Edition of July 21, 2026, continued — page 2 of 3. Back to page 1 · page 3
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-60613 | 6.6 | 30.5 | Oracle Corporation | PeopleSoft Enterprise CS Student Records | CWE-20 | Vulnerability in the PeopleSoft Enterprise CS Student Records product of Orac… |
| CVE-2026-65319 | 8.7 | 30.2 | Feedbin | Feedbin | CWE-306 | Feedbin Unauthenticated Entry Content Disclosure via GET /api/v2/entries/:id/… |
| CVE-2026-56817 | 8.3 | 30.2 | netty | netty | CWE-611 | Netty: XML External Entity (XXE) injection via unconfigured XML factory when … |
| CVE-2026-47058 | 7.4 | 30.3 | Oracle Corporation | Oracle Java SE | CWE-502 | Vulnerability in Oracle Java SE (component: Scripting). Supported versions th… |
| CVE-2026-47009 | 6.5 | 30.1 | Oracle Corporation | Oracle Agile PLM | CWE-200 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-50756 | 7.5 | 30.0 | n/a | n/a | CWE-1390 | An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to ob… |
| CVE-2026-52476 | 7.5 | 29.9 | n/a | n/a | CWE-89 | SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to o… |
| CVE-2026-60316 | 7.2 | 29.8 | Oracle Corporation | MySQL Server | CWE-284 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-61201 | 9.0 | 29.7 | Oracle Corporation | PeopleSoft Enterprise CRM Common Objects | CWE-269 | Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Orac… |
| CVE-2026-61223 | 9.0 | 29.7 | Oracle Corporation | Oracle Communications Converged Application Server | CWE-284 | Vulnerability in the Oracle Communications Converged Application Server produ… |
| CVE-2026-60169 | 8.1 | 29.7 | Oracle Corporation | Oracle Hospitality Simphony | CWE-306 | Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and B… |
| CVE-2026-60201 | 8.1 | 29.7 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60222 | 8.1 | 29.7 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60417 | 8.1 | 29.7 | Oracle Corporation | Oracle Unified Directory | CWE-306 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60543 | 8.1 | 29.7 | Oracle Corporation | Oracle SOA Suite | CWE-306 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co… |
| CVE-2026-60558 | 8.1 | 29.7 | Oracle Corporation | Oracle WebCenter Sites | CWE-200 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-60621 | 8.1 | 29.7 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-306 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-60756 | 8.1 | 29.7 | Oracle Corporation | Oracle EDI Gateway | CWE-284 | Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (c… |
| CVE-2026-60780 | 8.1 | 29.7 | Oracle Corporation | Oracle Workflow | CWE-284 | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (comp… |
| CVE-2026-60785 | 8.1 | 29.7 | Oracle Corporation | Oracle iReceivables | CWE-284 | Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (… |
| CVE-2026-61074 | 8.1 | 29.7 | Oracle Corporation | PeopleSoft Enterprise FIN Common Objects Brazil | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product … |
| CVE-2026-61092 | 8.1 | 29.7 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-61106 | 8.1 | 29.7 | Oracle Corporation | Oracle GoldenGate | CWE-284 | Vulnerability in Oracle GoldenGate (component: Config Service Executable). Su… |
| CVE-2026-61163 | 8.1 | 29.7 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-287 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-61170 | 8.1 | 29.7 | Oracle Corporation | Oracle Agile PLM | CWE-284 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-56819 | 7.5 | 29.6 | netty | netty | CWE-400 | Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompress… |
| CVE-2026-60314 | 7.5 | 29.6 | Oracle Corporation | MySQL Router | CWE-400 | Vulnerability in the MySQL Router product of Oracle MySQL (component: Router:… |
| CVE-2026-65052 | 8.7 | 29.5 | Saturday Drive | Ninja Forms | CWE-472 | Ninja Forms Calculation and Payment Total Tampering via Fail-Open get_calc_va… |
| CVE-2026-60910 | 7.2 | 29.5 | Oracle Corporation | Oracle Property Manager | CWE-284 | Vulnerability in the Oracle Property Manager product of Oracle E-Business Sui… |
| CVE-2026-16243 | 5.7 | 29.5 | Eclipse Foundation | Eclipse OMR | CWE-125 | Eclipse OMR : arraycmp SIMD implementation does not check if the number of by… |
| CVE-2026-60255 | 8.2 | 29.4 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-46994 | 9.8 | 29.3 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-16392 | 9.1 | 29.3 | Mozilla | Firefox | CWE-670 | JIT miscompilation in the JavaScript Engine: JIT component |
| CVE-2026-16420 | 8.8 | 29.3 | Chrome | CWE-843 | Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a… | |
| CVE-2026-60840 | 8.1 | 29.3 | Oracle Corporation | Oracle Demand Signal Repository | CWE-284 | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Busi… |
| CVE-2026-60848 | 8.1 | 29.3 | Oracle Corporation | Oracle Project Contracts | CWE-284 | Vulnerability in the Oracle Project Contracts product of Oracle E-Business Su… |
| CVE-2026-60871 | 8.1 | 29.3 | Oracle Corporation | Oracle Risk Management | CWE-284 | Vulnerability in the Oracle Risk Management product of Oracle E-Business Suit… |
| CVE-2026-60948 | 8.1 | 29.3 | Oracle Corporation | Oracle Learning Management | CWE-284 | Vulnerability in the Oracle Learning Management product of Oracle E-Business … |
| CVE-2026-60951 | 8.1 | 29.3 | Oracle Corporation | Oracle Time and Labor | CWE-863 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite… |
| CVE-2026-60953 | 8.1 | 29.3 | Oracle Corporation | Oracle Telecommunications Billing Integrator | CWE-862 | Vulnerability in the Oracle Telecommunications Billing Integrator product of … |
| CVE-2026-60982 | 8.1 | 29.3 | Oracle Corporation | Oracle US Federal Human Resources | CWE-284 | Vulnerability in the Oracle US Federal Human Resources product of Oracle E-Bu… |
| CVE-2026-16376 | 7.5 | 29.3 | Mozilla | Firefox | CWE-400 | Denial-of-service in the Graphics: WebGPU component |
| CVE-2026-61237 | 9.9 | 29.2 | Oracle Corporation | PeopleSoft Enterprise FIN Common Objects Argentina | CWE-269 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina produ… |
| CVE-2026-60854 | 8.2 | 29.2 | Oracle Corporation | Oracle Quality | CWE-269 | Vulnerability in the Oracle Quality product of Oracle E-Business Suite (compo… |
| CVE-2026-60377 | 9.9 | 29.1 | Oracle Corporation | Service Delivery Platform | CWE-284 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-47410 | 9.8 | 29.1 | MervinPraison | praisonai-platform | CWE-321 | praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-… |
| CVE-2026-60788 | 8.3 | 29.1 | Oracle Corporation | Oracle Sales Offline | CWE-284 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite … |
| CVE-2026-60647 | 7.1 | 29.1 | Oracle Corporation | Oracle WebCenter Content | CWE-200 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60363 | 9.8 | 28.6 | Oracle Corporation | Oracle HTTP Server | CWE-284 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (… |
| CVE-2026-60364 | 9.8 | 28.6 | Oracle Corporation | Oracle HTTP Server | CWE-284 | Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle F… |
| CVE-2026-61249 | 6.5 | 28.6 | Oracle Corporation | Oracle Learning Management | CWE-200 | Vulnerability in the Oracle Learning Management product of Oracle E-Business … |
| CVE-2026-47056 | 10.0 | 28.5 | Oracle Corporation | Oracle Data Integrator | CWE-306 | Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middlewa… |
| CVE-2026-60644 | 10.0 | 28.5 | Oracle Corporation | Oracle WebCenter Content | CWE-306 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-46924 | 9.8 | 28.5 | Oracle Corporation | Oracle Application Testing Suite | CWE-284 | Vulnerability in Oracle Application Testing Suite. The supported version that… |
| CVE-2026-46982 | 9.8 | 28.5 | Oracle Corporation | Oracle Retail Integration Bus | CWE-284 | Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail A… |
| CVE-2026-47036 | 9.8 | 28.5 | Oracle Corporation | Siebel CRM Development | CWE-306 | Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (com… |
| CVE-2026-60221 | 9.8 | 28.5 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60232 | 9.8 | 28.5 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60241 | 9.8 | 28.5 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60244 | 9.8 | 28.5 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60246 | 9.8 | 28.5 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60250 | 9.8 | 28.5 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60251 | 9.8 | 28.5 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60269 | 9.8 | 28.5 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60276 | 9.8 | 28.5 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60278 | 9.8 | 28.5 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60279 | 9.8 | 28.5 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60328 | 9.8 | 28.5 | Oracle Corporation | Oracle Access Manager | CWE-287 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-60329 | 9.8 | 28.5 | Oracle Corporation | Oracle Identity Manager | CWE-306 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-60374 | 9.8 | 28.5 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60380 | 9.8 | 28.5 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60387 | 9.8 | 28.5 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60388 | 9.8 | 28.5 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60435 | 9.8 | 28.5 | Oracle Corporation | Oracle WebCenter Content | CWE-306 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60441 | 9.8 | 28.5 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60446 | 9.8 | 28.5 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-306 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60460 | 9.8 | 28.5 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-306 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60463 | 9.8 | 28.5 | Oracle Corporation | WebCenter Content: Imaging | CWE-306 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd… |
| CVE-2026-60566 | 9.8 | 28.5 | Oracle Corporation | Oracle WebCenter Portal | CWE-269 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-60999 | 9.8 | 28.5 | Oracle Corporation | Oracle Data Integrator | CWE-284 | Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middlewa… |
| CVE-2026-61154 | 9.8 | 28.5 | Oracle Corporation | Oracle Commerce Guided Search Platform Services | CWE-269 | Vulnerability in the Oracle Commerce Guided Search Platform Services product … |
| CVE-2026-61245 | 9.8 | 28.5 | Oracle Corporation | PeopleSoft Enterprise FIN Manufacturing Brazil | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product o… |
| CVE-2026-61130 | 9.1 | 28.5 | Oracle Corporation | Oracle Commerce Platform | CWE-284 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com… |
| CVE-2026-60211 | 8.8 | 28.5 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60261 | 8.8 | 28.5 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60580 | 8.8 | 28.5 | Oracle Corporation | Oracle Enterprise Command Center Framework | CWE-306 | Vulnerability in the Oracle Enterprise Command Center Framework product of Or… |
| CVE-2026-60233 | 4.3 | 28.5 | Oracle Corporation | Oracle Coherence | CWE-400 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60690 | 7.7 | 28.3 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-284 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-63453 | 7.2 | 28.3 | Hewlett Packard Enterprise (HPE) | AOS-CX | CWE-120 | Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution i… |
| CVE-2026-60220 | 9.3 | 28.1 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60632 | 9.3 | 28.1 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60700 | 8.1 | 28.1 | Oracle Corporation | Oracle Universal Work Queue | CWE-284 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business… |
| CVE-2026-60557 | 6.5 | 28.1 | Oracle Corporation | Oracle WebCenter Sites | CWE-200 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-60624 | 6.5 | 28.1 | Oracle Corporation | MySQL Connectors | CWE-404 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Con… |
| CVE-2026-60790 | 8.0 | 28.1 | Oracle Corporation | Oracle Sales Offline | CWE-284 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite … |
| CVE-2026-61224 | 8.0 | 28.1 | Oracle Corporation | Oracle Communications Converged Application Server | CWE-284 | Vulnerability in the Oracle Communications Converged Application Server produ… |
| CVE-2026-46600 | 7.5 | 28.1 | Go standard library | net | CWE-125 | Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage |
| CVE-2026-60178 | 6.6 | 28.1 | Oracle Corporation | MySQL Server | CWE-284 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60585 | 6.6 | 28.0 | Oracle Corporation | MySQL Server | CWE-284 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60825 | 6.6 | 28.1 | Oracle Corporation | Oracle iSupport | CWE-284 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (comp… |
| CVE-2026-60826 | 6.6 | 28.0 | Oracle Corporation | Oracle iSupport | CWE-284 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (comp… |
| CVE-2026-61328 | 6.6 | 28.0 | Oracle Corporation | Oracle Cost Management | CWE-284 | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suit… |
| CVE-2026-59139 | 9.1 | 28.0 | EGOR | Data::ReqRep::Shared | CWE-125 | Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds rea… |
| CVE-2026-61225 | 8.1 | 27.8 | Oracle Corporation | Oracle Communications Converged Application Server | CWE-269 | Vulnerability in the Oracle Communications Converged Application Server produ… |
| CVE-2026-60773 | 9.6 | 27.7 | Oracle Corporation | Oracle Application Object Library | CWE-284 | Vulnerability in the Oracle Application Object Library product of Oracle E-Bu… |
| CVE-2026-60586 | 7.7 | 27.7 | Oracle Corporation | MySQL Connectors | CWE-306 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Con… |
| CVE-2026-47396 | 9.8 | 27.6 | MervinPraison | PraisonAI | CWE-284 | PraisonAI call server exposes unauthenticated agent listing, invocation, and … |
| CVE-2026-28306 | 9.1 | 27.4 | SolarWinds | Serv-U | CWE-284 | SolarWinds Serv-U Privilege Escalation Vulnerability |
| CVE-2026-28307 | 9.1 | 27.4 | SolarWinds | Serv-U | CWE-284 | SolarWinds Serv-U Privilege Escalation Vulnerability |
| CVE-2026-28309 | 9.1 | 27.4 | SolarWinds | Serv-U | CWE-862 | SolarWinds Serv-U Broken Access Control Vulnerability |
| CVE-2026-28310 | 9.1 | 27.4 | SolarWinds | Serv-U | CWE-862 | SolarWinds Serv-U Privilege Escalation Vulnerability |
| CVE-2026-28313 | 9.1 | 27.4 | SolarWinds | Serv-U | CWE-639 | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-28317 | 9.1 | 27.4 | SolarWinds | Serv-U | CWE-639 | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-65050 | 7.1 | 27.3 | Saturday Drive | Ninja Forms | CWE-862 | Ninja Forms Missing Authorization in submissions-table Gutenberg Block Disclo… |
| CVE-2026-47012 | 4.4 | 27.3 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60177 | 4.4 | 27.3 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60182 | 4.4 | 27.3 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60184 | 4.4 | 27.3 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60185 | 4.4 | 27.3 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60186 | 4.4 | 27.3 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60187 | 4.4 | 27.3 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-47695 | 7.1 | 27.3 | cc-tweaked | CC-Tweaked | CWE-918 | CC-Tweaked has an SSRF Protection Bypass with NAT64 |
| CVE-2026-46403 | 6.3 | 27.2 | klever-io | klever-go | CWE-693 | Klever-Go KVM read-only execution can commit contract delete and upgrade side… |
| CVE-2026-16354 | 7.5 | 27.1 | Mozilla | Firefox | CWE-200 | Information disclosure in the Graphics: ImageLib component |
| CVE-2026-15724 | 8.7 | 27.0 | Progress | ShareFile Storage Zones Controller | CWE-20 | Path traversal in Progress ShareFile Storage Zones Controller (SZC) |
| CVE-2026-46988 | 7.2 | 26.8 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-47005 | 7.2 | 26.8 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-47006 | 7.2 | 26.8 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-60335 | 7.2 | 26.8 | Oracle Corporation | Oracle WebCenter Content | CWE-306 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60340 | 7.2 | 26.8 | Oracle Corporation | Oracle Project Costing | CWE-269 | Vulnerability in the Oracle Project Costing product of Oracle E-Business Suit… |
| CVE-2026-60396 | 7.2 | 26.8 | Oracle Corporation | Oracle GoldenGate | CWE-306 | Vulnerability in Oracle GoldenGate (component: Distribution Server executable… |
| CVE-2026-60418 | 7.2 | 26.8 | Oracle Corporation | Oracle Unified Directory | CWE-269 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60755 | 7.2 | 26.8 | Oracle Corporation | Oracle Assets | CWE-284 | Vulnerability in the Oracle Assets product of Oracle E-Business Suite (compon… |
| CVE-2026-60787 | 7.2 | 26.8 | Oracle Corporation | Oracle Receivables | CWE-284 | Vulnerability in the Oracle Receivables product of Oracle E-Business Suite (c… |
| CVE-2026-60813 | 7.2 | 26.8 | Oracle Corporation | Oracle iStore | CWE-284 | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (compon… |
| CVE-2026-60836 | 7.2 | 26.9 | Oracle Corporation | Oracle HCM Common Architecture | CWE-269 | Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Busin… |
| CVE-2026-61027 | 7.2 | 26.8 | Oracle Corporation | Oracle Cost Management | CWE-284 | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suit… |
| CVE-2026-61285 | 7.2 | 26.9 | Oracle Corporation | Oracle Process Manufacturing Systems | CWE-306 | Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E… |
| CVE-2026-62548 | 7.2 | 26.8 | Oracle Corporation | Oracle HRMS (US) | CWE-269 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (com… |
| CVE-2026-61207 | 9.3 | 26.7 | Oracle Corporation | PeopleSoft Enterprise SCM eProcurement | CWE-284 | Vulnerability in the PeopleSoft Enterprise SCM eProcurement product of Oracle… |
| CVE-2026-60284 | 8.2 | 26.7 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60615 | 8.2 | 26.7 | Oracle Corporation | PeopleSoft Enterprise CS Campus Community | CWE-287 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Ora… |
| CVE-2026-60668 | 8.2 | 26.7 | Oracle Corporation | PeopleSoft Enterprise HCM Human Resources | CWE-284 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Ora… |
| CVE-2026-61089 | 8.2 | 26.7 | Oracle Corporation | PeopleSoft Enterprise SCM Inventory | CWE-284 | Vulnerability in the PeopleSoft Enterprise SCM Inventory product of Oracle Pe… |
| CVE-2026-60686 | 8.1 | 26.7 | Oracle Corporation | Oracle U.S. Federal Financials | CWE-284 | Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Busin… |
| CVE-2026-60741 | 8.1 | 26.7 | Oracle Corporation | Oracle Cost Management | CWE-284 | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suit… |
| CVE-2026-60749 | 8.1 | 26.7 | Oracle Corporation | Oracle Assets | CWE-284 | Vulnerability in the Oracle Assets product of Oracle E-Business Suite (compon… |
| CVE-2026-60771 | 8.1 | 26.7 | Oracle Corporation | Oracle Complex Maintenance, Repair and Overhaul | CWE-284 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product … |
| CVE-2026-60867 | 8.1 | 26.7 | Oracle Corporation | Oracle Advanced Pricing | CWE-284 | Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Sui… |
| CVE-2026-60875 | 8.1 | 26.7 | Oracle Corporation | Oracle Trade Management | CWE-284 | Vulnerability in the Oracle Trade Management product of Oracle E-Business Sui… |
| CVE-2026-60942 | 8.1 | 26.7 | Oracle Corporation | Oracle Service Fulfillment Manager | CWE-284 | Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-B… |
| CVE-2026-60963 | 8.1 | 26.7 | Oracle Corporation | Oracle Treasury | CWE-284 | Vulnerability in the Oracle Treasury product of Oracle E-Business Suite (comp… |
| CVE-2026-60997 | 8.1 | 26.7 | Oracle Corporation | Oracle Universal Work Queue | CWE-284 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business… |
| CVE-2026-61000 | 8.1 | 26.7 | Oracle Corporation | Oracle Process Manufacturing Systems | CWE-284 | Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E… |
| CVE-2026-61004 | 8.1 | 26.7 | Oracle Corporation | Oracle Landed Cost Management | CWE-284 | Vulnerability in the Oracle Landed Cost Management product of Oracle E-Busine… |
| CVE-2026-61005 | 8.1 | 26.7 | Oracle Corporation | Oracle Process Manufacturing Logistics | CWE-284 | Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle… |
| CVE-2026-61019 | 8.1 | 26.7 | Oracle Corporation | Oracle Customers Online | CWE-284 | Vulnerability in the Oracle Customers Online product of Oracle E-Business Sui… |
| CVE-2026-61031 | 8.1 | 26.7 | Oracle Corporation | Oracle Financials Common Country | CWE-284 | Vulnerability in the Oracle Financials Common Country product of Oracle E-Bus… |
| CVE-2026-61287 | 8.1 | 26.7 | Oracle Corporation | Oracle Process Manufacturing Systems | CWE-284 | Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E… |
| CVE-2026-61310 | 8.1 | 26.7 | Oracle Corporation | Oracle Product Hub | CWE-284 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c… |
| CVE-2026-61327 | 8.1 | 26.7 | Oracle Corporation | Oracle Bills of Material | CWE-284 | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Su… |
| CVE-2026-61329 | 8.1 | 26.7 | Oracle Corporation | Oracle Price Protection | CWE-284 | Vulnerability in the Oracle Price Protection product of Oracle E-Business Sui… |
| CVE-2026-61338 | 8.1 | 26.7 | Oracle Corporation | Oracle Contracts Integration | CWE-284 | Vulnerability in the Oracle Contracts Integration product of Oracle E-Busines… |
| CVE-2026-62445 | 8.1 | 26.7 | Oracle Corporation | Oracle Order Management | CWE-284 | Vulnerability in the Oracle Order Management product of Oracle E-Business Sui… |
| CVE-2026-60750 | 7.7 | 26.7 | Oracle Corporation | Oracle Payroll | CWE-284 | Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (compo… |
| CVE-2026-61112 | 6.5 | 26.7 | Oracle Corporation | Oracle Order Management | CWE-200 | Vulnerability in the Oracle Order Management product of Oracle E-Business Sui… |
| CVE-2026-61323 | 6.5 | 26.7 | Oracle Corporation | Oracle Advanced Benefits | CWE-284 | Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Su… |
| CVE-2026-62480 | 6.5 | 26.7 | Oracle Corporation | Oracle Public Sector Financials | CWE-284 | Vulnerability in the Oracle Public Sector Financials product of Oracle E-Busi… |
| CVE-2026-60239 | 9.6 | 26.7 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60540 | 9.6 | 26.7 | Oracle Corporation | Oracle SOA Suite | CWE-284 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co… |
| CVE-2026-60564 | 9.6 | 26.7 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-59140 | 9.1 | 26.7 | EGOR | Data::SortedSet::Shared | CWE-125 | Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds … |
| CVE-2026-59141 | 9.1 | 26.7 | EGOR | Data::RadixTree::Shared | CWE-125 | Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds … |
| CVE-2026-59142 | 9.1 | 26.7 | EGOR | Data::HashMap::Shared | CWE-125 | Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds re… |
| CVE-2026-47019 | 8.1 | 26.7 | Oracle Corporation | Oracle Product Hub | CWE-306 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c… |
| CVE-2026-47028 | 8.1 | 26.7 | Oracle Corporation | Oracle Document Management and Collaboration | CWE-284 | Vulnerability in the Oracle Document Management and Collaboration product of … |
| CVE-2026-60520 | 8.1 | 26.7 | Oracle Corporation | Oracle Unified Directory | CWE-284 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60560 | 8.1 | 26.7 | Oracle Corporation | Oracle Identity Manager | CWE-284 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-60599 | 8.1 | 26.7 | Oracle Corporation | PeopleSoft Enterprise CS Student Records | CWE-287 | Vulnerability in the PeopleSoft Enterprise CS Student Records product of Orac… |
| CVE-2026-60706 | 8.1 | 26.7 | Oracle Corporation | Oracle Process Manufacturing Inventory | CWE-284 | Vulnerability in the Oracle Process Manufacturing Inventory product of Oracle… |
| CVE-2026-60714 | 8.1 | 26.7 | Oracle Corporation | Oracle Price Protection | CWE-284 | Vulnerability in the Oracle Price Protection product of Oracle E-Business Sui… |
| CVE-2026-60736 | 8.1 | 26.7 | Oracle Corporation | Oracle E-Business Intelligence | CWE-284 | Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Busin… |
| CVE-2026-60778 | 8.1 | 26.7 | Oracle Corporation | Oracle Payments | CWE-284 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (comp… |
| CVE-2026-60784 | 8.1 | 26.7 | Oracle Corporation | Oracle Trading Community | CWE-284 | Vulnerability in the Oracle Trading Community product of Oracle E-Business Su… |
| CVE-2026-60793 | 8.1 | 26.7 | Oracle Corporation | Oracle TeleSales | CWE-284 | Vulnerability in the Oracle TeleSales product of Oracle E-Business Suite (com… |
| CVE-2026-60817 | 8.1 | 26.7 | Oracle Corporation | Oracle iStore | CWE-284 | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (compon… |
| CVE-2026-60844 | 8.1 | 26.6 | Oracle Corporation | Oracle Customer Support | CWE-200 | Vulnerability in the Oracle Customer Support product of Oracle E-Business Sui… |
| CVE-2026-60877 | 8.1 | 26.7 | Oracle Corporation | Oracle Trade Management | CWE-284 | Vulnerability in the Oracle Trade Management product of Oracle E-Business Sui… |
| CVE-2026-60904 | 8.1 | 26.7 | Oracle Corporation | Oracle Installed Base | CWE-284 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite… |
| CVE-2026-60917 | 8.1 | 26.7 | Oracle Corporation | Oracle Inventory Management | CWE-284 | Vulnerability in the Oracle Inventory Management product of Oracle E-Business… |
| CVE-2026-60959 | 8.1 | 26.7 | Oracle Corporation | Oracle SDP Number Portability | CWE-284 | Vulnerability in the Oracle SDP Number Portability product of Oracle E-Busine… |
| CVE-2026-60965 | 8.1 | 26.7 | Oracle Corporation | Oracle HRMS (France) | CWE-284 | Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite … |
| CVE-2026-60966 | 8.1 | 26.7 | Oracle Corporation | Oracle Public Sector Human Resources | CWE-284 | Vulnerability in the Oracle Public Sector Human Resources product of Oracle E… |
| CVE-2026-60972 | 8.1 | 26.7 | Oracle Corporation | Oracle E-Business Tax | CWE-284 | Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite… |
| CVE-2026-60974 | 8.1 | 26.7 | Oracle Corporation | Oracle E-Business Tax | CWE-284 | Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite… |
| CVE-2026-60986 | 8.1 | 26.7 | Oracle Corporation | Oracle Project Portfolio Analysis | CWE-284 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Bu… |
| CVE-2026-61024 | 8.1 | 26.7 | Oracle Corporation | Oracle iRecruitment | CWE-284 | Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (… |
| CVE-2026-61030 | 8.1 | 26.7 | Oracle Corporation | Oracle Process Manufacturing Product Development | CWE-284 | Vulnerability in the Oracle Process Manufacturing Product Development product… |
| CVE-2026-61037 | 8.1 | 26.7 | Oracle Corporation | Oracle Loans | CWE-284 | Vulnerability in the Oracle Loans product of Oracle E-Business Suite (compone… |
| CVE-2026-61102 | 8.1 | 26.7 | Oracle Corporation | Oracle Banking Trade Finance | CWE-284 | Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial… |
| CVE-2026-61105 | 8.1 | 26.7 | Oracle Corporation | Oracle Banking Trade Finance | CWE-284 | Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial… |
| CVE-2026-61122 | 8.1 | 26.7 | Oracle Corporation | Oracle HRMS (UK) | CWE-284 | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (com… |
| CVE-2026-61333 | 8.1 | 26.7 | Oracle Corporation | Oracle Product Workbench | CWE-284 | Vulnerability in the Oracle Product Workbench product of Oracle E-Business Su… |
| CVE-2026-61335 | 8.1 | 26.7 | Oracle Corporation | Oracle Product Workbench | CWE-284 | Vulnerability in the Oracle Product Workbench product of Oracle E-Business Su… |
| CVE-2026-62468 | 8.1 | 26.6 | Oracle Corporation | Oracle Human Resources | CWE-284 | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suit… |
| CVE-2026-60683 | 7.7 | 26.7 | Oracle Corporation | Oracle Process Manufacturing Regulatory Management | CWE-284 | Vulnerability in the Oracle Process Manufacturing Regulatory Management produ… |
| CVE-2026-60425 | 7.5 | 26.6 | Oracle Corporation | Oracle Unified Directory | CWE-400 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60436 | 7.5 | 26.6 | Oracle Corporation | Oracle Unified Directory | CWE-400 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-16395 | 9.8 | 26.5 | Mozilla | Firefox | CWE-190 | Integer overflow in the Audio/Video component |
| CVE-2026-16402 | 9.8 | 26.5 | Mozilla | Firefox | CWE-190 | Integer overflow in the Graphics: ImageLib component |
| CVE-2026-16408 | 9.8 | 26.5 | Mozilla | Firefox | CWE-190 | Integer overflow in the Audio/Video: Playback component |
| CVE-2026-16418 | 8.8 | 26.3 | Chrome | CWE-121 | Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed … | |
| CVE-2026-55082 | 8.7 | 26.3 | dhis2 | dhis2-core | CWE-89 | DHIS2 SQL injection in SQL View filter values |
| CVE-2026-60855 | 7.5 | 26.3 | Oracle Corporation | Oracle Quality | CWE-269 | Vulnerability in the Oracle Quality product of Oracle E-Business Suite (compo… |
| CVE-2026-60859 | 7.5 | 26.3 | Oracle Corporation | Oracle Quoting | CWE-269 | Vulnerability in the Oracle Quoting product of Oracle E-Business Suite (compo… |
| CVE-2026-60894 | 7.5 | 26.3 | Oracle Corporation | Oracle Payroll | CWE-269 | Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (compo… |
| CVE-2026-60927 | 7.5 | 26.3 | Oracle Corporation | Oracle Public Sector Financials | CWE-269 | Vulnerability in the Oracle Public Sector Financials product of Oracle E-Busi… |
| CVE-2026-60931 | 7.5 | 26.3 | Oracle Corporation | Oracle Public Sector Financials | CWE-269 | Vulnerability in the Oracle Public Sector Financials product of Oracle E-Busi… |
| CVE-2026-60943 | 7.5 | 26.3 | Oracle Corporation | Oracle Service Fulfillment Manager | CWE-269 | Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-B… |
| CVE-2026-60988 | 7.5 | 26.3 | Oracle Corporation | Oracle Project Portfolio Analysis | CWE-269 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Bu… |
| CVE-2026-60266 | 5.9 | 26.3 | Oracle Corporation | Oracle Coherence | CWE-200 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60610 | 5.9 | 26.3 | Oracle Corporation | PeopleSoft Enterprise CS Campus Community | CWE-200 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Ora… |
| CVE-2026-16412 | 9.8 | 26.2 | Mozilla | Firefox | CWE-119 | Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 |
| CVE-2026-16421 | 8.8 | 26.0 | Chrome | CWE-20 | Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871… | |
| CVE-2026-60667 | 7.4 | 26.1 | Oracle Corporation | PeopleSoft Enterprise HCM Human Resources | CWE-284 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Ora… |
| CVE-2026-60309 | 8.8 | 25.9 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60196 | 8.4 | 25.8 | Oracle Corporation | Oracle WebLogic Server | CWE-284 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-10678 | 8.1 | 25.9 | zephyrproject | zephyr | CWE-476 | NULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding dri… |
| CVE-2026-47398 | 8.1 | 25.9 | MervinPraison | PraisonAI | CWE-94 | PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` i… |
| CVE-2026-60593 | 7.5 | 25.9 | Oracle Corporation | PeopleSoft Enterprise FIN Staffing Front Office | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office product … |
| CVE-2026-60235 | 8.6 | 25.7 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-44907 | 7.5 | 25.8 | Meta | react-server-dom-turbopack | — | A denial of service vulnerability could be triggered by sending specially cra… |
| CVE-2026-60492 | 7.1 | 25.7 | Oracle Corporation | JD Edwards EnterpriseOne HCM Foundation | CWE-269 | Vulnerability in the JD Edwards EnterpriseOne HCM Foundation product of Oracl… |
| CVE-2026-60311 | 6.5 | 25.7 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-62498 | 8.8 | 25.5 | Oracle Corporation | Oracle Flow Manufacturing | CWE-269 | Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business S… |
| CVE-2026-16360 | 9.8 | 25.5 | Mozilla | Firefox | CWE-119 | Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefo… |
| CVE-2026-61297 | 8.1 | 25.5 | Oracle Corporation | Oracle Customers Online | CWE-284 | Vulnerability in the Oracle Customers Online product of Oracle E-Business Sui… |
| CVE-2026-61301 | 8.1 | 25.5 | Oracle Corporation | Oracle Process Manufacturing Financials | CWE-284 | Vulnerability in the Oracle Process Manufacturing Financials product of Oracl… |
| CVE-2026-60179 | 7.4 | 25.4 | Oracle Corporation | MySQL Connectors | CWE-284 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Con… |
| CVE-2026-60431 | 8.6 | 25.2 | Oracle Corporation | Oracle HTTP Server | CWE-200 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (… |
| CVE-2026-60652 | 8.0 | 25.2 | Oracle Corporation | Oracle WebCenter Content | CWE-306 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60807 | 8.0 | 25.2 | Oracle Corporation | Oracle Bills of Material | CWE-284 | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Su… |
| CVE-2026-61116 | 7.5 | 25.3 | Oracle Corporation | Oracle Application Object Library | CWE-200 | Vulnerability in the Oracle Application Object Library product of Oracle E-Bu… |
| CVE-2026-47689 | 5.2 | 25.2 | FOGProject | fogproject | CWE-79 | FOGProject has stored XSS via unescaped inventory data in buildRow() rendered… |
| CVE-2026-60898 | 8.8 | 25.1 | Oracle Corporation | Oracle Warehouse Management | CWE-269 | Vulnerability in the Oracle Warehouse Management product of Oracle E-Business… |
| CVE-2026-60578 | 7.6 | 25.1 | Oracle Corporation | Oracle Enterprise Command Center Framework | CWE-287 | Vulnerability in the Oracle Enterprise Command Center Framework product of Or… |
| CVE-2026-61325 | 7.6 | 25.1 | Oracle Corporation | Oracle Advanced Benefits | CWE-284 | Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Su… |
| CVE-2026-62515 | 7.6 | 25.1 | Oracle Corporation | Oracle Advanced Planning Command Center | CWE-269 | Vulnerability in the Oracle Advanced Planning Command Center product of Oracl… |
| CVE-2026-60270 | 5.5 | 25.1 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60156 | 5.3 | 25.1 | Oracle Corporation | Oracle APEX | CWE-200 | Vulnerability in Oracle APEX (component: General). Supported versions that ar… |
| CVE-2026-60237 | 5.3 | 25.1 | Oracle Corporation | Oracle Coherence | CWE-200 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60260 | 5.3 | 25.1 | Oracle Corporation | Oracle Coherence | CWE-200 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60283 | 5.3 | 25.1 | Oracle Corporation | Oracle Coherence | CWE-200 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60394 | 5.3 | 25.1 | Oracle Corporation | Oracle GoldenGate | CWE-200 | Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supp… |
| CVE-2026-60611 | 5.3 | 25.1 | Oracle Corporation | PeopleSoft Enterprise CS Campus Community | CWE-200 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Ora… |
| CVE-2026-47008 | 4.9 | 25.1 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-47023 | 4.9 | 25.1 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-61128 | 4.9 | 25.1 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-21575 | 8.0 | 25.0 | Atlassian | Sourcetree for Mac | CWE-94 | This High severity RCE (Remote Code Execution) vulnerability was introduced i… |
| CVE-2026-16374 | 7.5 | 25.0 | Mozilla | Firefox | CWE-200 | Information disclosure in the Framework component in DevTools |
| CVE-2026-16391 | 7.5 | 25.0 | Mozilla | Firefox | CWE-200 | Information disclosure in the Storage: IndexedDB component |
| CVE-2026-59850 | 7.5 | 25.0 | Red Hat | Red Hat Enterprise Linux 10 | CWE-416 | Libssh: libssh: use-after-free via data callbacks on closed channels |
| CVE-2026-61192 | 5.3 | 25.0 | Oracle Corporation | Oracle Agile Engineering Data Management | CWE-400 | Vulnerability in the Oracle Agile Engineering Data Management product of Orac… |
| CVE-2026-60326 | 9.1 | 24.9 | Oracle Corporation | Oracle Access Manager | CWE-287 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-60327 | 8.6 | 24.9 | Oracle Corporation | Oracle Access Manager | CWE-287 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-60584 | 7.6 | 24.8 | Oracle Corporation | Oracle Transportation Management | CWE-284 | Vulnerability in the Oracle Transportation Management product of Oracle Suppl… |
| CVE-2026-60320 | 7.5 | 24.9 | Oracle Corporation | Oracle Data Integrator | CWE-863 | Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middlewa… |
| CVE-2026-60704 | 7.5 | 24.8 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-306 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-47237 | 8.0 | 24.6 | kubeflow | community-distribution | CWE-266 | Kubeflow Community Distribution: Overly Permissive Istio Permissions Allows K… |
| CVE-2026-61012 | 7.1 | 24.5 | Oracle Corporation | Oracle Time and Labor | CWE-863 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite… |
| CVE-2026-61119 | 7.1 | 24.5 | Oracle Corporation | Oracle HRMS (UK) | CWE-284 | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (com… |
| CVE-2026-60448 | 8.7 | 24.4 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60597 | 8.7 | 24.4 | Oracle Corporation | PeopleSoft Enterprise FIN Cash Management | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Cash Management product of Ora… |
| CVE-2026-60281 | 8.1 | 24.5 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-46943 | 7.4 | 24.4 | Oracle Corporation | Oracle Retail EFTLink | CWE-284 | Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applicati… |
| CVE-2026-60725 | 7.4 | 24.4 | Oracle Corporation | MySQL Router | CWE-284 | Vulnerability in the MySQL Router product of Oracle MySQL (component: Router:… |
| CVE-2026-61113 | 7.4 | 24.4 | Oracle Corporation | Oracle Application Object Library | CWE-284 | Vulnerability in the Oracle Application Object Library product of Oracle E-Bu… |
| CVE-2026-61135 | 7.4 | 24.4 | Oracle Corporation | Oracle Commerce Platform | CWE-284 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com… |
| CVE-2026-61164 | 7.4 | 24.4 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-61173 | 7.4 | 24.4 | Oracle Corporation | Oracle Agile PLM | CWE-284 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-61210 | 7.4 | 24.4 | Oracle Corporation | PeopleSoft Enterprise SCM Manufacturing | CWE-284 | Vulnerability in the PeopleSoft Enterprise SCM Manufacturing product of Oracl… |
| CVE-2026-61234 | 7.4 | 24.4 | Oracle Corporation | PeopleSoft Enterprise FIN Common Objects Brazil | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product … |
| CVE-2026-47003 | 5.9 | 24.4 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-60348 | 5.9 | 24.4 | Oracle Corporation | Oracle JDeveloper | CWE-284 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (c… |
| CVE-2026-60189 | 4.4 | 24.5 | Oracle Corporation | MySQL Server | CWE-284 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-16390 | 9.1 | 24.3 | Mozilla | Firefox | CWE-693 | Mitigation bypass in the Enterprise Policies component |
| CVE-2026-16493 | 7.8 | 24.3 | Red Hat | Red Hat Ansible Automation Platform 2 | CWE-88 | Ansible-core: argument injection in ansible-galaxy collection install via git… |
| CVE-2026-16411 | 9.8 | 24.3 | Mozilla | Firefox | CWE-119 | Memory safety bugs fixed in Firefox 153 |
| CVE-2026-59847 | 7.5 | 24.1 | Red Hat | Red Hat Enterprise Linux 10 | CWE-253 | Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification |
| CVE-2026-15789 | 6.9 | 24.1 | moby | BuildKit | CWE-22 | Malicious client can bypass destination directory validation on local sources… |
| CVE-2026-62503 | 6.7 | 24.1 | Oracle Corporation | Oracle Time and Labor | CWE-284 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite… |
| CVE-2026-60805 | 6.2 | 24.1 | Oracle Corporation | Oracle Cost Management | CWE-284 | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suit… |
| CVE-2026-60888 | 5.3 | 24.1 | Oracle Corporation | Oracle Work in Process | CWE-200 | Vulnerability in the Oracle Work in Process product of Oracle E-Business Suit… |
| CVE-2026-65048 | 9.3 | 24.0 | Saturday Drive | Ninja Forms | CWE-79 | Ninja Forms Unauthenticated Stored Cross-Site Scripting via Repeatable Fields… |
| CVE-2026-60213 | 6.5 | 24.0 | Oracle Corporation | Oracle Coherence | CWE-400 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-59848 | 5.3 | 24.1 | Red Hat | Red Hat Enterprise Linux 10 | CWE-770 | Libssh: libssh: denial of service via sftp responses with unknown request ids |
| CVE-2026-60770 | 7.5 | 23.8 | Oracle Corporation | Oracle Application Object Library | CWE-284 | Vulnerability in the Oracle Application Object Library product of Oracle E-Bu… |
| CVE-2026-61141 | 7.5 | 23.8 | Oracle Corporation | Oracle Advanced Benefits | CWE-269 | Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Su… |
| CVE-2026-60651 | 8.8 | 23.8 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-47033 | 8.5 | 23.8 | Oracle Corporation | Oracle Contracts Integration | CWE-284 | Vulnerability in the Oracle Contracts Integration product of Oracle E-Busines… |
| CVE-2026-60295 | 8.5 | 23.8 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60330 | 8.5 | 23.8 | Oracle Corporation | Oracle Identity Manager | CWE-284 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-61312 | 8.5 | 23.8 | Oracle Corporation | Oracle Product Hub | CWE-284 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c… |
| CVE-2026-16384 | 7.5 | 23.8 | Mozilla | Firefox | CWE-908 | Information disclosure due to uninitialized memory in the Graphics: WebGPU co… |
| CVE-2026-16385 | 7.5 | 23.8 | Mozilla | Firefox | CWE-908 | Information disclosure due to uninitialized memory in the Graphics: WebGPU co… |
| CVE-2026-16386 | 7.5 | 23.8 | Mozilla | Firefox | CWE-908 | Information disclosure due to uninitialized memory in the Graphics: WebGPU co… |
| CVE-2026-46941 | 7.5 | 23.8 | Oracle Corporation | Oracle Cost Management | CWE-284 | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suit… |
| CVE-2026-60495 | 7.5 | 23.8 | Oracle Corporation | JD Edwards EnterpriseOne Requirements Planning | CWE-306 | Vulnerability in the JD Edwards EnterpriseOne Requirements Planning product o… |
| CVE-2026-60496 | 7.5 | 23.8 | Oracle Corporation | JD Edwards EnterpriseOne Advanced Pricing - Procurement | CWE-306 | Vulnerability in the JD Edwards EnterpriseOne Advanced Pricing - Procurement … |
| CVE-2026-60497 | 7.5 | 23.8 | Oracle Corporation | JD Edwards EnterpriseOne CRM Foundation | CWE-306 | Vulnerability in the JD Edwards EnterpriseOne CRM Foundation product of Oracl… |
| CVE-2026-60498 | 7.5 | 23.8 | Oracle Corporation | JD Edwards EnterpriseOne Human Resources Management | CWE-306 | Vulnerability in the JD Edwards EnterpriseOne Human Resources Management prod… |
| CVE-2026-60598 | 7.5 | 23.8 | Oracle Corporation | PeopleSoft Enterprise CS Student Records | CWE-287 | Vulnerability in the PeopleSoft Enterprise CS Student Records product of Orac… |
| CVE-2026-60604 | 7.5 | 23.8 | Oracle Corporation | PeopleSoft Enterprise CS Campus Community | CWE-306 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Ora… |
| CVE-2026-60619 | 7.5 | 23.8 | Oracle Corporation | JD Edwards EnterpriseOne HCM Foundation | CWE-269 | Vulnerability in the JD Edwards EnterpriseOne HCM Foundation product of Oracl… |
| CVE-2026-60806 | 7.5 | 23.8 | Oracle Corporation | Oracle Cost Management | CWE-284 | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suit… |
| CVE-2026-61114 | 7.5 | 23.8 | Oracle Corporation | Oracle Application Object Library | CWE-269 | Vulnerability in the Oracle Application Object Library product of Oracle E-Bu… |
| CVE-2026-61188 | 7.5 | 23.8 | Oracle Corporation | Oracle Agile Product Lifecycle Management for Process | CWE-269 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process pr… |
| CVE-2026-61337 | 7.5 | 23.8 | Oracle Corporation | Oracle Lease and Finance Management | CWE-284 | Vulnerability in the Oracle Lease and Finance Management product of Oracle E-… |
| CVE-2026-60349 | 5.9 | 23.7 | Oracle Corporation | Oracle JDeveloper | CWE-200 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (c… |
| CVE-2026-16361 | 9.8 | 23.5 | Mozilla | Firefox | CWE-119 | Memory safety bugs fixed in Thunderbird ESR 140.13 |
| CVE-2026-16370 | 9.1 | 23.5 | Mozilla | Firefox | CWE-693 | Mitigation bypass in the DOM: Networking component |
| CVE-2026-16380 | 9.1 | 23.5 | Mozilla | Firefox | CWE-693 | Mitigation bypass in the Networking component |
| CVE-2026-60438 | 9.1 | 23.3 | Oracle Corporation | Oracle HTTP Server | CWE-284 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (… |
| CVE-2026-60567 | 9.1 | 23.3 | Oracle Corporation | Oracle Identity Manager | CWE-269 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-61238 | 9.1 | 23.3 | Oracle Corporation | PeopleSoft Enterprise FIN Common Objects Argentina | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina produ… |
| CVE-2026-61244 | 9.1 | 23.3 | Oracle Corporation | PeopleSoft Enterprise FIN Manufacturing Argentina | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Argentina produc… |
| CVE-2026-63764 | 7.7 | 23.3 | InternLM | lmdeploy | CWE-918 | LMDeploy Server-Side Request Forgery via HTTP Redirect Bypass |
| CVE-2026-35287 | 7.5 | 23.3 | Oracle Corporation | Oracle Application Testing Suite | CWE-284 | Vulnerability in Oracle Application Testing Suite. The supported version that… |
| CVE-2026-61232 | 7.5 | 23.3 | Oracle Corporation | PeopleSoft Enterprise FIN Common Objects Brazil | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product … |
| CVE-2026-61236 | 7.5 | 23.3 | Oracle Corporation | PeopleSoft Enterprise FIN Common Objects Brazil | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product … |
| CVE-2026-16364 | 9.1 | 23.2 | Mozilla | Firefox | CWE-119 | Incorrect boundary conditions in the Audio/Video: Playback component |
| CVE-2026-61205 | 8.2 | 23.2 | Oracle Corporation | PeopleSoft Enterprise SCM Purchasing | CWE-284 | Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle P… |
| CVE-2026-16378 | 7.5 | 23.2 | Mozilla | Firefox | CWE-20 | Other issue in the DOM: Copy & Paste and Drag & Drop component |
| CVE-2026-46984 | 5.3 | 23.2 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-46986 | 5.3 | 23.2 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-60342 | 5.3 | 23.2 | Oracle Corporation | Oracle Access Manager | CWE-269 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-47059 | 3.7 | 23.2 | Oracle Corporation | Oracle Java SE | CWE-284 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM E… |
| CVE-2026-16410 | 9.8 | 23.1 | Mozilla | Firefox | CWE-843 | JIT miscompilation in the JavaScript Engine: JIT component |
| CVE-2026-47013 | 5.3 | 23.1 | Oracle Corporation | Oracle Java SE | CWE-770 | Vulnerability in Oracle Java SE (component: JavaFX). The supported version th… |
| CVE-2026-47021 | 5.3 | 23.1 | Oracle Corporation | Oracle Java SE | CWE-400 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM E… |
| CVE-2026-60695 | 5.9 | 23.0 | Oracle Corporation | Oracle Enterprise Asset Management | CWE-284 | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-B… |
| CVE-2026-60801 | 5.9 | 23.0 | Oracle Corporation | Oracle E-Business Intelligence | CWE-284 | Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Busin… |
| CVE-2026-60534 | 7.7 | 22.9 | Oracle Corporation | Oracle Identity Manager Connector | CWE-284 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-60399 | 6.5 | 22.9 | Oracle Corporation | Oracle GoldenGate | CWE-400 | Vulnerability in Oracle GoldenGate (component: Receiver Service Executable). … |
| CVE-2026-60403 | 6.5 | 22.9 | Oracle Corporation | TimesTen In-Memory Database | CWE-400 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen I… |
| CVE-2026-61108 | 6.5 | 22.9 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60562 | 9.9 | 22.7 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-47708 | 9.3 | 22.8 | SepineTam | stata-mcp | CWE-77 | MCP-for-Stata: Command injection via log_file_name parameter in Stata command… |
| CVE-2026-60400 | 8.8 | 22.7 | Oracle Corporation | Oracle GoldenGate | CWE-284 | Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supp… |
| CVE-2026-60675 | 8.8 | 22.7 | Oracle Corporation | Oracle Applications Framework | CWE-284 | Vulnerability in the Oracle Applications Framework product of Oracle E-Busine… |
| CVE-2026-60381 | 9.9 | 22.7 | Oracle Corporation | Service Delivery Platform | CWE-284 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60402 | 9.9 | 22.7 | Oracle Corporation | TimesTen In-Memory Database | CWE-284 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen I… |
| CVE-2026-60429 | 9.9 | 22.7 | Oracle Corporation | Oracle Unified Directory | CWE-284 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60445 | 9.9 | 22.7 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60447 | 9.9 | 22.7 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60568 | 9.9 | 22.7 | Oracle Corporation | Oracle WebCenter Portal | CWE-287 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-60663 | 9.9 | 22.7 | Oracle Corporation | Oracle WebCenter Content | CWE-269 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-61242 | 9.9 | 22.7 | Oracle Corporation | PeopleSoft Enterprise FIN Common Objects Argentina | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina produ… |
| CVE-2026-47037 | 8.8 | 22.7 | Oracle Corporation | Oracle Access Manager | CWE-287 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-60218 | 8.8 | 22.7 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60419 | 8.8 | 22.7 | Oracle Corporation | Oracle Unified Directory | CWE-269 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60423 | 8.8 | 22.7 | Oracle Corporation | Oracle Unified Directory | CWE-287 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60464 | 8.8 | 22.7 | Oracle Corporation | WebCenter Content: Imaging | CWE-287 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd… |
| CVE-2026-60472 | 8.8 | 22.7 | Oracle Corporation | WebCenter Content: Imaging | CWE-284 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd… |
| CVE-2026-60489 | 8.8 | 22.7 | Oracle Corporation | JD Edwards EnterpriseOne CRM Foundation | CWE-306 | Vulnerability in the JD Edwards EnterpriseOne CRM Foundation product of Oracl… |
| CVE-2026-60490 | 8.8 | 22.7 | Oracle Corporation | JD Edwards EnterpriseOne CRM Foundation | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne CRM Foundation product of Oracl… |
| CVE-2026-60563 | 8.8 | 22.7 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-60654 | 8.8 | 22.7 | Oracle Corporation | Oracle WebCenter Content | CWE-269 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60681 | 8.8 | 22.7 | Oracle Corporation | Oracle Process Manufacturing Regulatory Management | CWE-284 | Vulnerability in the Oracle Process Manufacturing Regulatory Management produ… |
| CVE-2026-61148 | 8.8 | 22.7 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-62464 | 8.8 | 22.7 | Oracle Corporation | Oracle Payroll | CWE-269 | Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (compo… |
| CVE-2026-61067 | 8.0 | 22.7 | Oracle Corporation | Oracle Access Manager | CWE-287 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-60528 | 7.6 | 22.7 | Oracle Corporation | Oracle WebLogic Server | CWE-284 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60467 | 7.5 | 22.7 | Oracle Corporation | WebCenter Content: Imaging | CWE-601 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd… |
| CVE-2026-9499 | 6.3 | 22.7 | Qt | Qt | CWE-125 | Out-of-bounds read in QTextCodec::codecForName() in Qt |
| CVE-2026-61050 | 5.3 | 22.6 | Oracle Corporation | Oracle Production Scheduling | CWE-200 | Vulnerability in the Oracle Production Scheduling product of Oracle E-Busines… |
| CVE-2026-16393 | 9.1 | 22.5 | Mozilla | Firefox | CWE-119 | Incorrect boundary conditions in the Graphics: WebGPU component |
| CVE-2026-60945 | 7.3 | 22.4 | Oracle Corporation | Oracle Learning Management | CWE-284 | Vulnerability in the Oracle Learning Management product of Oracle E-Business … |
| CVE-2026-60437 | 8.7 | 22.4 | Oracle Corporation | Oracle Unified Directory | CWE-284 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60443 | 8.7 | 22.4 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60469 | 8.7 | 22.4 | Oracle Corporation | WebCenter Content: Imaging | CWE-284 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd… |
| CVE-2026-60523 | 8.7 | 22.4 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-61078 | 8.7 | 22.4 | Oracle Corporation | PeopleSoft Enterprise CC Common Application Objects | CWE-284 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects prod… |
| CVE-2026-61185 | 7.4 | 22.2 | Oracle Corporation | Oracle Agile Product Lifecycle Management for Process | CWE-200 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process pr… |
| CVE-2026-16441 | 6.9 | 22.2 | Eclipse Foundation | OpenJ9 | CWE-758 | Eclipse OpenJ9 : Method resolution default method precedence failure |
| CVE-2026-60346 | 3.7 | 22.3 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-47419 | 8.3 | 22.1 | MervinPraison | praisonai-platform | CWE-639 | praisonai-platform: Agent endpoints accept any agent_id without workspace own… |
| CVE-2026-42397 | 6.5 | 22.2 | Elastic | Kibana | CWE-770 | Allocation of Resources Without Limits or Throttling in Kibana Leading to Den… |
| CVE-2026-56145 | 6.5 | 22.2 | Elastic | Elasticsearch | CWE-400 | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-60143 | 7.3 | 22.0 | Oracle Corporation | Oracle Workflow | CWE-284 | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (comp… |
| CVE-2026-47046 | 8.2 | 21.9 | Oracle Corporation | Oracle Database Server | CWE-400 | Vulnerability in the RDBMS component of Oracle Database Server. Supported ver… |
| CVE-2026-62518 | 7.6 | 21.9 | Oracle Corporation | Oracle Production Scheduling | CWE-200 | Vulnerability in the Oracle Production Scheduling product of Oracle E-Busines… |
| CVE-2026-47690 | 7.5 | 21.9 | meltano | hub | CWE-77 | MeltanoHub vulnerable to command injection in the `test_dispatcher` GitHub Ac… |
| CVE-2026-61136 | 7.3 | 22.0 | Oracle Corporation | Oracle Commerce Platform | CWE-284 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com… |
| CVE-2026-16362 | 8.8 | 21.7 | Mozilla | Firefox | CWE-416 | Use-after-free in the WebRTC: Audio/Video component |
| CVE-2026-60827 | 7.4 | 21.7 | Oracle Corporation | Oracle iSupport | CWE-284 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (comp… |
| CVE-2026-60424 | 9.0 | 21.6 | Oracle Corporation | Oracle Unified Directory | CWE-306 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-59851 | 8.8 | 21.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-863 | Libssh: libssh: authentication bypass via missing gssapi principal check |
| CVE-2026-60273 | 8.1 | 21.6 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60277 | 8.1 | 21.6 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60416 | 8.1 | 21.6 | Oracle Corporation | Oracle Access Manager | CWE-287 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-60450 | 8.1 | 21.6 | Oracle Corporation | Oracle WebCenter Content | CWE-306 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60462 | 8.1 | 21.6 | Oracle Corporation | Oracle WebCenter Content | CWE-306 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60670 | 8.1 | 21.6 | Oracle Corporation | Oracle Applications Technology Stack | CWE-284 | Vulnerability in the Oracle Applications Technology Stack product of Oracle E… |
| CVE-2026-60979 | 8.1 | 21.6 | Oracle Corporation | Oracle Scripting | CWE-284 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (com… |
| CVE-2026-61137 | 8.1 | 21.6 | Oracle Corporation | Oracle Commerce Platform | CWE-287 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com… |
| CVE-2026-60440 | 7.7 | 21.6 | Oracle Corporation | Service Delivery Platform | CWE-200 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60705 | 7.0 | 21.7 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-200 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-60812 | 6.5 | 21.6 | Oracle Corporation | Oracle Supply Chain Trading Connector | CWE-200 | Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle … |
| CVE-2026-60899 | 6.5 | 21.6 | Oracle Corporation | Oracle HCM Configuration Workbench | CWE-200 | Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-B… |
| CVE-2026-62470 | 6.5 | 21.7 | Oracle Corporation | Oracle Self-Service Human Resources | CWE-200 | Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-… |
| CVE-2026-47399 | 8.8 | 21.5 | MervinPraison | praisonai-platform | CWE-284 | PraisonAI Platform workspace-scoped routes allow cross-workspace object acces… |
| CVE-2026-47405 | 8.8 | 21.5 | MervinPraison | praisonai-platform | CWE-284 | PraisonAI Platform missing role checks let any workspace member become owner … |
| CVE-2026-60395 | 4.3 | 21.5 | Oracle Corporation | Oracle GoldenGate | CWE-200 | Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supp… |
| CVE-2026-61292 | 4.3 | 21.5 | Oracle Corporation | Oracle U.S. Federal Financials | CWE-200 | Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Busin… |
| CVE-2026-61315 | 4.3 | 21.5 | Oracle Corporation | Oracle EDI Gateway | CWE-200 | Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (c… |
| CVE-2026-61316 | 4.3 | 21.5 | Oracle Corporation | Oracle EDI Gateway | CWE-200 | Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (c… |
| CVE-2026-47418 | 8.1 | 21.4 | MervinPraison | praisonai-platform | CWE-639 | praisonai-platform: Project endpoints accept any project_id without workspace… |
| CVE-2026-46917 | 5.3 | 21.4 | Oracle Corporation | Oracle Java SE | CWE-284 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM E… |
| CVE-2026-47027 | 5.3 | 21.4 | Oracle Corporation | Oracle Java SE | CWE-284 | Vulnerability in Oracle Java SE (component: Libraries). Supported versions th… |
| CVE-2026-16409 | 7.5 | 21.3 | Mozilla | Firefox | CWE-824 | Invalid pointer in the Security: PSM component |
| CVE-2026-61267 | 7.3 | 21.3 | Oracle Corporation | Oracle HCM Configuration Workbench | CWE-200 | Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-B… |
| CVE-2026-61271 | 7.3 | 21.3 | Oracle Corporation | Oracle Document Management and Collaboration | CWE-284 | Vulnerability in the Oracle Document Management and Collaboration product of … |
| CVE-2026-60774 | 7.1 | 21.2 | Oracle Corporation | Oracle Applications Framework | CWE-284 | Vulnerability in the Oracle Applications Framework product of Oracle E-Busine… |
| CVE-2026-60799 | 7.1 | 21.2 | Oracle Corporation | Oracle Compensation Workbench | CWE-284 | Vulnerability in the Oracle Compensation Workbench product of Oracle E-Busine… |
| CVE-2026-60870 | 7.1 | 21.2 | Oracle Corporation | Oracle Advanced Pricing | CWE-284 | Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Sui… |
| CVE-2026-60908 | 7.1 | 21.2 | Oracle Corporation | Oracle Installed Base | CWE-284 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite… |
| CVE-2026-60420 | 8.5 | 21.2 | Oracle Corporation | Oracle Unified Directory | CWE-284 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60444 | 8.5 | 21.2 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60452 | 8.5 | 21.2 | Oracle Corporation | WebCenter Content: Imaging | CWE-284 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd… |
| CVE-2026-60641 | 7.6 | 21.2 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60451 | 7.1 | 21.2 | Oracle Corporation | WebCenter Content: Imaging | CWE-284 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd… |
| CVE-2026-60577 | 7.1 | 21.2 | Oracle Corporation | Oracle Enterprise Command Center Framework | CWE-287 | Vulnerability in the Oracle Enterprise Command Center Framework product of Or… |
| CVE-2026-60800 | 7.1 | 21.2 | Oracle Corporation | Oracle Compensation Workbench | CWE-284 | Vulnerability in the Oracle Compensation Workbench product of Oracle E-Busine… |
| CVE-2026-61095 | 7.1 | 21.2 | Oracle Corporation | Oracle Communications Unified Inventory Management | CWE-284 | Vulnerability in the Oracle Communications Unified Inventory Management produ… |
| CVE-2026-61151 | 7.1 | 21.2 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-61299 | 7.1 | 21.2 | Oracle Corporation | Oracle Process Manufacturing Logistics | CWE-284 | Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle… |
| CVE-2026-60147 | 6.5 | 21.2 | Oracle Corporation | Oracle Java SE | CWE-284 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM E… |
| CVE-2026-60304 | 6.5 | 21.2 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60303 | 4.3 | 21.2 | Oracle Corporation | Oracle Coherence | CWE-400 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-62546 | 9.1 | 21.0 | Oracle Corporation | Oracle Applications Framework | CWE-284 | Vulnerability in the Oracle Applications Framework product of Oracle E-Busine… |
| CVE-2026-46998 | 8.8 | 21.0 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-601 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-15927 | 6.8 | 21.0 | Red Hat | Red Hat Quay 3.1 | CWE-918 | Quay: mirror-registry: ssrf: repo-level mirror accepts external_reference wit… |
| CVE-2026-47409 | 8.1 | 20.9 | MervinPraison | praisonai-platform | CWE-269 | praisonai-platform: Any workspace member can remove any other member (includi… |
| CVE-2026-47412 | 8.1 | 20.9 | MervinPraison | praisonai-platform | CWE-269 | praisonai-platform: Any workspace member can delete the entire workspace via … |
| CVE-2026-46681 | 7.2 | 20.9 | nevware21 | ts-utils | CWE-1321 | @nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for.… |
| CVE-2026-60190 | 2.2 | 20.9 | Oracle Corporation | MySQL Server | CWE-284 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-16424 | 9.6 | 20.8 | Chrome | CWE-416 | Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 all… | |
| CVE-2026-65051 | 6.9 | 20.7 | Saturday Drive | Ninja Forms | CWE-602 | Ninja Forms Server-Side Validation Bypass via Client-Controlled Field Metadat… |
| CVE-2026-28315 | 6.2 | 20.8 | SolarWinds | Serv-U | CWE-79 | SolarWinds Serv-U Authenticated Stored Cross-site Scripting (XSS) Vulnerability |
| CVE-2025-68640 | 5.3 | 20.8 | n/a | n/a | CWE-287 | The Apple Find My backend service through 2025-12-17 allows an attacker in po… |
| CVE-2026-61044 | 4.7 | 20.7 | Oracle Corporation | Oracle Production Scheduling | CWE-284 | Vulnerability in the Oracle Production Scheduling product of Oracle E-Busines… |
| CVE-2026-60936 | 3.1 | 20.7 | Oracle Corporation | Oracle Labor Distribution | CWE-400 | Vulnerability in the Oracle Labor Distribution product of Oracle E-Business S… |
| CVE-2026-61048 | 3.1 | 20.7 | Oracle Corporation | Oracle Inventory Optimization | CWE-400 | Vulnerability in the Oracle Inventory Optimization product of Oracle E-Busine… |
| CVE-2026-60852 | 8.1 | 20.5 | Oracle Corporation | Oracle Lease and Finance Management | CWE-284 | Vulnerability in the Oracle Lease and Finance Management product of Oracle E-… |
| CVE-2026-60857 | 8.1 | 20.5 | Oracle Corporation | Oracle Contracts Integration | CWE-284 | Vulnerability in the Oracle Contracts Integration product of Oracle E-Busines… |
| CVE-2026-60325 | 8.0 | 20.6 | Oracle Corporation | Oracle Access Manager | CWE-284 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-61324 | 7.7 | 20.6 | Oracle Corporation | Oracle Advanced Benefits | CWE-284 | Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Su… |
| CVE-2026-47039 | 6.5 | 20.6 | Oracle Corporation | Oracle Database Server | CWE-284 | Vulnerability in the Java VM component of Oracle Database Server. Supported v… |
| CVE-2026-47415 | 8.3 | 20.5 | MervinPraison | praisonai-platform | CWE-639 | praisonai-platform: Issue endpoints accept any issue_id without workspace own… |
| CVE-2026-60581 | 7.5 | 20.5 | Oracle Corporation | Oracle Enterprise Command Center Framework | CWE-284 | Vulnerability in the Oracle Enterprise Command Center Framework product of Or… |
| CVE-2026-13693 | 5.9 | 20.5 | Unknown | Bit Form | CWE-22 | Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path Traversal |
| CVE-2026-46968 | 5.9 | 20.4 | Oracle Corporation | Oracle Java SE | CWE-284 | Vulnerability in Oracle Java SE (component: JSSE). Supported versions that ar… |
| CVE-2026-60422 | 9.9 | 20.4 | Oracle Corporation | Oracle Unified Directory | CWE-284 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-16407 | 9.8 | 20.4 | Mozilla | Firefox | CWE-284 | Mitigation bypass in the DOM: Service Workers component |
| CVE-2026-60677 | 8.4 | 20.4 | Oracle Corporation | Oracle Common Application Components | CWE-284 | Vulnerability in the Oracle Common Application Components product of Oracle E… |
| CVE-2026-62473 | 8.3 | 20.4 | Oracle Corporation | Oracle Installed Base | CWE-200 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite… |
| CVE-2026-46923 | 8.0 | 20.3 | Oracle Corporation | Oracle Public Sector Financials (International) | CWE-284 | Vulnerability in the Oracle Public Sector Financials (International) product … |
| CVE-2026-64627 | 6.9 | 20.3 | parse-community | parse-server | CWE-209 | Parse Server 9.0.0 Schema Disclosure via GraphQL Variable Coercion |
| CVE-2026-61279 | 6.3 | 20.4 | Oracle Corporation | Oracle Proposals | CWE-200 | Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (com… |
| CVE-2026-65058 | 5.9 | 20.4 | Trezor | Safe 3 | CWE-358 | Trezor Safe improper security check in on-device display |
| CVE-2026-16371 | 8.8 | 20.2 | Mozilla | Firefox | CWE-269 | Privilege escalation in the DOM: Navigation component |
| CVE-2026-16379 | 8.8 | 20.2 | Mozilla | Firefox | CWE-269 | Privilege escalation in the DOM: Content Processes component |
| CVE-2026-60701 | 6.6 | 20.3 | Oracle Corporation | Oracle Universal Work Queue | CWE-284 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business… |
| CVE-2026-60571 | 5.4 | 20.1 | Oracle Corporation | Oracle SDP Number Portability | CWE-284 | Vulnerability in the Oracle SDP Number Portability product of Oracle E-Busine… |
| CVE-2026-3182 | 4.3 | 20.1 | Zohocorp | ManageEngine Endpoint Central | CWE-319 | Sensitive Data Exposure |
| CVE-2026-11767 | 8.8 | 20.0 | Unknown | Free Theme Builder for Elementor | CWE-79 | CRT Addons for Elementor < 1.6.7 - Unauthenticated Stored XSS via Contact Form |
| CVE-2026-8989 | 8.6 | 20.1 | Autel | MaxiCharger Single | CWE-1191 | Open Recovery Mode |
| CVE-2026-65049 | 8.4 | 19.9 | Saturday Drive | Ninja Forms | CWE-863 | Ninja Forms Cross-Site Network-Wide Data Deletion on WordPress Multisite via … |
| CVE-2026-60410 | 4.3 | 19.8 | Oracle Corporation | TimesTen In-Memory Database | CWE-400 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen I… |
| CVE-2026-16450 | 2.1 | 19.8 | zsadmin2025 | ZS-Admin | CWE-285 | zsadmin2025 ZS-Admin MyBatis-Plus Tenant Plugin page getTenantId authorization |
| CVE-2026-62549 | 9.6 | 19.7 | Oracle Corporation | Oracle HRMS (UK) | CWE-284 | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (com… |
| CVE-2026-60323 | 8.1 | 19.7 | Oracle Corporation | Oracle Identity Manager | CWE-284 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-62514 | 8.1 | 19.7 | Oracle Corporation | Oracle Process Manufacturing Regulatory Management | CWE-284 | Vulnerability in the Oracle Process Manufacturing Regulatory Management produ… |
| CVE-2026-47045 | 6.8 | 19.7 | Oracle Corporation | Oracle Database Server | CWE-601 | Vulnerability in the JDBC component of Oracle Database Server. Supported vers… |
| CVE-2026-16485 | 2.1 | 19.7 | SourceCodester | Class and Exam Timetabling System | CWE-79 | SourceCodester Class and Exam Timetabling System class.php cross site scripting |
| CVE-2026-16486 | 2.1 | 19.7 | SourceCodester | Class and Exam Timetabling System | CWE-79 | SourceCodester Class and Exam Timetabling System BSIS.php cross site scripting |
| CVE-2026-16372 | 8.8 | 19.6 | Mozilla | Firefox | CWE-269 | Privilege escalation in the DOM: Content Processes component |
| CVE-2026-16373 | 7.5 | 19.5 | Mozilla | Firefox | CWE-200 | Information disclosure in the Privacy component in Firefox for Android |
| CVE-2026-47026 | 7.4 | 19.6 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | CWE-601 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-47687 | 8.7 | 19.3 | FOGProject | fogproject | CWE-79 | FOGProject has stored XSS via unescaped option label in selectForm() accessib… |
| CVE-2026-62415 | 9.1 | 19.3 | joomdonation.com | Membership Pro extension for Joomla | CWE-1188 | Joomla Extension - joomdonation.com - Insecure default configuration Membersh… |
| CVE-2026-46993 | 8.2 | 19.2 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-60525 | 8.2 | 19.2 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60665 | 8.2 | 19.2 | Oracle Corporation | PeopleSoft Enterprise HCM Global Payroll Switzerland | CWE-284 | Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland pro… |
| CVE-2026-60629 | 7.5 | 19.2 | Oracle Corporation | Oracle JDeveloper | CWE-284 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (c… |
| CVE-2026-60612 | 6.8 | 19.2 | Oracle Corporation | PeopleSoft Enterprise CS Financial Aid | CWE-284 | Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle… |
| CVE-2026-60744 | 6.8 | 19.2 | Oracle Corporation | Oracle Cost Management | CWE-284 | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suit… |
| CVE-2026-60795 | 6.8 | 19.2 | Oracle Corporation | Oracle iSetup | CWE-284 | Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (compon… |
| CVE-2026-61134 | 6.8 | 19.2 | Oracle Corporation | Oracle Commerce Platform | CWE-284 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com… |
| CVE-2026-60616 | 6.5 | 19.2 | Oracle Corporation | PeopleSoft Enterprise CS Campus Community | CWE-306 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Ora… |
| CVE-2026-63139 | 6.5 | 19.2 | Elastic | Kibana | CWE-400 | Uncontrolled Resource Consumption in Kibana Leading to Denial of Service |
| CVE-2026-63260 | 6.5 | 19.2 | Elastic | Kibana | CWE-400 | Uncontrolled Resource Consumption in Kibana Leading to Denial of Service |
| CVE-2026-63261 | 6.5 | 19.2 | Elastic | Kibana | CWE-400 | Uncontrolled Resource Consumption in Kibana Leading to Denial of Service |
| CVE-2026-61117 | 6.3 | 19.2 | Oracle Corporation | Oracle HRMS (UK) | CWE-200 | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (com… |
| CVE-2026-16365 | 8.8 | 19.1 | Mozilla | Firefox | CWE-269 | Privilege escalation in the DOM: Workers component |
| CVE-2026-16366 | 8.8 | 19.1 | Mozilla | Firefox | CWE-269 | Privilege escalation in the DOM: Navigation component |
| CVE-2026-60940 | 5.7 | 19.1 | Oracle Corporation | Oracle Service Contracts | CWE-284 | Vulnerability in the Oracle Service Contracts product of Oracle E-Business Su… |
| CVE-2026-61239 | 9.9 | 19.0 | Oracle Corporation | PeopleSoft Enterprise FIN Common Objects Argentina | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina produ… |
| CVE-2026-55081 | 7.3 | 18.9 | dhis2 | dhis2-core | CWE-79 | DHIS2 Reflected XSS in OpenAPI HTML scope parameter |
| CVE-2026-65007 | 8.7 | 18.5 | getgrav | grav | CWE-862 | Grav before 1.0.8 Missing Authorization on API Key Generation |
| CVE-2026-60582 | 8.3 | 18.6 | Oracle Corporation | Oracle Enterprise Command Center Framework | CWE-89 | Vulnerability in the Oracle Enterprise Command Center Framework product of Or… |
| CVE-2026-47671 | 5.4 | 18.9 | nhost | cli | CWE-306 | Nhost CLI local configserver allows cross-origin unauthenticated read/write a… |
| CVE-2026-60471 | 8.3 | 18.5 | Oracle Corporation | WebCenter Content: Imaging | CWE-284 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd… |
| CVE-2026-47064 | 6.5 | 18.5 | Oracle Corporation | MySQL Server | CWE-284 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-62516 | 8.8 | 18.4 | Oracle Corporation | Oracle Demantra Demand Management | CWE-89 | Vulnerability in the Oracle Demantra Demand Management product of Oracle Supp… |
| CVE-2026-16359 | 9.1 | 18.3 | Mozilla | Firefox | CWE-119 | Incorrect boundary conditions in the Audio/Video: GMP component |
| CVE-2026-60352 | 3.7 | 18.3 | Oracle Corporation | Oracle JDeveloper | CWE-200 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (c… |
| CVE-2026-60354 | 3.7 | 18.3 | Oracle Corporation | Oracle JDeveloper | CWE-200 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (c… |
| CVE-2026-60919 | 3.7 | 18.3 | Oracle Corporation | Oracle iSupplier Portal | CWE-200 | Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Sui… |
| CVE-2026-61015 | 3.7 | 18.3 | Oracle Corporation | Oracle Time and Labor | CWE-200 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite… |
| CVE-2026-61104 | 3.7 | 18.3 | Oracle Corporation | PeopleSoft Enterprise CS Student Records | CWE-200 | Vulnerability in the PeopleSoft Enterprise CS Student Records product of Orac… |
| CVE-2026-60428 | 8.2 | 18.0 | Oracle Corporation | Oracle Unified Directory | CWE-284 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60674 | 8.2 | 18.0 | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | CWE-284 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-60810 | 8.2 | 18.0 | Oracle Corporation | Oracle Supply Chain Trading Connector | CWE-306 | Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle … |
| CVE-2026-47014 | 8.1 | 18.0 | Oracle Corporation | Oracle Product Workbench | CWE-284 | Vulnerability in the Oracle Product Workbench product of Oracle E-Business Su… |
| CVE-2026-60708 | 8.1 | 18.0 | Oracle Corporation | Oracle Process Manufacturing Financials | CWE-284 | Vulnerability in the Oracle Process Manufacturing Financials product of Oracl… |
| CVE-2026-60732 | 8.1 | 18.0 | Oracle Corporation | Oracle iReceivables | CWE-284 | Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (… |
| CVE-2026-60735 | 8.1 | 18.0 | Oracle Corporation | Oracle Sales Offline | CWE-284 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite … |
| CVE-2026-60740 | 8.1 | 18.0 | Oracle Corporation | Oracle Cash Management | CWE-284 | Vulnerability in the Oracle Cash Management product of Oracle E-Business Suit… |
| CVE-2026-60764 | 8.1 | 18.0 | Oracle Corporation | Oracle Financials Common Modules | CWE-284 | Vulnerability in the Oracle Financials Common Modules product of Oracle E-Bus… |
| CVE-2026-61020 | 8.1 | 18.0 | Oracle Corporation | Oracle Customers Online | CWE-284 | Vulnerability in the Oracle Customers Online product of Oracle E-Business Sui… |
| CVE-2026-61218 | 8.1 | 18.0 | Oracle Corporation | Oracle E-Business Suite Secure Enterprise Search | CWE-284 | Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product… |
| CVE-2026-62472 | 8.1 | 18.0 | Oracle Corporation | Oracle Installed Base | CWE-284 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite… |
| CVE-2026-60824 | 7.7 | 18.0 | Oracle Corporation | Oracle iSupport | CWE-284 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (comp… |
| CVE-2026-8082 | 7.5 | 18.1 | Unknown | bpost-shipping-platform | CWE-89 | Bpost Shipping Platform < 3.2.3 - Unauthenticated SQL Injection |
| CVE-2026-61250 | 6.5 | 18.0 | Oracle Corporation | Oracle Payroll | CWE-284 | Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (compo… |
| CVE-2026-60427 | 8.7 | 17.9 | Oracle Corporation | Oracle Unified Directory | CWE-284 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60553 | 8.7 | 17.9 | Oracle Corporation | Oracle WebCenter Sites | CWE-200 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-60653 | 8.1 | 18.0 | Oracle Corporation | Oracle WebCenter Content | CWE-306 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60691 | 8.1 | 18.0 | Oracle Corporation | Oracle Content Manager | CWE-284 | Vulnerability in the Oracle Content Manager product of Oracle E-Business Suit… |
| CVE-2026-60710 | 8.1 | 18.0 | Oracle Corporation | Oracle EDI Gateway | CWE-284 | Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (c… |
| CVE-2026-60768 | 8.1 | 18.0 | Oracle Corporation | Oracle Applications Framework | CWE-284 | Vulnerability in the Oracle Applications Framework product of Oracle E-Busine… |
| CVE-2026-61150 | 8.1 | 18.0 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-62451 | 8.1 | 18.0 | Oracle Corporation | Oracle Work in Process | CWE-284 | Vulnerability in the Oracle Work in Process product of Oracle E-Business Suit… |
| CVE-2026-46987 | 7.7 | 18.0 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-61142 | 7.7 | 18.0 | Oracle Corporation | Oracle Payroll | CWE-284 | Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (compo… |
| CVE-2026-60823 | 7.4 | 17.9 | Oracle Corporation | Oracle iSupport | CWE-284 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (comp… |
| CVE-2026-60984 | 7.1 | 17.9 | Oracle Corporation | Oracle Project Portfolio Analysis | CWE-284 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Bu… |
| CVE-2026-61334 | 7.1 | 17.9 | Oracle Corporation | Oracle Price Protection | CWE-284 | Vulnerability in the Oracle Price Protection product of Oracle E-Business Sui… |
| CVE-2026-60687 | 6.8 | 18.0 | Oracle Corporation | Oracle U.S. Federal Financials | CWE-200 | Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Busin… |
| CVE-2026-60521 | 6.5 | 18.0 | Oracle Corporation | Oracle Advanced Pricing | CWE-284 | Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Sui… |
| CVE-2026-61262 | 6.5 | 17.9 | Oracle Corporation | Oracle Teleservice | CWE-284 | Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (c… |
| CVE-2026-62556 | 6.5 | 18.0 | Oracle Corporation | Oracle HRMS (US) | CWE-200 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (com… |
| CVE-2026-1617 | 9.8 | 17.9 | Turkmesh Communication Services Inc. | Turkhotspot 5651 Loglama | CWE-89 | SQLi in Turkmesh's Turkhotspot 5651 Loglama |
| CVE-2026-60838 | 7.1 | 17.9 | Oracle Corporation | Oracle Price Protection | CWE-284 | Vulnerability in the Oracle Price Protection product of Oracle E-Business Sui… |
| CVE-2026-21579 | 8.2 | 17.7 | Atlassian | Confluence Data Center | CWE-200 | This High severity Information Disclosure vulnerability was introduced in ver… |
| CVE-2026-60614 | 7.1 | 17.7 | Oracle Corporation | PeopleSoft Enterprise CS Campus Community | CWE-284 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Ora… |
| CVE-2026-61013 | 6.6 | 17.7 | Oracle Corporation | Oracle Time and Labor | CWE-269 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite… |
| CVE-2026-61294 | 6.3 | 17.7 | Oracle Corporation | Oracle Common Applications Calendar | CWE-89 | Vulnerability in the Oracle Common Applications Calendar product of Oracle E-… |
| CVE-2026-61247 | 4.8 | 17.7 | Oracle Corporation | Oracle Workflow | CWE-306 | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (comp… |
| CVE-2026-16336 | 5.3 | 17.7 | trinodb | trino | CWE-601 | trinodb trino OAuth2/OIDC ExternalUriInfo.java redirect |
| CVE-2026-60166 | 3.1 | 17.6 | Oracle Corporation | Oracle Java SE | CWE-693 | Vulnerability in Oracle Java SE (component: JavaFX). The supported version th… |
| CVE-2026-16413 | 8.3 | 17.5 | Chrome | CWE-787 | Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed… | |
| CVE-2026-61138 | 7.5 | 17.5 | Oracle Corporation | Oracle Complex Maintenance, Repair and Overhaul | CWE-284 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product … |
| CVE-2026-60317 | 7.4 | 17.5 | Oracle Corporation | MySQL Connectors | CWE-284 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Con… |
| CVE-2026-45383 | 6.9 | 17.5 | strukturag | libde265 | CWE-125 | libde265 has a heap buffer overflow (OOB read) in decode_slice_unit_WPP() via… |
| CVE-2026-16405 | 7.5 | 17.4 | Mozilla | Firefox | CWE-200 | Information disclosure in the Networking: WebSockets component |
| CVE-2026-47063 | 7.5 | 17.4 | Oracle Corporation | Oracle Java SE | CWE-284 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM E… |
| CVE-2026-16419 | 9.6 | 17.2 | Chrome | CWE-125 | Out of bounds read and write in ANGLE in Google Chrome on Android prior to 15… | |
| CVE-2026-16423 | 8.8 | 17.2 | Chrome | CWE-416 | Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remot… | |
| CVE-2026-60214 | 8.7 | 17.3 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60315 | 8.2 | 17.1 | Oracle Corporation | MySQL Server | CWE-200 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60522 | 7.6 | 17.1 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-61181 | 7.6 | 17.1 | Oracle Corporation | Oracle Agile Product Lifecycle Management for Process | CWE-284 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process pr… |
| CVE-2026-55084 | 8.8 | 17.0 | dhis2 | dhis2-core | CWE-89 | SQL Injection in SqlView Filter Parameter Leading to Arbitrary Database Read |
| CVE-2026-61049 | 7.1 | 16.9 | Oracle Corporation | Oracle Production Scheduling | CWE-284 | Vulnerability in the Oracle Production Scheduling product of Oracle E-Busines… |
| CVE-2026-45382 | 6.9 | 17.0 | strukturag | libde265 | CWE-125 | libde265 has a heap-buffer-overflow READ in decode_slice_unit_tiles via unval… |
| CVE-2026-61069 | 5.9 | 16.9 | Oracle Corporation | PeopleSoft Enterprise FIN General Ledger Argentina | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN General Ledger Argentina produ… |
| CVE-2026-46936 | 4.4 | 16.9 | Oracle Corporation | MySQL Server | CWE-284 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60188 | 4.4 | 16.9 | Oracle Corporation | MySQL Server | CWE-284 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60950 | 2.2 | 16.9 | Oracle Corporation | Oracle HRMS (Ireland) | CWE-200 | Vulnerability in the Oracle HRMS (Ireland) product of Oracle E-Business Suite… |
| CVE-2026-61214 | 2.2 | 16.9 | Oracle Corporation | Oracle HRMS (UK) | CWE-200 | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (com… |
| CVE-2026-16394 | 9.1 | 16.7 | Mozilla | Firefox | CWE-693 | Mitigation bypass in the DOM: Security component |
| CVE-2026-65055 | 6.9 | 16.7 | Taiga | taiga-back | CWE-862 | Taiga taiga-back Private Project Member Roster Disclosure via Unauthenticated… |
| CVE-2026-60572 | 6.3 | 16.7 | Oracle Corporation | Oracle E-Business Suite Integrated SOA Gateway | CWE-284 | Vulnerability in the Oracle E-Business Suite Integrated SOA Gateway product o… |
| CVE-2026-60575 | 6.3 | 16.7 | Oracle Corporation | Oracle Workflow | CWE-284 | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (comp… |
| CVE-2026-60777 | 6.3 | 16.7 | Oracle Corporation | Oracle Application Object Library | CWE-284 | Vulnerability in the Oracle Application Object Library product of Oracle E-Bu… |
| CVE-2026-60811 | 6.3 | 16.7 | Oracle Corporation | Oracle Supply Chain Trading Connector | CWE-284 | Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle … |
| CVE-2026-61216 | 6.3 | 16.7 | Oracle Corporation | Oracle Payroll | CWE-200 | Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (compo… |
| CVE-2026-61269 | 6.3 | 16.7 | Oracle Corporation | Oracle Product Workbench | CWE-284 | Vulnerability in the Oracle Product Workbench product of Oracle E-Business Su… |
| CVE-2026-61278 | 6.3 | 16.7 | Oracle Corporation | Oracle Workflow | CWE-284 | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (comp… |
| CVE-2026-61282 | 6.3 | 16.7 | Oracle Corporation | Oracle Advanced Benefits | CWE-284 | Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Su… |
| CVE-2026-61283 | 6.3 | 16.7 | Oracle Corporation | Oracle Bills of Material | CWE-284 | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Su… |
| CVE-2026-62519 | 6.3 | 16.7 | Oracle Corporation | Oracle Succession planning | CWE-20 | Vulnerability in the Oracle Succession planning product of Oracle E-Business … |
| CVE-2026-60617 | 6.5 | 16.6 | Oracle Corporation | PeopleSoft Enterprise CS Campus Community | CWE-284 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Ora… |
| CVE-2026-60491 | 6.3 | 16.7 | Oracle Corporation | Oracle Advanced Inbound Telephony | CWE-284 | Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Bu… |
| CVE-2026-60573 | 6.3 | 16.7 | Oracle Corporation | Oracle Partner Management | CWE-284 | Vulnerability in the Oracle Partner Management product of Oracle E-Business S… |
| CVE-2026-60574 | 6.3 | 16.7 | Oracle Corporation | Oracle Content Manager | CWE-306 | Vulnerability in the Oracle Content Manager product of Oracle E-Business Suit… |
| CVE-2026-60587 | 6.3 | 16.7 | Oracle Corporation | Oracle Project Foundation | CWE-284 | Vulnerability in the Oracle Project Foundation product of Oracle E-Business S… |