21  Published (CNA: zdi)
CWE-829 · CNA: zdi · 2 references · NVD status: Analyzed · KEV due July 24, 2026
DD-WRT DD-WRT
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .1649   96.7   YES
AFFECTED
  Product  Versions     Fixed
  DD-WRT   unspecified  —
TIMELINE
  Feb 10  Reserved by CNA
  Jul 21  Added to CISA KEV, due Jul 24
  Jul 21  Published (CNA: mitre)
CWE-121 · CNA: mitre · 6 references · NVD status: Analyzed · KEV due July 24, 2026
Autel MaxiCharger Single — Unauthenticated Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0660   93.3     —
AFFECTED
  Product             Versions     Fixed
  MaxiCharger Single  unspecified  —
TIMELINE
  May 19  Reserved by CNA
  Jul 21  Published (CNA: CyberDanube)
CWE-78 · CNA: CyberDanube · 1 reference · NVD status: Analyzed
Tenable, Inc. Security Center — Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0259   84.0     —
AFFECTED
  Product          Versions     Fixed
  Security Center  unspecified  Patch SC202607.1
TIMELINE
  Jul 20  Reserved by CNA
  Jul 21  Published (CNA: tenable)
CWE-78 · CNA: tenable · 1 reference · NVD status: Analyzed
Autel MaxiCharger Single — Command Injection via Malicious OCPP Server
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.5   .0229   81.7     —
AFFECTED
  Product             Versions     Fixed
  MaxiCharger Single  unspecified  —
TIMELINE
  May 19  Reserved by CNA
  Jul 21  Published (CNA: CyberDanube)
CWE-78 · CNA: CyberDanube · 1 reference · NVD status: Analyzed
Hewlett Packard Enterprise (HPE) EdgeConnect SD-WAN Gateway (ECOS) — Authenticated Command Injection allows arbitrary command execution in CLI Interface
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0165   74.5     —
AFFECTED
  Product                            Versions   Fixed
  EdgeConnect SD-WAN Gateway (ECOS)  9.4.0.0 –  —
TIMELINE
  May 7   Reserved by CNA
  Jul 21  Published (CNA: hpe)
CWE-77 · CNA: hpe · 1 reference · NVD status: Awaiting Analysis
Tenable, Inc. Security Center — Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0144   71.0     —
AFFECTED
  Product          Versions     Fixed
  Security Center  unspecified  Patch SC202607.1
TIMELINE
  Jul 20  Reserved by CNA
  Jul 21  Published (CNA: tenable)
CWE-78 · CNA: tenable · 1 reference · NVD status: Analyzed
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0128   67.6     —
AFFECTED
  Product  Versions                Fixed
  Serv-U   15.5.4 HF1 and below –  —
TIMELINE
  Feb 26  Reserved by CNA
  Jul 21  Published (CNA: SolarWinds)
CWE-639 · CNA: SolarWinds · 2 references · NVD status: Analyzed
D-Link DNS-1550-04 remote_backup.cgi cgi_check_rsync_rw command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0106   61.6     —
AFFECTED
  Product    Versions    Fixed
  DNS-120    20260205 –  —
  DNR-202L   20260205 –  —
  DNS-315L   20260205 –  —
  DNS-320    20260205 –  —
  DNS-320L   20260205 –  —
  DNS-320LW  20260205 –  —
  DNS-321    20260205 –  —
  DNR-322L   20260205 –  —
  DNS-323    20260205 –  —
  DNS-325    20260205 –  —
  + 10 more
TIMELINE
  Jul 21  Reserved by CNA
  Jul 21  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 6 references · NVD status: Deferred
QUSETIONS MiniCode-Python Project File config.py subprocess.Popen os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   P   L   L   L    1.3   .0100   60.1     —
AFFECTED
  Product          Versions  Fixed
  MiniCode-Python  0.1.0 –   0.1.0-rc1
TIMELINE
  Jul 21  Reserved by CNA
  Jul 21  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 10 references · NVD status: Deferred
Red Hat Red Hat Enterprise Linux 8 — Dracut: dracut: root code execution via dhcp options command injection in networkmanager initrd module
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   A   H   N   N  U  H  H  H    7.5   .0099   59.6     —
AFFECTED
  Product                                 Versions     Fixed
  Red Hat Enterprise Linux 8              unspecified  0:049-244.git20260529.el8_10
  Red Hat Hardened Images                 unspecified  109-7.hum1
  Red Hat Enterprise Linux 10             unspecified  —
  Red Hat Enterprise Linux 6              unspecified  —
  Red Hat Enterprise Linux 7              unspecified  —
  Red Hat Enterprise Linux 9              unspecified  —
  Red Hat OpenShift Container Platform 4  unspecified  —
TIMELINE
  Jul 21  Reserved by CNA
  Jul 21  Published (CNA: redhat)
CWE-78 · CNA: redhat · 6 references · NVD status: Awaiting Analysis
Zyxel AX7501-B1 firmware — A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Z…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0095   58.3     —
AFFECTED
  Product             Versions               Fixed
  AX7501-B1 firmware  <= 5.17(ABPC.7.2)C0 –  —
TIMELINE
  Apr 24  Reserved by CNA
  Jul 21  Published (CNA: Zyxel)
CWE-78 · CNA: Zyxel · 1 reference · NVD status: Awaiting Analysis
frangoteam FUXA — FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0086   55.5     —
AFFECTED
  Product  Versions              Fixed
  FUXA     >= 1.2.11, < 1.3.1 –  —
TIMELINE
  May 4   Reserved by CNA
  Jul 21  Published (CNA: GitHub_M)
CWE-94, CWE-284, CWE-288, CWE-863 · CNA: GitHub_M · 2 references · NVD status: Deferred
getgrav grav — Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0084   54.8     —
AFFECTED
  Product  Versions     Fixed
  grav     unspecified  2.0.7
TIMELINE
  Jul 21  Reserved by CNA
  Jul 21  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · 2 references · NVD status: Deferred
NASA-AMMOS AIT-Core — NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0080   53.7     —
AFFECTED
  Product   Versions   Fixed
  AIT-Core  < 2.6.1 –  —
TIMELINE
  May 19  Reserved by CNA
  Jul 21  Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · 3 references · NVD status: Deferred
MervinPraison PraisonAI — PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0078   52.9     —
AFFECTED
  Product    Versions    Fixed
  PraisonAI  < 4.6.40 –  —
TIMELINE
  May 19  Reserved by CNA
  Jul 21  Published (CNA: GitHub_M)
CWE-95, CWE-306 · CNA: GitHub_M · 3 references · NVD status: Deferred
Autel MaxiCharger Single — Unauthenticated RCE
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0077   52.5     —
AFFECTED
  Product             Versions     Fixed
  MaxiCharger Single  unspecified  —
TIMELINE
  May 19  Reserved by CNA
  Jul 21  Published (CNA: CyberDanube)
CWE-94 · CNA: CyberDanube · 1 reference · NVD status: Analyzed
D-Link DNS-320 uploadify.php unrestricted upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0073   51.2     —
AFFECTED
  Product  Versions  Fixed
  DNS-320  1.0.2 –   —
TIMELINE
  Jul 20  Reserved by CNA
  Jul 21  Published (CNA: VulDB)
CWE-284, CWE-434 · CNA: VulDB · 6 references · NVD status: Deferred
D-Link DNS-320 save_ajax.php unrestricted upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0073   51.2     —
AFFECTED
  Product  Versions  Fixed
  DNS-320  1.0.2 –   —
TIMELINE
  Jul 20  Reserved by CNA
  Jul 21  Published (CNA: VulDB)
CWE-284, CWE-434 · CNA: VulDB · 6 references · NVD status: Deferred
D-Link DNS-320 multi_uploadify.php unrestricted upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0073   51.2     —
AFFECTED
  Product  Versions  Fixed
  DNS-320  1.0.2 –   —
TIMELINE
  Jul 21  Reserved by CNA
  Jul 21  Published (CNA: VulDB)
CWE-284, CWE-434 · CNA: VulDB · 6 references · NVD status: Deferred
frangoteam FUXA — FUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorization Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0067   48.8     —
AFFECTED
  Product  Versions   Fixed
  FUXA     = 1.3.0 –  —
TIMELINE
  May 4   Reserved by CNA
  Jul 21  Published (CNA: GitHub_M)
CWE-863 · CNA: GitHub_M · 4 references · NVD status: Deferred
n/a n/a — Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_d…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0066   48.6     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Mar 4   Reserved by CNA
  Jul 21  Published (CNA: mitre)
CWE-22 · CNA: mitre · 2 references · NVD status: Deferred
n/a n/a — Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and upd…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0066   48.6     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Mar 4   Reserved by CNA
  Jul 21  Published (CNA: mitre)
CWE-22 · CNA: mitre · 2 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-646069.847.5Apache Software FoundationApache ForyCWE-502Apache Fory, Apache Fory: Class-registration bypass through an auto-admitted …
CVE-2026-164891.947.0n/ajsforceCWE-77jsforce SFDX Connection Registry sfdx.js _execCommand os command injection
CVE-2026-558518.746.4nettynettyCWE-400Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder …
CVE-2026-567458.746.4nettynettyCWE-400Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native M…
CVE-2026-473929.946.0MervinPraisonPraisonAICWE-184PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module l…
CVE-2026-17717.245.2oyatekMapSVG – Vector maps, Image maps, Google MapsCWE-20MapSVG <= 8.14.0 - Authenticated (Administrator+) Arbitrary File Upload via '…
CVE-2026-648249.344.8home-assistantHome Assistant CoreCWE-22Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore
CVE-2026-653158.744.6OllamaOllamaCWE-789Ollama Remote Denial of Service via Attacker-Controlled Allocation in GGUF Me…
CVE-2026-283029.143.8SolarWindsServ-UCWE-639SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVE-2026-634547.243.3Hewlett Packard Enterprise (HPE)AOS-CXCWE-22Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in …
CVE-2026-283049.143.3SolarWindsServ-UCWE-284SolarWinds Serv-U Remote Code Execution Vulnerability
CVE-2026-283059.143.3SolarWindsServ-UCWE-639SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVE-2026-283089.143.3SolarWindsServ-UCWE-639SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVE-2026-648789.443.0Tenable, Inc.Security CenterCWE-78Command Injection
CVE-2026-439467.743.0frangoteamFUXACWE-863FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue
CVE-2026-163295.542.9D-LinkDNS-320CWE-284D-Link DNS-320 uploadify.php unrestricted upload
CVE-2026-163325.542.9D-LinkDNS-320CWE-284D-Link DNS-320 multi_uploadify.php unrestricted upload
CVE-2026-448808.842.2Hewlett Packard Enterprise (HPE)AOS-CXCWE-120Low-Privilege Authenticated Buffer Overflow Vulnerabilities lead to Remote Co…
CVE-2026-598436.542.1Red HatRed Hat Enterprise Linux 10CWE-835Libssh: libssh: denial of service via zero advertised channel packet size
CVE-2026-598446.542.1Red HatRed Hat Enterprise Linux 10CWE-789Libssh: libssh: denial of service via oversized sftp read length
CVE-2026-601989.841.9Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-602059.841.9Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-602929.841.9Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-568167.541.9nettynettyCWE-400Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types
CVE-2026-89879.441.3AutelMaxiCharger SingleCWE-122Authenticated Heap Overflow
CVE-2026-602009.841.0Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-602029.841.0Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-602049.841.0Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-602919.841.0Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-602949.841.0Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-507588.140.9n/an/aCWE-79Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allo…
CVE-2026-306319.840.4n/an/aCWE-78An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309a…
CVE-2026-602069.939.7Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-607867.239.7Oracle CorporationOracle ReceivablesCWE-284Vulnerability in the Oracle Receivables product of Oracle E-Business Suite (c…
CVE-2026-609007.239.7Oracle CorporationOracle HCM Configuration WorkbenchCWE-269Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-B…
CVE-2026-609187.239.7Oracle CorporationOracle Shipping ExecutionCWE-269Vulnerability in the Oracle Shipping Execution product of Oracle E-Business S…
CVE-2026-609257.239.7Oracle CorporationOracle Public Sector PayrollCWE-269Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Busines…
CVE-2026-609267.239.7Oracle CorporationOracle Public Sector PayrollCWE-284Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Busines…
CVE-2026-610067.239.7Oracle CorporationOracle Process Manufacturing LogisticsCWE-269Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle…
CVE-2026-611409.839.6Oracle CorporationOracle WebCenter SitesCWE-284Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-648259.039.5home-assistantHome Assistant CoreCWE-22Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload
CVE-2026-653179.239.4WeaviateVerbaCWE-918Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Ori…
CVE-2026-31837.139.4ZohocorpManageEngine ADSelfService PlusCWE-290Multi Factor Auth Bypass
CVE-2026-646089.839.4Apache Software FoundationApache ForyCWE-502Apache Fory: Heap type confusion and out-of-bounds read/write in C++ compatib…
CVE-2026-646099.139.1Apache Software FoundationApache ForyCWE-125Apache Fory, Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy…
CVE-2026-6021710.038.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602259.838.9Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-605519.838.9Oracle CorporationOracle WebCenter SitesCWE-200Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-470409.138.9Oracle CorporationOracle Net ServicesCWE-306Vulnerability in the Oracle Net Services component of Oracle Database Server.…
CVE-2026-6035810.038.9Oracle CorporationOracle Access ManagerCWE-284Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-6036010.038.9Oracle CorporationOracle Unified DirectoryCWE-306Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-6037910.038.9Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-6038910.038.9Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-352909.838.9Oracle CorporationOracle Application Testing SuiteCWE-284Vulnerability in Oracle Application Testing Suite. The supported version that…
CVE-2026-468769.838.9Oracle CorporationOracle Application Testing SuiteCWE-284Vulnerability in Oracle Application Testing Suite. The supported version that…
CVE-2026-469839.838.9Oracle CorporationOracle Retail Integration BusCWE-284Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail A…
CVE-2026-601739.838.9Oracle CorporationOracle BI PublisherCWE-284Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone…
CVE-2026-601979.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602099.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602109.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602129.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602159.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602169.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602199.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602249.838.9Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602269.838.9Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602279.838.9Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602289.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602299.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602309.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602349.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602369.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602409.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602429.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602479.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602539.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602549.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602569.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602579.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602589.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602599.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602629.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602729.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602749.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602759.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602809.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602859.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602869.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602879.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602889.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602899.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602909.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602969.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602979.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602989.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602999.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-603009.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-603029.838.9Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-603559.838.9Oracle CorporationOracle Access ManagerCWE-306Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-603629.838.9Oracle CorporationOracle Unified DirectoryCWE-306Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-603759.838.9Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-603769.838.9Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-603789.838.9Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-603849.838.9Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-603859.838.9Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-603869.838.9Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-604429.838.9Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-605329.838.9Oracle CorporationOracle Identity Manager ConnectorCWE-269Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi…
CVE-2026-605359.838.9Oracle CorporationOracle Identity Manager ConnectorCWE-306Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi…
CVE-2026-605389.838.9Oracle CorporationOracle SOA SuiteCWE-306Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co…
CVE-2026-605419.838.9Oracle CorporationOracle SOA SuiteCWE-284Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co…
CVE-2026-605559.838.9Oracle CorporationOracle WebCenter SitesCWE-200Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-610659.838.9Oracle CorporationOracle Access ManagerCWE-287Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-611009.838.9Oracle CorporationOracle WebCenter Enterprise CaptureCWE-306Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-611299.838.9Oracle CorporationOracle Commerce PlatformCWE-287Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com…
CVE-2026-611319.838.9Oracle CorporationOracle Commerce PlatformCWE-284Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com…
CVE-2026-611459.838.9Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-611619.838.9Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-611679.838.9Oracle CorporationOracle Agile PLMCWE-284Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone…
CVE-2026-611789.838.9Oracle CorporationOracle Agile Product Lifecycle Management for ProcessCWE-287Vulnerability in the Oracle Agile Product Lifecycle Management for Process pr…
CVE-2026-611839.838.9Oracle CorporationOracle Agile Product Lifecycle Management for ProcessCWE-287Vulnerability in the Oracle Agile Product Lifecycle Management for Process pr…
CVE-2026-611969.838.9Oracle CorporationOracle Identity ManagerCWE-306Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-612339.838.9Oracle CorporationPeopleSoft Enterprise FIN Common Objects BrazilCWE-200Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product …
CVE-2026-611559.138.9Oracle CorporationOracle Commerce Guided Search Platform ServicesCWE-284Vulnerability in the Oracle Commerce Guided Search Platform Services product …
CVE-2026-605297.238.4Oracle CorporationOracle WebLogic ServerCWE-284Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-507577.838.3n/an/aCWE-22Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allow…
CVE-2026-470577.538.2Oracle CorporationOracle Java SECWE-400Vulnerability in Oracle Java SE (component: Scripting). Supported versions th…
CVE-2026-601807.538.2Oracle CorporationMySQL ConnectorsCWE-400Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Con…
CVE-2026-602089.138.1Oracle CorporationOracle WebLogic ServerCWE-400Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-507597.538.2n/an/aCWE-306An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privi…
CVE-2026-608457.238.2Oracle CorporationOracle Mobile Application ServerCWE-284Vulnerability in the Oracle Mobile Application Server product of Oracle E-Bus…
CVE-2026-591449.838.0EGORData::RingBuffer::SharedCWE-121Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer o…
CVE-2026-612359.137.6Oracle CorporationPeopleSoft Enterprise HCM Global Payroll SwitzerlandCWE-284Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland pro…
CVE-2026-469547.237.6Oracle CorporationOracle Human ResourcesCWE-284Vulnerability in the Oracle Human Resources product of Oracle E-Business Suit…
CVE-2026-601537.237.6Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-603457.237.6Oracle CorporationOracle JDeveloperCWE-284Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (c…
CVE-2026-604667.237.6Oracle CorporationWebCenter Content: ImagingCWE-284Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd…
CVE-2026-605027.237.6Oracle CorporationWebCenter Content: ImagingCWE-284Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd…
CVE-2026-605197.237.6Oracle CorporationOracle Unified DirectoryCWE-284Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-605467.237.6Oracle CorporationOracle SOA SuiteCWE-269Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co…
CVE-2026-605767.237.6Oracle CorporationOracle Enterprise Command Center FrameworkCWE-269Vulnerability in the Oracle Enterprise Command Center Framework product of Or…
CVE-2026-606457.237.6Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-608287.237.6Oracle CorporationOracle Interaction BlendingCWE-284Vulnerability in the Oracle Interaction Blending product of Oracle E-Business…
CVE-2026-610257.237.6Oracle CorporationOracle iRecruitmentCWE-284Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (…
CVE-2026-610357.237.6Oracle CorporationOracle Financials for the AmericasCWE-284Vulnerability in the Oracle Financials for the Americas product of Oracle E-B…
CVE-2026-610397.237.6Oracle CorporationOracle Advanced Supply Chain PlanningCWE-284Vulnerability in the Oracle Advanced Supply Chain Planning product of Oracle …
CVE-2026-610687.237.5Oracle CorporationPeopleSoft Enterprise FIN Billing ArgentinaCWE-284Vulnerability in the PeopleSoft Enterprise FIN Billing Argentina product of O…
CVE-2026-610947.237.6Oracle CorporationMySQL ServerCWE-269Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com…
CVE-2026-611077.237.6Oracle CorporationOracle Applications DBACWE-269Vulnerability in the Oracle Applications DBA product of Oracle E-Business Sui…
CVE-2026-611157.237.6Oracle CorporationOracle Order ManagementCWE-284Vulnerability in the Oracle Order Management product of Oracle E-Business Sui…
CVE-2026-613147.237.6Oracle CorporationOracle EDI GatewayCWE-284Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (c…
CVE-2026-613367.237.6Oracle CorporationOracle Lease and Finance ManagementCWE-269Vulnerability in the Oracle Lease and Finance Management product of Oracle E-…
CVE-2026-624667.237.6Oracle CorporationOracle Human ResourcesCWE-284Vulnerability in the Oracle Human Resources product of Oracle E-Business Suit…
CVE-2026-470187.537.4Oracle CorporationSiebel CRM Cloud ApplicationsCWE-400Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-602527.537.4Oracle CorporationOracle CoherenceCWE-400Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-603017.537.4Oracle CorporationOracle CoherenceCWE-400Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-603827.537.4Oracle CorporationService Delivery PlatformCWE-400Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-472477.537.2strukturaglibheifCWE-200libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninit…
CVE-2026-568527.537.1golang.org/x/textgolang.org/x/text/unicode/normCWE-835Infinite loop on invalid input in golang.org/x/text
CVE-2026-283149.137.0SolarWindsServ-UCWE-639SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVE-2026-612119.936.6Oracle CorporationOracle Database ServerCWE-284Vulnerability in the RDBMS component of Oracle Database Server. Supported ver…
CVE-2026-163639.836.3MozillaFirefoxCWE-682JIT miscompilation in the JavaScript: WebAssembly component
CVE-2026-163699.836.3MozillaFirefoxCWE-190Integer overflow in the JavaScript: WebAssembly component
CVE-2026-163899.836.3MozillaFirefoxCWE-190Incorrect boundary conditions, integer overflow in the Libraries component in…
CVE-2026-606788.836.0Oracle CorporationOracle General LedgerCWE-269Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite…
CVE-2026-607898.836.0Oracle CorporationOracle Sales OfflineCWE-284Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite …
CVE-2026-608638.836.0Oracle CorporationOracle Advanced PricingCWE-269Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Sui…
CVE-2026-608728.836.0Oracle CorporationOracle Order ManagementCWE-269Vulnerability in the Oracle Order Management product of Oracle E-Business Sui…
CVE-2026-608908.836.0Oracle CorporationOracle PayrollCWE-269Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (compo…
CVE-2026-608978.836.0Oracle CorporationOracle PayrollCWE-269Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (compo…
CVE-2026-609018.836.0Oracle CorporationOracle Project IntelligenceCWE-269Vulnerability in the Oracle Project Intelligence product of Oracle E-Business…
CVE-2026-609208.836.0Oracle CorporationOracle Customer CareCWE-269Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite …
CVE-2026-609248.836.0Oracle CorporationOracle Public Sector PayrollCWE-269Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Busines…
CVE-2026-609328.836.0Oracle CorporationOracle Labor DistributionCWE-269Vulnerability in the Oracle Labor Distribution product of Oracle E-Business S…
CVE-2026-609528.836.0Oracle CorporationOracle Transportation ExecutionCWE-269Vulnerability in the Oracle Transportation Execution product of Oracle E-Busi…
CVE-2026-609898.836.0Oracle CorporationOracle Advanced CollectionsCWE-306Vulnerability in the Oracle Advanced Collections product of Oracle E-Business…
CVE-2026-610108.836.0Oracle CorporationOracle Process Manufacturing SystemsCWE-269Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E…
CVE-2026-607347.235.9Oracle CorporationOracle Trading CommunityCWE-284Vulnerability in the Oracle Trading Community product of Oracle E-Business Su…
CVE-2026-470524.935.9Oracle CorporationMySQL ServerCWE-400Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com…
CVE-2026-601714.935.9Oracle CorporationMySQL ClusterCWE-400Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Server…
CVE-2026-611444.935.9Oracle CorporationMySQL ServerCWE-400Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com…
CVE-2026-898310.035.7AutelMaxiCharger SingleCWE-798Backdoor Authentication Token
CVE-2026-473948.735.6MervinPraisonPraisonAICWE-22PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.…
CVE-2026-476677.535.5GreycLabCImgCWE-401CImg Library: Uncontrolled Memory Allocation and Memory Leak in `_load_analyz…
CVE-2026-507559.835.5n/an/aCWE-290An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to ob…
CVE-2026-612039.435.4Oracle CorporationPeopleSoft Enterprise FIN ExpensesCWE-269Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle Peo…
CVE-2026-611759.335.4Oracle CorporationOracle Product Lifecycle AnalyticsCWE-200Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Sup…
CVE-2026-653189.235.4WeaviateVerbaCWE-918Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket…
CVE-2026-605448.235.4Oracle CorporationOracle SOA SuiteCWE-306Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co…
CVE-2026-600807.335.4Apache Software FoundationApache ForyCWE-416Apache Fory: Rust MetaString heap use-after-free
CVE-2026-607186.535.3Oracle CorporationMySQL ServerCWE-400Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com…
CVE-2026-598425.335.0Red HatRed Hat Hardened ImagesCWE-125Libssh: libssh: information disclosure via short gssapi curve25519 public key
CVE-2026-602938.634.9Oracle CorporationOracle WebLogic ServerCWE-200Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-605568.634.9Oracle CorporationOracle WebCenter SitesCWE-200Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-601677.534.9Oracle CorporationOracle Hospitality SimphonyCWE-200Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and B…
CVE-2026-605547.534.9Oracle CorporationOracle WebCenter SitesCWE-200Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-611337.534.9Oracle CorporationOracle Commerce PlatformCWE-200Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com…
CVE-2026-611597.534.9Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-200Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-159578.734.8AWSaws-sdk-rustCWE-770Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserialize…
CVE-2026-591479.834.7EGORData::DisjointSet::SharedCWE-125Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds r…
CVE-2026-591459.134.7EGORData::Intern::SharedCWE-125Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds rea…
CVE-2026-601689.134.7Oracle CorporationOracle Hospitality SimphonyCWE-284Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and B…
CVE-2026-602237.534.7Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602078.834.5Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-603438.834.5Oracle CorporationOracle WebLogic ServerCWE-284Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-606897.534.5Oracle CorporationSiebel CRM Cloud ApplicationsCWE-306Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-448787.234.4Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateway (ECOS)CWE-377Authenticated Path Traversal allows Unauthorized Access in Web Interface
CVE-2026-164845.534.4SourceCodesterClass and Exam Timetabling SystemCWE-74SourceCodester Class and Exam Timetabling System edit_subjecta.php sql injection
CVE-2026-283219.134.1SolarWindsServ-UCWE-284SolarWinds Serv-U Broken Access Control Vulnerability
CVE-2026-163509.833.7MozillaFirefoxCWE-119Incorrect boundary conditions in the Audio/Video: cubeb component
CVE-2026-163539.833.7MozillaFirefoxCWE-416Invalid pointer in the DOM: Bindings (WebIDL) component
CVE-2026-163559.833.7MozillaFirefoxCWE-843JIT miscompilation in the JavaScript Engine: JIT component
CVE-2026-163579.833.7MozillaFirefoxCWE-119Incorrect boundary conditions in the Graphics component
CVE-2026-611766.733.8Oracle CorporationOracle Product Lifecycle AnalyticsCWE-269Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Sup…
CVE-2026-601746.533.7Oracle CorporationMySQL ServerCWE-400Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com…
CVE-2026-602436.533.7Oracle CorporationOracle CoherenceCWE-400Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-604046.533.7Oracle CorporationTimesTen In-Memory DatabaseCWE-400Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen I…
CVE-2026-610936.533.7Oracle CorporationMySQL ServerCWE-400Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com…
CVE-2026-611096.533.7Oracle CorporationMySQL ServerCWE-400Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com…
CVE-2026-611946.533.7Oracle CorporationOracle Agile Engineering Data ManagementCWE-400Vulnerability in the Oracle Agile Engineering Data Management product of Orac…
CVE-2026-611956.533.7Oracle CorporationOracle Agile Engineering Data ManagementCWE-400Vulnerability in the Oracle Agile Engineering Data Management product of Orac…
CVE-2026-605429.933.5Oracle CorporationOracle Business Process Management SuiteCWE-284Vulnerability in the Oracle Business Process Management Suite product of Orac…
CVE-2026-605619.933.5Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-605659.933.5Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-473939.833.6MervinPraisonPraisonAICWE-306PraisonAI `deploy --type api` emits a Flask server with authentication disabl…
CVE-2026-601578.833.5Oracle CorporationOracle GoldenGateCWE-284Vulnerability in Oracle GoldenGate (component: Service Manager). Supported ve…
CVE-2026-601758.833.5Oracle CorporationOracle Database ServerCWE-269Vulnerability in the RDBMS component of Oracle Database Server. Supported ver…
CVE-2026-602038.833.5Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-603988.833.5Oracle CorporationOracle GoldenGateCWE-306Vulnerability in Oracle GoldenGate (component: Oracle GoldenGate Microservice…
CVE-2026-606768.833.5Oracle CorporationOracle Applications FrameworkCWE-284Vulnerability in the Oracle Applications Framework product of Oracle E-Busine…
CVE-2026-606928.833.5Oracle CorporationOracle Enterprise Asset ManagementCWE-284Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-B…
CVE-2026-608298.833.5Oracle CorporationOracle Advanced Outbound TelephonyCWE-284Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-B…
CVE-2026-613118.833.5Oracle CorporationOracle Product HubCWE-306Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c…
CVE-2026-613228.833.5Oracle CorporationTeleSalesCWE-269Vulnerability in the TeleSales product of Oracle E-Business Suite (component:…
CVE-2026-603339.933.5Oracle CorporationOracle Access ManagerCWE-287Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-603619.933.4Oracle CorporationOracle Unified DirectoryCWE-306Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-604569.933.5Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-604579.933.4Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-604589.933.4Oracle CorporationOracle WebCenter Enterprise CaptureCWE-306Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-604599.933.4Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-604619.933.5Oracle CorporationOracle WebCenter Enterprise CaptureCWE-306Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-605249.933.4Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-605319.933.4Oracle CorporationOracle Identity Manager ConnectorCWE-306Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi…
CVE-2026-605379.933.4Oracle CorporationOracle Managed File TransferCWE-306Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Mi…
CVE-2026-605479.933.4Oracle CorporationOracle Managed File TransferCWE-284Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Mi…
CVE-2026-605529.933.4Oracle CorporationOracle WebCenter SitesCWE-200Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-606279.933.4Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-306Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-607119.933.4Oracle CorporationSiebel CRM Cloud ApplicationsCWE-306Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-610419.933.4Oracle CorporationOracle Demantra Demand ManagementCWE-284Vulnerability in the Oracle Demantra Demand Management product of Oracle Supp…
CVE-2026-610729.933.4Oracle CorporationPeopleSoft Enterprise FIN Staffing Front Office BrazilCWE-284Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office Brazil p…
CVE-2026-610769.933.5Oracle CorporationPeopleSoft Enterprise HCM Talent Acquisition ManagerCWE-269Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager pro…
CVE-2026-611469.933.5Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-269Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-612099.933.4Oracle CorporationPeopleSoft In-Memory Project DiscoveryCWE-269Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle…
CVE-2026-469928.833.4Oracle CorporationOracle Enterprise Manager Base PlatformCWE-306Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-469958.833.5Oracle CorporationOracle Enterprise Manager Base PlatformCWE-269Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-470048.833.5Oracle CorporationOracle Enterprise Manager Base PlatformCWE-306Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-470318.833.5Oracle CorporationOracle Bills of MaterialCWE-284Vulnerability in the Oracle Bills of Material product of Oracle E-Business Su…
CVE-2026-602688.833.5Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-603348.833.5Oracle CorporationOracle WebCenter ContentCWE-306Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-604308.833.4Oracle CorporationOracle Unified DirectoryCWE-284Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-604658.833.4Oracle CorporationWebCenter Content: ImagingCWE-284Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd…
CVE-2026-604938.833.5Oracle CorporationJD Edwards EnterpriseOne Human Resources ManagementCWE-306Vulnerability in the JD Edwards EnterpriseOne Human Resources Management prod…
CVE-2026-604998.833.4Oracle CorporationJD Edwards EnterpriseOne Solution AdvisorCWE-306Vulnerability in the JD Edwards EnterpriseOne Solution Advisor product of Ora…
CVE-2026-605038.833.5Oracle CorporationWebCenter Content: ImagingCWE-284Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd…
CVE-2026-605398.833.5Oracle CorporationOracle SOA SuiteCWE-306Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co…
CVE-2026-605458.833.5Oracle CorporationOracle Managed File TransferCWE-306Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Mi…
CVE-2026-605498.833.4Oracle CorporationOracle Managed File TransferCWE-306Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Mi…
CVE-2026-605838.833.5Oracle CorporationOracle Transportation ManagementCWE-269Vulnerability in the Oracle Transportation Management product of Oracle Suppl…
CVE-2026-605948.833.5Oracle CorporationPeopleSoft Enterprise CS Campus CommunityCWE-284Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Ora…
CVE-2026-606028.833.4Oracle CorporationPeopleSoft Enterprise CS Student FinancialsCWE-306Vulnerability in the PeopleSoft Enterprise CS Student Financials product of O…
CVE-2026-606038.833.4Oracle CorporationPeopleSoft Enterprise CS Student RecordsCWE-20Vulnerability in the PeopleSoft Enterprise CS Student Records product of Orac…
CVE-2026-606188.833.5Oracle CorporationJD Edwards EnterpriseOne Procurement and Subcontract ManagementCWE-306Vulnerability in the JD Edwards EnterpriseOne Procurement and Subcontract Man…
CVE-2026-606558.833.5Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-606568.833.4Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-607388.833.4Oracle CorporationOracle Installed BaseCWE-284Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite…
CVE-2026-607838.833.5Oracle CorporationOracle iReceivablesCWE-284Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (…
CVE-2026-610988.833.5Oracle CorporationOracle WebCenter Enterprise CaptureCWE-269Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-610998.833.5Oracle CorporationOracle WebCenter Enterprise CaptureCWE-269Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-611108.833.4Oracle CorporationOracle Applications DBACWE-269Vulnerability in the Oracle Applications DBA product of Oracle E-Business Sui…
CVE-2026-611218.833.4Oracle CorporationOracle HRMS (UK)CWE-269Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (com…
CVE-2026-611278.833.4Oracle CorporationOracle Communications Service Catalog and DesignCWE-269Vulnerability in the Oracle Communications Service Catalog and Design product…
CVE-2026-611498.833.5Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-269Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-611668.833.4Oracle CorporationOracle Agile PLMCWE-284Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone…
CVE-2026-611688.833.4Oracle CorporationOracle Agile PLMCWE-269Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone…
CVE-2026-611798.833.4Oracle CorporationOracle Agile Product Lifecycle Management for ProcessCWE-269Vulnerability in the Oracle Agile Product Lifecycle Management for Process pr…
CVE-2026-611808.833.5Oracle CorporationOracle Agile Product Lifecycle Management for ProcessCWE-269Vulnerability in the Oracle Agile Product Lifecycle Management for Process pr…
CVE-2026-612438.833.5Oracle CorporationPeopleSoft Enterprise FIN Common Objects ArgentinaCWE-269Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina produ…
CVE-2026-612898.833.4Oracle CorporationOracle Process Manufacturing Product DevelopmentCWE-284Vulnerability in the Oracle Process Manufacturing Product Development product…
CVE-2026-613208.833.4Oracle CorporationOracle PayablesCWE-269Vulnerability in the Oracle Payables product of Oracle E-Business Suite (comp…
CVE-2026-624478.833.5Oracle CorporationOracle Trade ManagementCWE-306Vulnerability in the Oracle Trade Management product of Oracle E-Business Sui…
CVE-2026-611608.133.4Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-20Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-601767.133.4Oracle CorporationOracle PaymentsCWE-200Vulnerability in the Oracle Payments product of Oracle E-Business Suite (comp…
CVE-2026-134399.833.3hassantafreshiEasy Form Builder by WhiteStudio – Drag & Drop Form BuilderCWE-269Easy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escala…
CVE-2026-283129.133.3SolarWindsServ-UCWE-285SolarWinds Serv-U Privilege Escalation Vulnerability
CVE-2026-471435.933.0capstone-enginecapstoneCWE-476Capstone has a NULL Pointer Dereference with 3DNow! opcodes
CVE-2026-601454.933.0Oracle CorporationMySQL ServerCWE-284Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com…
CVE-2026-601944.933.0Oracle CorporationMySQL ServerCWE-284Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com…
CVE-2026-601954.933.0Oracle CorporationMySQL ServerCWE-284Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com…
CVE-2026-6036510.032.9Oracle CorporationOracle HTTP ServerCWE-306Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle F…
CVE-2026-605508.632.9Oracle CorporationOracle WebCenter SitesCWE-200Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-610267.532.9Oracle CorporationOracle iRecruitmentCWE-284Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (…
CVE-2026-625217.532.9Oracle CorporationOracle HRMS (US)CWE-284Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (com…
CVE-2026-602679.132.8Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-606069.132.8Oracle CorporationPeopleSoft Enterprise CC Common Application ObjectsCWE-284Vulnerability in the PeopleSoft Enterprise CC Common Application Objects prod…
CVE-2026-606499.132.8Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-610599.132.8Oracle CorporationPeopleSoft Enterprise SCM Order ManagementCWE-284Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Or…
CVE-2026-611539.132.8Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-611569.132.8Oracle CorporationOracle Commerce Guided Search Platform ServicesCWE-284Vulnerability in the Oracle Commerce Guided Search Platform Services product …
CVE-2026-611719.132.8Oracle CorporationOracle Agile PLMCWE-284Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone…
CVE-2026-611849.132.8Oracle CorporationOracle Agile Product Lifecycle Management for ProcessCWE-284Vulnerability in the Oracle Agile Product Lifecycle Management for Process pr…
CVE-2026-611979.132.8Oracle CorporationOracle Identity ManagerCWE-284Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-603568.632.8Oracle CorporationOracle Access ManagerCWE-306Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-603598.632.8Oracle CorporationOracle Unified DirectoryCWE-306Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-605368.632.8Oracle CorporationOracle Identity Manager ConnectorCWE-284Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi…
CVE-2026-605598.632.8Oracle CorporationOracle Access ManagerCWE-284Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-601707.532.8Oracle CorporationOracle Hospitality SimphonyCWE-284Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and B…
CVE-2026-602637.532.8Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-606057.532.8Oracle CorporationPeopleSoft Enterprise CS Student RecordsCWE-306Vulnerability in the PeopleSoft Enterprise CS Student Records product of Orac…
CVE-2026-606227.532.8Oracle CorporationOracle JDeveloperCWE-284Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (c…
CVE-2026-610737.532.8Oracle CorporationPeopleSoft Enterprise FIN Common Objects BrazilCWE-284Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product …
CVE-2026-610857.532.8Oracle CorporationPeopleSoft Enterprise SCM InventoryCWE-284Vulnerability in the PeopleSoft Enterprise SCM Inventory product of Oracle Pe…
CVE-2026-610867.532.8Oracle CorporationPeopleSoft Enterprise SCM Order ManagementCWE-284Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Or…
CVE-2026-610877.532.8Oracle CorporationPeopleSoft Enterprise FIN PayablesCWE-284Vulnerability in the PeopleSoft Enterprise FIN Payables product of Oracle Peo…
CVE-2026-610887.532.8Oracle CorporationPeopleSoft Enterprise SCM ManufacturingCWE-284Vulnerability in the PeopleSoft Enterprise SCM Manufacturing product of Oracl…
CVE-2026-611577.532.8Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-611587.532.8Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-611727.532.8Oracle CorporationOracle Agile PLMCWE-284Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone…
CVE-2026-608809.832.7Oracle CorporationOracle Work in ProcessCWE-284Vulnerability in the Oracle Work in Process product of Oracle E-Business Suit…
CVE-2026-163519.832.6MozillaFirefoxCWE-416Sandbox escape due to use-after-free in the DOM: Navigation component
CVE-2026-163529.832.6MozillaFirefoxCWE-416Sandbox escape due to use-after-free in the Disability Access APIs component
CVE-2026-163569.832.6MozillaFirefoxCWE-416Sandbox escape due to use-after-free in the Disability Access APIs component
CVE-2026-610705.332.5Oracle CorporationPeopleSoft Enterprise FIN Common Objects ArgentinaCWE-400Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina produ…
CVE-2026-609237.732.4Oracle CorporationOracle CapacityCWE-200Vulnerability in the Oracle Capacity product of Oracle E-Business Suite (comp…
CVE-2026-601999.832.1Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-163689.832.0MozillaFirefoxCWE-119Incorrect boundary conditions in the JavaScript: WebAssembly component
CVE-2026-163186.932.0Amazons2n-tlsCWE-401QUIC Transport Parameters Memory Leak During HelloRetryRequest in s2n-tls
CVE-2026-607199.931.8Oracle CorporationOracle BI PublisherCWE-20Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone…
CVE-2026-163779.831.8MozillaFirefoxCWE-693Mitigation bypass in the PDF Viewer component
CVE-2026-163839.831.8MozillaFirefoxCWE-693Mitigation bypass in the DOM: Networking component
CVE-2026-611869.431.8Oracle CorporationOracle Agile Engineering Data ManagementCWE-284Vulnerability in the Oracle Agile Engineering Data Management product of Orac…
CVE-2026-608466.731.7Oracle CorporationOracle Mobile Application ServerCWE-284Vulnerability in the Oracle Mobile Application Server product of Oracle E-Bus…
CVE-2026-898210.031.6AutelMaxiCharger SingleCWE-798Hard-coded / Backdoor Accounts
CVE-2026-603069.831.5Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-603089.831.5Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-524699.831.4n/an/aCWE-89SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to es…
CVE-2026-524709.831.4n/an/aCWE-89SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to es…
CVE-2026-524729.831.4n/an/aCWE-89SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to esca…
CVE-2026-602649.831.5Oracle CorporationOracle CoherenceCWE-200Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2016-200969.331.4Kunshi Network Technology Co., Ltd.Linknat VOS3000CWE-89Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp
CVE-2026-653167.131.3xuxuelixxl-jobCWE-639xxl-job Cross-Job-Group Log Disclosure via Missing Authorization Check in /jo…
CVE-2026-473977.131.3MervinPraisonPraisonAICWE-22PraisonAI has an Arbitrary File Write in Python API
CVE-2026-609418.731.1Oracle CorporationOracle Service Fulfillment ManagerCWE-269Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-B…
CVE-2026-601656.531.1Oracle CorporationOracle Cost ManagementCWE-284Vulnerability in the Oracle Cost Management product of Oracle E-Business Suit…
CVE-2026-609786.531.1Oracle CorporationOracle ScriptingCWE-284Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (com…
CVE-2026-608626.831.1Oracle CorporationOracle Order ManagementCWE-284Vulnerability in the Oracle Order Management product of Oracle E-Business Sui…
CVE-2026-567466.531.1nettynettyCWE-284Netty has a Security Control Bypass via CORS Short-Circuit Failure
CVE-2026-604336.531.1Oracle CorporationOracle Transportation ManagementCWE-284Vulnerability in the Oracle Transportation Management product of Oracle Suppl…
CVE-2026-608436.531.1Oracle CorporationOracle Citizen Interaction CenterCWE-284Vulnerability in the Oracle Citizen Interaction Center product of Oracle E-Bu…
CVE-2026-470494.931.1Oracle CorporationPeopleSoft Enterprise PeopleToolsCWE-284Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop…
CVE-2026-163829.830.9MozillaFirefoxCWE-693Mitigation bypass in the DOM: Service Workers component
CVE-2026-613097.530.8Oracle CorporationOracle In-Memory Cost Management for Discrete IndustriesCWE-284Vulnerability in the Oracle In-Memory Cost Management for Discrete Industries…
CVE-2026-601928.130.8Oracle CorporationMySQL ConnectorsCWE-284Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Con…
CVE-2026-605487.730.7Oracle CorporationOracle SOA SuiteCWE-200Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co…
CVE-2026-610147.730.8Oracle CorporationOracle Inventory ManagementCWE-200Vulnerability in the Oracle Inventory Management product of Oracle E-Business…
CVE-2026-611257.730.8Oracle CorporationOracle Configure to OrderCWE-200Vulnerability in the Oracle Configure to Order product of Oracle E-Business S…
CVE-2026-606096.530.7Oracle CorporationPeopleSoft Enterprise CS Campus CommunityCWE-200Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Ora…
CVE-2026-606736.530.7Oracle CorporationOracle BI PublisherCWE-200Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone…
CVE-2026-608356.530.8Oracle CorporationOracle Price ProtectionCWE-200Vulnerability in the Oracle Price Protection product of Oracle E-Business Sui…
CVE-2026-612516.530.8Oracle CorporationHRMS (Australia)CWE-200Vulnerability in the HRMS (Australia) product of Oracle E-Business Suite (com…
CVE-2026-1636710.030.7MozillaFirefoxCWE-119Sandbox escape due to invalid pointer in the Disability Access APIs component
CVE-2026-163889.830.7MozillaFirefoxCWE-693Sandbox escape in the DOM: Networking component
CVE-2026-610098.030.7Oracle CorporationOracle Process Manufacturing LogisticsCWE-284Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle…
CVE-2026-524747.530.6n/an/aCWE-200An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive inf…
CVE-2026-611657.130.6Oracle CorporationOracle Commerce Guided Search Platform ServicesCWE-200Vulnerability in the Oracle Commerce Guided Search Platform Services product …
CVE-2026-608926.630.7Oracle CorporationOracle HRMS (Norway)CWE-284Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite …

Results continue: ranks 401–1477.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-21 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.