Edition of July 21, 2026, continued — page 3 of 3. Back to page 1 · page 2
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-60688 | 6.3 | 16.7 | Oracle Corporation | Oracle Scheduler | CWE-284 | Vulnerability in the Oracle Scheduler product of Oracle E-Business Suite (com… |
| CVE-2026-61304 | 6.3 | 16.7 | Oracle Corporation | Oracle Price Protection | CWE-200 | Vulnerability in the Oracle Price Protection product of Oracle E-Business Sui… |
| CVE-2026-47685 | 8.7 | 16.5 | FOGProject | fogproject | CWE-79 | FOGProject has stored XSS via unauthenticated inventory service renders unesc… |
| CVE-2023-37507 | 6.9 | 16.5 | HCLSoftware | DevOps Plan | CWE-497 | An information disclosure vulnerability affects HCL DevOps Plan |
| CVE-2026-10675 | 6.5 | 16.5 | zephyrproject | zephyr | CWE-400 | Bluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely,… |
| CVE-2026-61051 | 6.3 | 16.5 | Oracle Corporation | Oracle Concurrent Processing | CWE-284 | Vulnerability in the Oracle Concurrent Processing product of Oracle E-Busines… |
| CVE-2026-61256 | 6.3 | 16.5 | Oracle Corporation | Oracle Advanced Inbound Telephony | CWE-284 | Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Bu… |
| CVE-2026-61274 | 6.3 | 16.5 | Oracle Corporation | Oracle Product Hub | CWE-284 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c… |
| CVE-2026-61275 | 6.3 | 16.5 | Oracle Corporation | Oracle Product Hub | CWE-284 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c… |
| CVE-2026-61277 | 6.3 | 16.5 | Oracle Corporation | Oracle Marketing | CWE-284 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (com… |
| CVE-2026-61280 | 6.3 | 16.5 | Oracle Corporation | Oracle Sales for Handhelds | CWE-284 | Vulnerability in the Oracle Sales for Handhelds product of Oracle E-Business … |
| CVE-2026-61036 | 3.8 | 16.5 | Oracle Corporation | Oracle HRMS (Norway) | CWE-284 | Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite … |
| CVE-2026-15791 | 1.8 | 16.4 | moby | BuildKit | CWE-22 | LLB file operation can be tricked to remove /tmp directory contents |
| CVE-2026-60193 | 8.5 | 16.3 | Oracle Corporation | MySQL Connectors | CWE-284 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Con… |
| CVE-2026-16400 | 7.5 | 16.3 | Mozilla | Firefox | CWE-200 | Information disclosure in the DOM: Security component |
| CVE-2026-62495 | 7.5 | 16.3 | Oracle Corporation | Oracle Process Manufacturing Process Execution | CWE-284 | Vulnerability in the Oracle Process Manufacturing Process Execution product o… |
| CVE-2026-62493 | 7.5 | 16.3 | Oracle Corporation | Oracle Purchasing | CWE-269 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co… |
| CVE-2026-64822 | 6.9 | 16.2 | thiagopena | djangoSIGE | CWE-203 | djangoSIGE 1.10 User Enumeration via ForgotPasswordView |
| CVE-2026-16266 | 6.3 | 16.2 | n/a | mongo-object | CWE-1321 | Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype… |
| CVE-2026-62490 | 5.3 | 16.3 | Oracle Corporation | Oracle Contracts Integration | CWE-200 | Vulnerability in the Oracle Contracts Integration product of Oracle E-Busines… |
| CVE-2026-65057 | 9.2 | 16.1 | keephq | keep | CWE-918 | Keep Unauthenticated Server-Side Request Forgery via POST /providers/healthcheck |
| CVE-2026-60671 | 8.6 | 16.1 | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | CWE-284 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-56147 | 7.1 | 16.1 | Elastic | Kibana | CWE-639 | Authorization Bypass Through User-Controlled Key in Kibana Leading to Unautho… |
| CVE-2026-60985 | 7.1 | 16.1 | Oracle Corporation | Oracle Project Portfolio Analysis | CWE-284 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Bu… |
| CVE-2026-60324 | 6.5 | 16.1 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60411 | 6.5 | 16.2 | Oracle Corporation | TimesTen In-Memory Database | CWE-400 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen I… |
| CVE-2026-16406 | 9.1 | 16.0 | Mozilla | Firefox | CWE-693 | Mitigation bypass in the Networking component |
| CVE-2026-60313 | 8.8 | 15.9 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-62478 | 8.8 | 15.9 | Oracle Corporation | Oracle Public Sector Financials | CWE-269 | Vulnerability in the Oracle Public Sector Financials product of Oracle E-Busi… |
| CVE-2026-62534 | 8.8 | 15.9 | Oracle Corporation | Oracle Applications Framework | CWE-269 | Vulnerability in the Oracle Applications Framework product of Oracle E-Busine… |
| CVE-2026-62476 | 8.8 | 15.9 | Oracle Corporation | Oracle Public Sector Payroll | CWE-269 | Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Busines… |
| CVE-2026-62496 | 8.8 | 15.9 | Oracle Corporation | Oracle Yard Management | CWE-269 | Vulnerability in the Oracle Yard Management product of Oracle E-Business Suit… |
| CVE-2026-47010 | 3.7 | 15.8 | Oracle Corporation | Oracle Java SE | CWE-284 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM E… |
| CVE-2026-46989 | 9.1 | 15.7 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-60533 | 8.0 | 15.7 | Oracle Corporation | Oracle Identity Manager Connector | CWE-284 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-60579 | 8.0 | 15.7 | Oracle Corporation | Oracle Enterprise Command Center Framework | CWE-287 | Vulnerability in the Oracle Enterprise Command Center Framework product of Or… |
| CVE-2026-21577 | 7.1 | 15.8 | Atlassian | Confluence Data Center | CWE-400 | This High severity DoS (Denial of Service) vulnerability was introduced in ve… |
| CVE-2026-15792 | 6.0 | 15.7 | moby | BuildKit | CWE-20 | Possible panic when incorrect parameters sent from frontend |
| CVE-2026-16396 | 8.8 | 15.4 | Mozilla | Firefox | CWE-269 | Privilege escalation in WebExtensions |
| CVE-2026-15145 | 6.4 | 15.5 | wpdevteam | Essential Addons for Elementor – Popular Elementor Templates & Widgets | CWE-79 | Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Store… |
| CVE-2026-63136 | 6.5 | 15.4 | Elastic | Elasticsearch | CWE-400 | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-63140 | 6.5 | 15.4 | Elastic | Elasticsearch | CWE-617 | Reachable Assertion in Elasticsearch Leading to Denial of Service |
| CVE-2026-63144 | 6.5 | 15.4 | Elastic | Elasticsearch | CWE-674 | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-63263 | 6.5 | 15.4 | Elastic | Elasticsearch | CWE-400 | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-16439 | 5.8 | 15.3 | Eclipse Foundation | OpenJ9 | CWE-124 | Eclipse OpenJ9 : Using -Xtrace to trace method arguments can lead to buffer u… |
| CVE-2026-60657 | 7.7 | 15.1 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-61046 | 6.6 | 15.2 | Oracle Corporation | Oracle Production Scheduling | CWE-284 | Vulnerability in the Oracle Production Scheduling product of Oracle E-Busines… |
| CVE-2026-61190 | 6.4 | 15.1 | Oracle Corporation | Oracle Agile Engineering Data Management | CWE-284 | Vulnerability in the Oracle Agile Engineering Data Management product of Orac… |
| CVE-2026-61081 | 2.7 | 15.3 | Oracle Corporation | MySQL Server | CWE-200 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-47407 | 9.4 | 15.1 | MervinPraison | praisonai-platform | CWE-269 | PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation |
| CVE-2026-62559 | 6.8 | 15.0 | Oracle Corporation | Oracle HRMS (US) | CWE-200 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (com… |
| CVE-2026-60307 | 4.3 | 15.1 | Oracle Corporation | Oracle Coherence | CWE-200 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-63080 | 7.1 | 15.0 | aptabase | aptabase | CWE-89 | Aptabase SQL Injection via ClickHouse query backend |
| CVE-2026-46985 | 5.3 | 14.9 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-60357 | 3.7 | 14.9 | Oracle Corporation | Siebel CRM Integration | CWE-287 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-60339 | 3.1 | 14.9 | Oracle Corporation | Oracle Project Manufacturing | CWE-200 | Vulnerability in the Oracle Project Manufacturing product of Oracle E-Busines… |
| CVE-2026-60922 | 3.1 | 14.9 | Oracle Corporation | Oracle iSupplier Portal | CWE-200 | Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Sui… |
| CVE-2026-60930 | 3.1 | 14.9 | Oracle Corporation | Oracle Public Sector Financials | CWE-200 | Vulnerability in the Oracle Public Sector Financials product of Oracle E-Busi… |
| CVE-2026-60939 | 3.1 | 14.9 | Oracle Corporation | Oracle Project Contracts | CWE-200 | Vulnerability in the Oracle Project Contracts product of Oracle E-Business Su… |
| CVE-2026-60312 | 8.1 | 14.8 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-62547 | 8.1 | 14.8 | Oracle Corporation | Oracle Workflow | CWE-287 | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (comp… |
| CVE-2026-59849 | 7.5 | 14.8 | Red Hat | Red Hat Hardened Images | CWE-835 | Libssh: libssh: denial of service via automatic certificate authentication loop |
| CVE-2026-60620 | 6.4 | 14.8 | Oracle Corporation | JD Edwards EnterpriseOne Configurator | CWE-20 | Vulnerability in the JD Edwards EnterpriseOne Configurator product of Oracle … |
| CVE-2026-8285 | 4.3 | 14.9 | Universal Software Inc. | FlexCity | CWE-307 | OTP Bypass in Universal Sotware's FlexCity |
| CVE-2026-59143 | 6.3 | 14.7 | EGOR | Data::RoaringBitmap::Shared | CWE-125 | Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bou… |
| CVE-2026-61103 | 5.9 | 14.7 | Oracle Corporation | PeopleSoft Enterprise CS Campus Community | CWE-200 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Ora… |
| CVE-2026-12548 | 4.2 | 14.7 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Libsoup: heap out-of-bounds read in libsoup due to integer truncation |
| CVE-2026-56144 | 6.5 | 14.5 | Elastic | Elasticsearch | CWE-863 | Incorrect Authorization in Elasticsearch Leading to Information Disclosure |
| CVE-2026-60832 | 4.1 | 14.3 | Oracle Corporation | Oracle Interaction Blending | CWE-284 | Vulnerability in the Oracle Interaction Blending product of Oracle E-Business… |
| CVE-2026-47030 | 3.1 | 14.3 | Oracle Corporation | Oracle Java SE | CWE-284 | Vulnerability in Oracle Java SE (component: JavaFX). The supported version th… |
| CVE-2026-47034 | 3.1 | 14.3 | Oracle Corporation | Oracle Java SE | CWE-284 | Vulnerability in Oracle Java SE (component: JavaFX). The supported version th… |
| CVE-2026-62508 | 3.1 | 14.3 | Oracle Corporation | Oracle Time and Labor | CWE-400 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite… |
| CVE-2026-47017 | 8.7 | 14.2 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | CWE-284 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-60470 | 8.7 | 14.2 | Oracle Corporation | WebCenter Content: Imaging | CWE-284 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd… |
| CVE-2026-65056 | 8.3 | 14.1 | mzxrai | mcp-webresearch | CWE-918 | mcp-webresearch Server-Side Request Forgery in visit_page Due to Missing Inte… |
| CVE-2026-47406 | 8.1 | 14.2 | MervinPraison | praisonai-platform | CWE-639 | praisonai-platform: Dependency endpoints accept any issue_id and dep_id witho… |
| CVE-2026-47408 | 6.5 | 14.2 | MervinPraison | praisonai-platform | CWE-639 | praisonai-platform: list_issue_activity returns activity log for any issue re… |
| CVE-2026-47002 | 6.1 | 14.1 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-601 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-60802 | 6.1 | 14.1 | Oracle Corporation | Oracle E-Business Intelligence | CWE-284 | Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Busin… |
| CVE-2026-60815 | 6.1 | 14.1 | Oracle Corporation | Oracle iStore | CWE-284 | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (compon… |
| CVE-2026-62444 | 6.1 | 14.1 | Oracle Corporation | Oracle Contracts Integration | CWE-285 | Vulnerability in the Oracle Contracts Integration product of Oracle E-Busines… |
| CVE-2026-62505 | 6.1 | 14.1 | Oracle Corporation | Oracle Time and Labor | CWE-284 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite… |
| CVE-2026-60152 | 5.4 | 14.1 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | CWE-285 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-60912 | 5.4 | 14.2 | Oracle Corporation | Oracle Property Manager | CWE-284 | Vulnerability in the Oracle Property Manager product of Oracle E-Business Sui… |
| CVE-2026-60868 | 7.1 | 14.0 | Oracle Corporation | Oracle Advanced Pricing | CWE-284 | Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Sui… |
| CVE-2026-60623 | 7.1 | 14.0 | Oracle Corporation | MySQL Connectors | CWE-306 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Con… |
| CVE-2026-61143 | 6.4 | 13.9 | Oracle Corporation | Oracle Communications Convergent Charging Controller | CWE-284 | Vulnerability in the Oracle Communications Convergent Charging Controller pro… |
| CVE-2026-47121 | 6.1 | 13.9 | sparkle-project | Sparkle | CWE-22 | Sparkle: Binary delta apply intermediate-symlink traversal in malicious .delta |
| CVE-2026-46990 | 7.3 | 13.8 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-65314 | 5.3 | 13.8 | ElectricSQL | Electric Postgres Sync | CWE-203 | Electric Postgres Sync Excluded-Column Value Inference via Subset Where Clauses |
| CVE-2026-12547 | 3.4 | 13.7 | Red Hat | Red Hat Enterprise Linux 10 | CWE-201 | Libsoup: information disclosure in libsoup via soupauthmanager proxy credenti… |
| CVE-2026-16461 | 6.5 | 13.7 | Red Hat | Red Hat Enterprise Linux 10 | CWE-121 | Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode vers… |
| CVE-2026-60397 | 4.3 | 13.7 | Oracle Corporation | Oracle GoldenGate | CWE-404 | Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supp… |
| CVE-2026-47060 | 6.5 | 13.6 | Oracle Corporation | Oracle Database Server | CWE-284 | Vulnerability in the JDBC component of Oracle Database Server. Supported vers… |
| CVE-2026-15342 | 6.5 | 13.5 | Plane | Plane | CWE-552 | CVE-2026-15342 |
| CVE-2026-60408 | 4.3 | 13.3 | Oracle Corporation | TimesTen In-Memory Database | CWE-200 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen I… |
| CVE-2026-46999 | 7.0 | 13.3 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-306 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-62484 | 5.9 | 13.2 | Oracle Corporation | Oracle Contracts Integration | CWE-284 | Vulnerability in the Oracle Contracts Integration product of Oracle E-Busines… |
| CVE-2026-47032 | 2.6 | 13.3 | Oracle Corporation | Siebel CRM End User | CWE-284 | Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (compon… |
| CVE-2026-8988 | 8.6 | 13.1 | Autel | MaxiCharger Single | CWE-1191 | Access to Bootloader |
| CVE-2026-60739 | 7.1 | 13.1 | Oracle Corporation | Oracle Field Service | CWE-284 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite … |
| CVE-2026-46975 | 5.8 | 13.1 | Oracle Corporation | Oracle Database Server | CWE-284 | Vulnerability in the RDBMS component of Oracle Database Server. Supported ver… |
| CVE-2026-60426 | 8.5 | 13.1 | Oracle Corporation | Oracle Unified Directory | CWE-284 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60421 | 8.2 | 13.0 | Oracle Corporation | Oracle Unified Directory | CWE-284 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-62456 | 8.2 | 13.0 | Oracle Corporation | Oracle HRMS (UK) | CWE-269 | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (com… |
| CVE-2026-60468 | 7.1 | 13.1 | Oracle Corporation | WebCenter Content: Imaging | CWE-284 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd… |
| CVE-2026-62557 | 7.1 | 13.1 | Oracle Corporation | Oracle HRMS (UK) | CWE-284 | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (com… |
| CVE-2026-60666 | 6.8 | 13.0 | Oracle Corporation | PeopleSoft Enterprise HCM Human Resources | CWE-284 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Ora… |
| CVE-2026-60864 | 6.4 | 13.0 | Oracle Corporation | Oracle Order Management | CWE-200 | Vulnerability in the Oracle Order Management product of Oracle E-Business Sui… |
| CVE-2026-47001 | 5.4 | 13.0 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-60154 | 5.4 | 13.0 | Oracle Corporation | Oracle Application Object Library | CWE-284 | Vulnerability in the Oracle Application Object Library product of Oracle E-Bu… |
| CVE-2026-60231 | 5.4 | 13.0 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60344 | 5.4 | 13.0 | Oracle Corporation | Oracle HRMS (France) | CWE-284 | Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite … |
| CVE-2026-60588 | 5.4 | 13.0 | Oracle Corporation | Oracle Enterprise Asset Management | CWE-284 | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-B… |
| CVE-2026-60717 | 5.4 | 13.0 | Oracle Corporation | Oracle Complex Maintenance, Repair and Overhaul | CWE-284 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product … |
| CVE-2026-60794 | 5.4 | 13.0 | Oracle Corporation | Oracle TeleSales | CWE-284 | Vulnerability in the Oracle TeleSales product of Oracle E-Business Suite (com… |
| CVE-2026-61060 | 5.4 | 13.0 | Oracle Corporation | Oracle E-Business Suite Secure Enterprise Search | CWE-284 | Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product… |
| CVE-2026-61064 | 5.4 | 13.0 | Oracle Corporation | Oracle iRecruitment | CWE-639 | Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (… |
| CVE-2026-61075 | 5.4 | 13.0 | Oracle Corporation | Oracle Self-Service Human Resources | CWE-284 | Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-… |
| CVE-2026-61080 | 5.4 | 13.0 | Oracle Corporation | Oracle Public Sector Human Resources | CWE-284 | Vulnerability in the Oracle Public Sector Human Resources product of Oracle E… |
| CVE-2026-61083 | 5.4 | 13.0 | Oracle Corporation | Oracle Performance Management | CWE-284 | Vulnerability in the Oracle Performance Management product of Oracle E-Busine… |
| CVE-2026-61152 | 5.4 | 13.0 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-61200 | 5.4 | 13.0 | Oracle Corporation | Oracle Labor Distribution | CWE-284 | Vulnerability in the Oracle Labor Distribution product of Oracle E-Business S… |
| CVE-2026-61221 | 5.4 | 13.0 | Oracle Corporation | Oracle Item Master | CWE-284 | Vulnerability in the Oracle Item Master product of Oracle E-Business Suite (c… |
| CVE-2026-61252 | 5.4 | 13.0 | Oracle Corporation | Oracle HRMS (Hong Kong) | CWE-284 | Vulnerability in the Oracle HRMS (Hong Kong) product of Oracle E-Business Sui… |
| CVE-2026-61255 | 5.4 | 13.0 | Oracle Corporation | Oracle HRMS (New Zealand) | CWE-284 | Vulnerability in the Oracle HRMS (New Zealand) product of Oracle E-Business S… |
| CVE-2026-61260 | 5.4 | 13.0 | Oracle Corporation | Oracle HRMS (UK) | CWE-284 | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (com… |
| CVE-2026-61264 | 5.4 | 13.0 | Oracle Corporation | Oracle Call Center Technology | CWE-284 | Vulnerability in the Oracle Call Center Technology product of Oracle E-Busine… |
| CVE-2026-60816 | 5.3 | 13.0 | Oracle Corporation | Oracle iStore | CWE-284 | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (compon… |
| CVE-2026-16454 | 4.3 | 13.1 | Eclipse Foundation | eclipse-hawkbit/hawkbit | CWE-284 | Privilege Escalation in Eclipse hawkBit DDI allows Tenant-Isolated Firmware E… |
| CVE-2026-60724 | 5.4 | 12.8 | Oracle Corporation | Oracle Customer Interaction History | CWE-284 | Vulnerability in the Oracle Customer Interaction History product of Oracle E-… |
| CVE-2026-61261 | 5.4 | 12.8 | Oracle Corporation | Oracle Knowledge Management | CWE-284 | Vulnerability in the Oracle Knowledge Management product of Oracle E-Business… |
| CVE-2026-61263 | 5.4 | 12.8 | Oracle Corporation | Oracle Scripting | CWE-284 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (com… |
| CVE-2026-61257 | 5.4 | 12.8 | Oracle Corporation | Oracle iSupport | CWE-284 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (comp… |
| CVE-2026-60249 | 9.0 | 12.7 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-61240 | 8.2 | 12.6 | Oracle Corporation | PeopleSoft Enterprise FIN Common Objects Argentina | CWE-200 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina produ… |
| CVE-2026-46997 | 6.5 | 12.4 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-306 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-62488 | 6.5 | 12.4 | Oracle Corporation | Oracle Contracts Integration | CWE-284 | Vulnerability in the Oracle Contracts Integration product of Oracle E-Busines… |
| CVE-2026-16358 | 9.8 | 12.3 | Mozilla | Firefox | CWE-346 | Site isolation issue in the Graphics: WebRender component |
| CVE-2026-52475 | 6.1 | 12.3 | n/a | n/a | CWE-79 | Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allows a remote attack… |
| CVE-2026-16349 | 9.8 | 12.2 | Mozilla | Firefox | CWE-346 | Same-origin policy bypass in the DOM: Navigation component |
| CVE-2026-8933 | 7.8 | 12.2 | — | snapd | CWE-250 | snap-confine Local Privilege Escalation via Capabilities Misconfiguration or … |
| CVE-2026-47414 | 7.6 | 12.2 | MervinPraison | praisonai-platform | CWE-639 | praisonai-platform: Label endpoints accept any label_id and any issue_id with… |
| CVE-2026-47657 | 7.1 | 12.2 | humhub | humhub | CWE-862 | HumHub Missing Authorization on Remove All Space Members Action |
| CVE-2026-16401 | 8.8 | 12.0 | Mozilla | Firefox | CWE-269 | Privilege escalation in the Data Loss Prevention component |
| CVE-2026-60305 | 7.1 | 12.0 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60322 | 6.5 | 12.1 | Oracle Corporation | Oracle Applications Manager | CWE-306 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business… |
| CVE-2026-60638 | 8.8 | 11.9 | Oracle Corporation | Oracle WebCenter Content | CWE-20 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60664 | 8.8 | 11.9 | Oracle Corporation | Oracle WebCenter Content | CWE-79 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60351 | 4.8 | 11.8 | Oracle Corporation | Oracle JDeveloper | CWE-284 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (c… |
| CVE-2026-61056 | 4.8 | 11.8 | Oracle Corporation | PeopleSoft Enterprise FIN Grants | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Grants product of Oracle Peopl… |
| CVE-2026-61057 | 4.8 | 11.8 | Oracle Corporation | PeopleSoft Enterprise FIN eSettlements | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle… |
| CVE-2026-61123 | 4.2 | 11.8 | Oracle Corporation | Oracle HRMS (US) | CWE-200 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (com… |
| CVE-2026-47038 | 2.7 | 11.9 | Oracle Corporation | Oracle Database Server | CWE-306 | Vulnerability in the RDBMS component of Oracle Database Server. Supported ver… |
| CVE-2026-62567 | 7.7 | 11.7 | Oracle Corporation | Oracle HRMS (UK) | CWE-200 | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (com… |
| CVE-2026-47709 | 6.9 | 11.8 | strukturag | libheif | CWE-476 | libheif has a NULL pointer dereference in heif_image_handle_get_image_tiling … |
| CVE-2026-62562 | 6.5 | 11.7 | Oracle Corporation | Oracle HRMS (US) | CWE-284 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (com… |
| CVE-2026-47061 | 5.6 | 11.7 | Oracle Corporation | Oracle Database Server | CWE-284 | Vulnerability in the JDBC component of Oracle Database Server. Supported vers… |
| CVE-2026-60164 | 3.1 | 11.8 | Oracle Corporation | Oracle Java SE | CWE-693 | Vulnerability in Oracle Java SE (component: JavaFX). The supported version th… |
| CVE-2026-60353 | 3.1 | 11.8 | Oracle Corporation | Oracle JDeveloper | CWE-284 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (c… |
| CVE-2026-62494 | 8.1 | 11.7 | Oracle Corporation | Oracle Time and Labor | CWE-284 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite… |
| CVE-2026-62497 | 8.1 | 11.7 | Oracle Corporation | Oracle Flow Manufacturing | CWE-284 | Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business S… |
| CVE-2026-62504 | 8.1 | 11.7 | Oracle Corporation | Oracle Time and Labor | CWE-284 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite… |
| CVE-2026-62530 | 8.1 | 11.7 | Oracle Corporation | Oracle HRMS (France) | CWE-284 | Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite … |
| CVE-2026-62560 | 7.7 | 11.7 | Oracle Corporation | Oracle HRMS (Norway) | CWE-200 | Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite … |
| CVE-2026-60929 | 3.1 | 11.6 | Oracle Corporation | Oracle Public Sector Financials | CWE-284 | Vulnerability in the Oracle Public Sector Financials product of Oracle E-Busi… |
| CVE-2026-60937 | 3.1 | 11.6 | Oracle Corporation | Oracle Labor Distribution | CWE-284 | Vulnerability in the Oracle Labor Distribution product of Oracle E-Business S… |
| CVE-2026-16375 | 9.8 | 11.4 | Mozilla | Firefox | CWE-346 | Site isolation issue in the Networking: HTTP component |
| CVE-2026-47413 | 9.6 | 11.3 | MervinPraison | praisonai-platform | CWE-269 | praisonai-platform: Any workspace member can add arbitrary user as owner via … |
| CVE-2026-47416 | 9.6 | 11.3 | MervinPraison | praisonai-platform | CWE-269 | praisonai-platform: Any workspace member can promote themselves (or any other… |
| CVE-2026-47417 | 8.1 | 11.3 | MervinPraison | praisonai-platform | CWE-639 | praisonai-platform: Comment endpoints accept any issue_id without workspace o… |
| CVE-2026-46556 | 6.5 | 11.3 | flaskbb | flaskbb | CWE-918 | FlaskBB: SSRF in get_image_info() via unrestricted avatar URL |
| CVE-2026-60669 | 5.9 | 11.2 | Oracle Corporation | PeopleSoft Enterprise HCM Global Payroll Mexico | CWE-284 | Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Mexico product … |
| CVE-2026-8593 | 5.3 | 11.1 | Checkmk GmbH | Checkmk | CWE-862 | Fix Business Intelligence API Pack permission |
| CVE-2026-60494 | 7.0 | 11.0 | Oracle Corporation | JD Edwards EnterpriseOne General Ledger | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracl… |
| CVE-2026-16417 | 3.1 | 10.9 | Chrome | CWE-457 | Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a … | |
| CVE-2026-16387 | 9.8 | 10.7 | Mozilla | Firefox | CWE-200 | Site isolation issue in the Networking component |
| CVE-2026-1372 | 4.3 | 10.6 | themeum | Tutor LMS Elementor Addons | CWE-862 | Tutor LMS Elementor Addons <= 4.0.0 - Missing Authorization to Authenticated … |
| CVE-2026-13694 | 6.5 | 10.5 | Unknown | Bit Form | CWE-862 | Bit Form < 3.1.0 - Unauthenticated Workflow Trigger via Authentication Bypass |
| CVE-2026-61071 | 3.3 | 10.6 | Oracle Corporation | PeopleSoft Enterprise FIN Engineering Argentina | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Engineering Argentina product … |
| CVE-2026-65054 | 8.2 | 10.5 | MediaCMS | MediaCMS | CWE-863 | MediaCMS Private Media Metadata Disclosure via Playlist Ownership Loophole |
| CVE-2026-15793 | 7.3 | 10.4 | moby | BuildKit | CWE-88 | Git source checkout from a bundle file could lead to command injection |
| CVE-2026-46981 | 7.2 | 10.4 | Oracle Corporation | Oracle Utilities Network Management System | CWE-284 | Vulnerability in the Oracle Utilities Network Management System product of Or… |
| CVE-2026-46996 | 7.1 | 10.4 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-60772 | 7.1 | 10.4 | Oracle Corporation | Oracle Financials Common Modules | CWE-284 | Vulnerability in the Oracle Financials Common Modules product of Oracle E-Bus… |
| CVE-2026-60987 | 7.1 | 10.4 | Oracle Corporation | Oracle Project Portfolio Analysis | CWE-284 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Bu… |
| CVE-2026-21954 | 4.3 | 10.4 | Oracle Corporation | Oracle Retail Xstore Point of Service | CWE-284 | Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle … |
| CVE-2026-46980 | 4.3 | 10.4 | Oracle Corporation | Oracle Utilities Network Management System | CWE-284 | Vulnerability in the Oracle Utilities Network Management System product of Or… |
| CVE-2026-60434 | 4.3 | 10.4 | Oracle Corporation | Oracle Transportation Management | CWE-287 | Vulnerability in the Oracle Transportation Management product of Oracle Suppl… |
| CVE-2026-6792 | 6.5 | 10.3 | Universal Software Inc. | FlexCity | CWE-862 | Improper Authorization in Universal Sotware's FlexCity |
| CVE-2026-15156 | 6.4 | 10.3 | wpdevteam | Essential Addons for Elementor – Popular Elementor Templates & Widgets | CWE-79 | Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Store… |
| CVE-2026-61266 | 6.3 | 10.4 | Oracle Corporation | Oracle Supply Chain Globalization | CWE-89 | Vulnerability in the Oracle Supply Chain Globalization product of Oracle E-Bu… |
| CVE-2026-62527 | 6.3 | 10.4 | Oracle Corporation | Oracle Learning Management | CWE-284 | Vulnerability in the Oracle Learning Management product of Oracle E-Business … |
| CVE-2026-62528 | 6.3 | 10.4 | Oracle Corporation | Oracle HCM Configuration Workbench | CWE-284 | Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-B… |
| CVE-2026-16451 | 2.1 | 10.4 | zsadmin2025 | ZS-Admin | CWE-284 | zsadmin2025 ZS-Admin com.zs.file.controller.SysFileController upload unrestri… |
| CVE-2026-60804 | 2.0 | 10.3 | Oracle Corporation | Oracle E-Business Intelligence | CWE-284 | Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Busin… |
| CVE-2026-16415 | 5.4 | 10.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in Extensions in Google Chrome pri… | |
| CVE-2026-63143 | 4.3 | 10.1 | Elastic | Kibana | CWE-862 | Missing Authorization in Kibana Leading to Unauthorized Information Disclosure |
| CVE-2026-16334 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System prescriptionorder.php sql injection |
| CVE-2026-47178 | 7.8 | 10.0 | strukturag | libheif | CWE-787 | libheif has Heap Out Of Bounds Write in unci subsystem |
| CVE-2026-16403 | 6.5 | 9.9 | Mozilla | Firefox | CWE-451 | Spoofing issue in the Address Bar component |
| CVE-2026-60907 | 5.0 | 9.9 | Oracle Corporation | Oracle Installed Base | CWE-284 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite… |
| CVE-2026-60834 | 7.1 | 9.8 | Oracle Corporation | Oracle Solaris | CWE-284 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Uti… |
| CVE-2026-60628 | 3.7 | 9.8 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-60634 | 8.8 | 9.6 | Oracle Corporation | Oracle WebCenter Content | CWE-20 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60637 | 8.8 | 9.6 | Oracle Corporation | Oracle WebCenter Content | CWE-20 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60694 | 5.4 | 9.7 | Oracle Corporation | Oracle Enterprise Asset Management | CWE-284 | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-B… |
| CVE-2026-62479 | 5.4 | 9.7 | Oracle Corporation | Oracle Public Sector Financials | CWE-284 | Vulnerability in the Oracle Public Sector Financials product of Oracle E-Busi… |
| CVE-2026-60684 | 4.6 | 9.7 | Oracle Corporation | Oracle Applications Framework | CWE-284 | Vulnerability in the Oracle Applications Framework product of Oracle E-Busine… |
| CVE-2026-47411 | 6.5 | 9.5 | MervinPraison | praisonai-platform | CWE-269 | praisonai-platform: Any workspace member can rewrite workspace name, descript… |
| CVE-2026-60697 | 6.3 | 9.4 | Oracle Corporation | Oracle Site Hub | CWE-284 | Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (comp… |
| CVE-2026-62453 | 6.3 | 9.5 | Oracle Corporation | Oracle HRMS (UK) | CWE-200 | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (com… |
| CVE-2026-62474 | 6.3 | 9.5 | Oracle Corporation | Oracle Lease and Finance Management | CWE-269 | Vulnerability in the Oracle Lease and Finance Management product of Oracle E-… |
| CVE-2026-62524 | 6.3 | 9.4 | Oracle Corporation | Oracle HRMS (US) | CWE-200 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (com… |
| CVE-2026-62525 | 6.3 | 9.4 | Oracle Corporation | Oracle Quality | CWE-284 | Vulnerability in the Oracle Quality product of Oracle E-Business Suite (compo… |
| CVE-2026-62542 | 6.3 | 9.5 | Oracle Corporation | Oracle Advanced Benefits | CWE-284 | Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Su… |
| CVE-2026-16449 | 2.1 | 9.2 | zsadmin2025 | ZS-Admin | CWE-74 | zsadmin2025 ZS-Admin com.zs.sys.dept.controller.SysDeptController page OrderI… |
| CVE-2026-64877 | 9.4 | 9.1 | Tenable, Inc. | Security Center | CWE-20 | An authenticated non-admin user can exploit a SQL injection flaw in the ticke… |
| CVE-2026-47035 | 3.1 | 9.1 | Oracle Corporation | Oracle Java SE | CWE-284 | Vulnerability in Oracle Java SE (component: JavaFX). The supported version th… |
| CVE-2026-62507 | 5.3 | 9.0 | Oracle Corporation | Oracle Time and Labor | CWE-284 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite… |
| CVE-2026-62483 | 4.3 | 8.9 | Oracle Corporation | Oracle Project Contracts | CWE-284 | Vulnerability in the Oracle Project Contracts product of Oracle E-Business Su… |
| CVE-2026-47254 | 6.1 | 8.8 | strukturag | libheif | CWE-125 | libheif Has Heap Buffer Overflow in `Track::get_next_sample_raw_data()` -- OO… |
| CVE-2026-16317 | 8.3 | 8.5 | AWS | s2n-tls | CWE-354 | Silent Drop of TLS 1.3 Encrypted Records in s2n-tls |
| CVE-2026-63141 | 5.4 | 8.5 | Elastic | Kibana | CWE-862 | Missing Authorization in Kibana Leading to Unauthorized Access to Cloud Conne… |
| CVE-2026-15432 | 8.2 | 8.4 | Tink-Java | CWE-208 | Observable Timing Discrepancy in Tink-Java and Tink-Android ChunkedMacVerific… | |
| CVE-2026-60643 | 8.0 | 8.4 | Oracle Corporation | Oracle WebCenter Content | CWE-352 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60709 | 4.2 | 8.4 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-284 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-64880 | 7.1 | 8.2 | Tenable, Inc. | Security Center | CWE-89 | Blind SQL Injection |
| CVE-2026-47688 | 8.2 | 8.2 | FOGProject | fogproject | CWE-862 | FOGProject has unauthenticated clearAES and clearPMTasks that allow remote de… |
| CVE-2026-60648 | 8.0 | 8.2 | Oracle Corporation | Oracle WebCenter Content | CWE-20 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-65009 | 5.3 | 8.2 | openremote | openremote | CWE-200 | OpenRemote before 1.26.2 Information Disclosure via Syslog REST API |
| CVE-2026-11876 | 5.0 | 8.2 | zenml-io | zenml-io/zenml | CWE-862 | Missing Authorization in get_deployed_stack Endpoint in zenml-io/zenml |
| CVE-2026-64823 | 2.1 | 8.1 | home-assistant | Home Assistant Core | CWE-79 | Home Assistant Core < 2026.5.4 XSS via Shelly media_player.py thumb URI |
| CVE-2026-56820 | 9.1 | 8.1 | netty | netty | CWE-295 | Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks |
| CVE-2026-15782 | 4.9 | 8.1 | smub | WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More | CWE-79 | WPForms <= 2.0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting… |
| CVE-2026-47697 | 7.1 | 8.0 | Shelf-nu | shelf.nu | CWE-863 | Shelf has cross-organization IDOR: authenticated users could read/attach anot… |
| CVE-2026-60775 | 6.7 | 7.9 | Oracle Corporation | Pasta | CWE-284 | Vulnerability in the Pasta product of Oracle E-Business Suite (component: Int… |
| CVE-2026-60776 | 6.7 | 7.9 | Oracle Corporation | Oracle Application Object Library | CWE-284 | Vulnerability in the Oracle Application Object Library product of Oracle E-Bu… |
| CVE-2026-63259 | 4.3 | 8.0 | Elastic | Kibana | CWE-639 | Authorization Bypass Through User-Controlled Key in Kibana Leading to Informa… |
| CVE-2026-62513 | 8.5 | 7.9 | Oracle Corporation | Oracle Process Manufacturing Regulatory Management | CWE-284 | Vulnerability in the Oracle Process Manufacturing Regulatory Management produ… |
| CVE-2026-62565 | 7.1 | 7.9 | Oracle Corporation | Oracle HRMS (US) | CWE-200 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (com… |
| CVE-2026-47251 | 6.8 | 7.8 | strukturag | libheif | CWE-125 | libheif has an incomplete fix for CVE-2026-3949: integer overflow bypass in v… |
| CVE-2026-60527 | 7.1 | 7.7 | Oracle Corporation | Oracle WebLogic Server | CWE-284 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-34316 | 6.1 | 7.7 | Oracle Corporation | Oracle Commerce Service Center | CWE-284 | Vulnerability in the Oracle Commerce Service Center product of Oracle Commerc… |
| CVE-2026-60146 | 6.1 | 7.7 | Oracle Corporation | Oracle Access Manager | CWE-284 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-61254 | 5.4 | 7.7 | Oracle Corporation | Oracle HRMS (Republic of Korea) | CWE-601 | Vulnerability in the Oracle HRMS (Republic of Korea) product of Oracle E-Busi… |
| CVE-2026-11925 | 2.7 | 7.6 | Tanium | Tanium Server | CWE-451 | Tanium addressed a User Interface (UI) Misrepresentation of Critical Informat… |
| CVE-2026-60646 | 8.0 | 7.5 | Oracle Corporation | Oracle WebCenter Content | CWE-79 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60650 | 8.0 | 7.5 | Oracle Corporation | Oracle WebCenter Content | CWE-20 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-56580 | 2.2 | 7.5 | HCLSoftware | MyCloud | CWE-1104 | HCL MyCloud was affected by Using Components with Known Vulnerability |
| CVE-2026-60163 | 8.4 | 7.4 | Oracle Corporation | MySQL Server | CWE-284 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-47015 | 7.1 | 7.4 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | CWE-601 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-15829 | 8.6 | 7.3 | MCP Toolbox for Databases (googleapis/mcp-toolbox) | CWE-89 | SQL Injection and Security Boundary Bypass in googleapis/mcp-toolbox | |
| CVE-2026-60238 | 5.4 | 7.3 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-61174 | 9.0 | 7.1 | Oracle Corporation | Oracle Product Lifecycle Analytics | CWE-284 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Sup… |
| CVE-2026-16397 | 6.5 | 7.1 | Mozilla | Firefox | CWE-1021 | Clickjacking issue in the WebExtensions component in Firefox for Android |
| CVE-2026-56146 | 5.4 | 7.1 | Elastic | Kibana | CWE-863 | Improper Access Control in Kibana Leading to Unauthorized Data Modification a… |
| CVE-2026-16381 | 9.1 | 7.1 | Mozilla | Firefox | CWE-346 | Same-origin policy bypass in the Networking: DNS component |
| CVE-2026-61097 | 9.6 | 7.0 | Oracle Corporation | Oracle Banking Trade Finance Process Management | CWE-601 | Vulnerability in the Oracle Banking Trade Finance Process Management product … |
| CVE-2026-61220 | 6.1 | 6.9 | Oracle Corporation | Oracle Banking Origination | CWE-284 | Vulnerability in the Oracle Banking Origination product of Oracle Financial S… |
| CVE-2026-60282 | 5.4 | 6.9 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-62482 | 5.4 | 6.9 | Oracle Corporation | Oracle Public Sector Financials | CWE-284 | Vulnerability in the Oracle Public Sector Financials product of Oracle E-Busi… |
| CVE-2026-56584 | 5.3 | 6.9 | HCLSoftware | IntelliOps Event Management | CWE-200 | HCL IEM was affected with the Information disclosure nginx server |
| CVE-2026-63142 | 5.0 | 6.9 | Elastic | Kibana | CWE-863 | Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request… |
| CVE-2026-47011 | 2.6 | 7.0 | Oracle Corporation | Siebel CRM Deployment | CWE-203 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-60600 | 7.8 | 6.7 | Oracle Corporation | PeopleSoft Enterprise FIN Project Costing | CWE-306 | Vulnerability in the PeopleSoft Enterprise FIN Project Costing product of Ora… |
| CVE-2026-60633 | 8.8 | 6.6 | Oracle Corporation | Oracle WebCenter Content | CWE-20 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-61204 | 9.0 | 6.5 | Oracle Corporation | PeopleSoft Enterprise FIN Program Management | CWE-269 | Vulnerability in the PeopleSoft Enterprise FIN Program Management product of … |
| CVE-2026-63092 | 5.3 | 6.5 | medienbaecker | kirby-modules | CWE-862 | kirby-modules License Key Disclosure via modules/activate Dialog |
| CVE-2026-56577 | 6.5 | 6.3 | HCLSoftware | MyCloud | CWE-521 | HCL MyCloud affected by Weak Password Policy |
| CVE-2026-60265 | 6.0 | 6.3 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-49092 | 4.3 | 6.4 | Elastic | Kibana | CWE-863 | Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Una… |
| CVE-2026-63262 | 4.3 | 6.4 | Elastic | Kibana | CWE-862 | Missing Authorization in Kibana Leading to Information Disclosure |
| CVE-2026-47390 | 5.5 | 6.2 | MervinPraison | PraisonAI | CWE-918 | PraisonAI spider_tools SSRF protection bypass via alternate loopback host enc… |
| CVE-2026-15812 | 4.8 | 6.2 | Red Hat | Red Hat Enterprise Linux 10 | CWE-290 | Kronosnet: kronosnet: access control list bypass via link id spoofing on unen… |
| CVE-2026-56578 | 2.2 | 6.0 | HCLSoftware | MyCloud | CWE-200 | HCL MyCloud was affected by Server Version Disclosure |
| CVE-2026-14183 | 4.3 | 5.9 | Unknown | Classified Listing | CWE-639 | Classified Listing < 5.3.9 - Subscriber+ Payment Receipt Disclosure via IDOR |
| CVE-2026-47043 | 3.2 | 5.8 | Oracle Corporation | Oracle VM VirtualBox | CWE-200 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-60631 | 9.3 | 5.8 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60625 | 7.8 | 5.8 | Oracle Corporation | Oracle Data Integrator | CWE-863 | Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middlewa… |
| CVE-2026-60350 | 6.5 | 5.8 | Oracle Corporation | Oracle JDeveloper | CWE-200 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (c… |
| CVE-2026-60607 | 5.5 | 5.8 | Oracle Corporation | PeopleSoft Enterprise CS Financial Aid | CWE-200 | Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle… |
| CVE-2026-63145 | 4.3 | 5.8 | Elastic | Kibana | CWE-863 | Incorrect Authorization in Kibana Leading to Machine Learning Audit Log Integ… |
| CVE-2026-60640 | 8.3 | 5.7 | Oracle Corporation | Oracle WebCenter Content | CWE-20 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-16404 | 7.4 | 5.7 | Mozilla | Firefox | CWE-290 | Spoofing issue in Firefox for Android |
| CVE-2026-60723 | 8.4 | 5.5 | Oracle Corporation | Oracle Data Integrator | CWE-863 | Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middlewa… |
| CVE-2026-60837 | 8.4 | 5.5 | Oracle Corporation | Oracle Price Protection | CWE-269 | Vulnerability in the Oracle Price Protection product of Oracle E-Business Sui… |
| CVE-2026-15370 | 7.3 | 5.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-121 | Libssh: libssh: stack buffer overflow in sftp server longname construction |
| CVE-2026-56579 | 3.1 | 5.3 | HCLSoftware | MyCloud | CWE-200 | HCL MyCloud was affected with Exposure of Sensitive Information to an Unautho… |
| CVE-2026-60635 | 8.8 | 5.1 | Oracle Corporation | Oracle WebCenter Content | CWE-79 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60636 | 8.8 | 5.1 | Oracle Corporation | Oracle WebCenter Content | CWE-20 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60639 | 8.8 | 5.1 | Oracle Corporation | Oracle WebCenter Content | CWE-20 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-56587 | 3.7 | 5.2 | HCLSoftware | IntelliOps Event Management | CWE-523 | HCL IEM was affected with Strict transport security not enforced |
| CVE-2026-16422 | 7.5 | 5.1 | Chrome | CWE-20 | Insufficient validation of untrusted input in Certificate in Google Chrome on… | |
| CVE-2026-62443 | 7.1 | 5.0 | Oracle Corporation | Oracle Contracts Integration | CWE-352 | Vulnerability in the Oracle Contracts Integration product of Oracle E-Busines… |
| CVE-2026-60712 | 6.5 | 5.1 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-862 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-60595 | 5.5 | 5.1 | Oracle Corporation | PeopleSoft Enterprise FIN Pay/Bill Management | CWE-306 | Vulnerability in the PeopleSoft Enterprise FIN Pay/Bill Management product of… |
| CVE-2026-60596 | 2.3 | 5.0 | Oracle Corporation | PeopleSoft Enterprise FIN eSettlements | CWE-306 | Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle… |
| CVE-2026-47024 | 5.4 | 4.9 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | CWE-284 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-47048 | 5.4 | 4.9 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | CWE-601 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-47051 | 5.4 | 4.9 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | CWE-601 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-46948 | 4.6 | 4.9 | Oracle Corporation | Oracle Utilities Network Management System | CWE-284 | Vulnerability in the Oracle Utilities Network Management System product of Or… |
| CVE-2026-14185 | 4.3 | 4.9 | Unknown | WPBot | CWE-862 | WPBot AI ChatBot < 8.2.0 - Subscriber+ RAG Settings Update |
| CVE-2026-60763 | 8.4 | 4.8 | Oracle Corporation | Oracle Applications Manager | CWE-284 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business… |
| CVE-2026-62486 | 5.0 | 4.8 | Oracle Corporation | Oracle Contracts Integration | CWE-284 | Vulnerability in the Oracle Contracts Integration product of Oracle E-Busines… |
| CVE-2026-60960 | 8.8 | 4.7 | Oracle Corporation | Oracle SDP Number Portability | CWE-284 | Vulnerability in the Oracle SDP Number Portability product of Oracle E-Busine… |
| CVE-2026-61062 | 8.8 | 4.7 | Oracle Corporation | PeopleSoft Enterprise FIN Cash Management | CWE-269 | Vulnerability in the PeopleSoft Enterprise FIN Cash Management product of Ora… |
| CVE-2026-60150 | 7.8 | 4.7 | Oracle Corporation | Oracle VM VirtualBox | CWE-269 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-60271 | 7.8 | 4.7 | Oracle Corporation | Oracle Coherence | CWE-269 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60530 | 7.8 | 4.7 | Oracle Corporation | Oracle HTTP Server | CWE-269 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (… |
| CVE-2026-60973 | 7.8 | 4.7 | Oracle Corporation | Oracle E-Business Tax | CWE-269 | Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite… |
| CVE-2026-61055 | 7.8 | 4.7 | Oracle Corporation | PeopleSoft Enterprise SCM Order Management | CWE-269 | Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Or… |
| CVE-2026-61090 | 7.8 | 4.7 | Oracle Corporation | Oracle Project Foundation | CWE-269 | Vulnerability in the Oracle Project Foundation product of Oracle E-Business S… |
| CVE-2026-61091 | 7.8 | 4.7 | Oracle Corporation | Oracle Communications Billing and Revenue Management | CWE-269 | Vulnerability in the Oracle Communications Billing and Revenue Management pro… |
| CVE-2026-61126 | 7.8 | 4.7 | Oracle Corporation | Oracle Communications Billing and Revenue Management | CWE-269 | Vulnerability in the Oracle Communications Billing and Revenue Management pro… |
| CVE-2026-60658 | 7.5 | 4.7 | Oracle Corporation | Oracle WebCenter Content | CWE-352 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-64628 | 5.1 | 4.7 | getgrav | grav | CWE-79 | Grav Stored Cross-Site Scripting via Shortcode Attribute Handlers |
| CVE-2026-16398 | 7.5 | 4.6 | Mozilla | Firefox | CWE-200 | Site isolation issue in the Graphics component |
| CVE-2026-16399 | 7.5 | 4.6 | Mozilla | Firefox | CWE-346 | Site isolation issue in the DOM: Navigation component |
| CVE-2026-64821 | 5.3 | 4.7 | thiagopena | djangoSIGE | CWE-352 | djangoSIGE 1.10 CSRF via GET-based Order Cancellation Views |
| CVE-2026-60760 | 4.2 | 4.6 | Oracle Corporation | Oracle Enterprise Asset Management | CWE-284 | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-B… |
| CVE-2026-62489 | 4.2 | 4.6 | Oracle Corporation | Oracle Contracts Integration | CWE-284 | Vulnerability in the Oracle Contracts Integration product of Oracle E-Busines… |
| CVE-2026-61162 | 7.1 | 4.5 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-60401 | 6.5 | 4.5 | Oracle Corporation | TimesTen In-Memory Database | CWE-284 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen I… |
| CVE-2026-60893 | 6.5 | 4.5 | Oracle Corporation | Oracle Payroll | CWE-284 | Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (compo… |
| CVE-2026-61111 | 6.5 | 4.5 | Oracle Corporation | Oracle Application Object Library | CWE-284 | Vulnerability in the Oracle Application Object Library product of Oracle E-Bu… |
| CVE-2026-61169 | 6.5 | 4.5 | Oracle Corporation | Oracle Agile PLM | CWE-284 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-61189 | 6.5 | 4.5 | Oracle Corporation | Oracle Agile Engineering Data Management | CWE-284 | Vulnerability in the Oracle Agile Engineering Data Management product of Orac… |
| CVE-2026-60630 | 5.5 | 4.5 | Oracle Corporation | Oracle APEX | CWE-284 | Vulnerability in Oracle APEX (component: Installation). Supported versions th… |
| CVE-2026-60405 | 3.8 | 4.5 | Oracle Corporation | TimesTen In-Memory Database | CWE-200 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen I… |
| CVE-2026-60847 | 3.4 | 4.5 | Oracle Corporation | Oracle Order Entry | CWE-269 | Vulnerability in the Oracle Order Entry product of Oracle E-Business Suite (c… |
| CVE-2026-47425 | 6.9 | 4.5 | conda | rattler | CWE-22 | Rattler vulnerable to entry-point path traversal in noarch:python install (ar… |
| CVE-2026-61082 | 6.5 | 4.5 | Oracle Corporation | MySQL Connectors | CWE-200 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Con… |
| CVE-2026-64613 | 6.2 | 4.5 | EGOR | Data::Buffer::Shared | CWE-59 | Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mm… |
| CVE-2026-62517 | 5.3 | 4.5 | Oracle Corporation | Oracle Production Scheduling | CWE-345 | Vulnerability in the Oracle Production Scheduling product of Oracle E-Busines… |
| CVE-2026-60449 | 7.1 | 4.4 | Oracle Corporation | Oracle WebCenter Content | CWE-200 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-61132 | 7.6 | 4.3 | Oracle Corporation | Oracle Commerce Platform | CWE-352 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com… |
| CVE-2026-47050 | 7.4 | 4.3 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-61052 | 5.5 | 4.3 | Oracle Corporation | Oracle Solaris | CWE-400 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Fil… |
| CVE-2026-56585 | 4.3 | 4.2 | HCLSoftware | IntelliOps Event Management | CWE-693 | HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing |
| CVE-2026-60762 | 5.7 | 4.2 | Oracle Corporation | Oracle Applications Technology Stack | CWE-284 | Vulnerability in the Oracle Applications Technology Stack product of Oracle E… |
| CVE-2026-59776 | 7.0 | 4.1 | Sony Corporation | FeliCa IC chips | CWE-325 | Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa I… |
| CVE-2026-47022 | 3.3 | 4.1 | Oracle Corporation | GoldenGate Stream Analytics | CWE-400 | Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate… |
| CVE-2026-8284 | 6.1 | 3.9 | Universal Software Inc. | FlexCity | CWE-601 | Open Redirect in Universal Sotware's FlexCity |
| CVE-2026-60310 | 5.4 | 3.9 | Oracle Corporation | Oracle Performance Management | CWE-284 | Vulnerability in the Oracle Performance Management product of Oracle E-Busine… |
| CVE-2026-60569 | 5.1 | 3.9 | Oracle Corporation | MySQL Cluster | CWE-306 | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluste… |
| CVE-2026-60248 | 9.3 | 3.9 | Oracle Corporation | Oracle Coherence | CWE-269 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-62561 | 7.8 | 3.9 | Oracle Corporation | Oracle HRMS (US) | CWE-269 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (com… |
| CVE-2026-60526 | 6.7 | 3.8 | Oracle Corporation | Oracle Java SE | CWE-20 | Vulnerability in Oracle Java SE (component: Installation). Supported versions… |
| CVE-2026-24232 | 4.3 | 3.9 | NVIDIA | Tranformers4Rec | CWE-502 | NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause… |
| CVE-2026-56583 | 3.1 | 3.9 | HCLSoftware | MyCloud | CWE-613 | HCL MyCloud was affected with Concurrent Login Vulnerability. |
| CVE-2026-59146 | 7.8 | 3.8 | EGOR | Data::SpatialHash::Shared | CWE-125 | Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds r… |
| CVE-2026-60886 | 7.6 | 3.8 | Oracle Corporation | Oracle Work in Process | CWE-200 | Vulnerability in the Oracle Work in Process product of Oracle E-Business Suit… |
| CVE-2026-60713 | 4.4 | 3.8 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-284 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-60181 | 6.7 | 3.6 | Oracle Corporation | MySQL Server | CWE-284 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60319 | 6.5 | 3.7 | Oracle Corporation | Oracle Data Integrator | CWE-284 | Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middlewa… |
| CVE-2026-60747 | 6.2 | 3.7 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-14184 | 5.4 | 3.6 | Unknown | Academy LMS | CWE-639 | Academy LMS < 3.8.1 - Subscriber+ Cross-User Lesson Note and Progress Modific… |
| CVE-2026-60318 | 3.3 | 3.7 | Oracle Corporation | Oracle Data Integrator | CWE-200 | Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middlewa… |
| CVE-2026-65069 | 4.0 | 3.6 | EGOR | Data::DisjointSet::Shared | CWE-59 | Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readab… |
| CVE-2026-60183 | 6.4 | 3.5 | Oracle Corporation | MySQL Server | CWE-269 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60331 | 6.4 | 3.5 | Oracle Corporation | MySQL Server | CWE-284 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60332 | 6.4 | 3.5 | Oracle Corporation | MySQL Server | CWE-284 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-61023 | 6.4 | 3.5 | Oracle Corporation | Oracle Inventory Management | CWE-269 | Vulnerability in the Oracle Inventory Management product of Oracle E-Business… |
| CVE-2026-60608 | 6.1 | 3.5 | Oracle Corporation | PeopleSoft Enterprise CS Financial Aid | CWE-284 | Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle… |
| CVE-2026-61053 | 7.8 | 3.4 | Oracle Corporation | Oracle Communications BRM - Elastic Charging Engine | CWE-269 | Vulnerability in the Oracle Communications BRM - Elastic Charging Engine prod… |
| CVE-2026-60659 | 7.1 | 3.3 | Oracle Corporation | Oracle Solaris | CWE-284 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Fil… |
| CVE-2026-60406 | 6.7 | 3.4 | Oracle Corporation | TimesTen In-Memory Database | CWE-269 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen I… |
| CVE-2026-61182 | 6.7 | 3.4 | Oracle Corporation | Oracle Agile Product Lifecycle Management for Process | CWE-269 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process pr… |
| CVE-2026-60162 | 6.1 | 3.3 | Oracle Corporation | Oracle VM VirtualBox | CWE-269 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-60336 | 5.7 | 3.4 | Oracle Corporation | Oracle Project Manufacturing | CWE-284 | Vulnerability in the Oracle Project Manufacturing product of Oracle E-Busines… |
| CVE-2026-61187 | 2.8 | 3.4 | Oracle Corporation | Oracle Agile Engineering Data Management | CWE-404 | Vulnerability in the Oracle Agile Engineering Data Management product of Orac… |
| CVE-2026-61303 | 1.9 | 3.3 | Oracle Corporation | Oracle EDI Gateway | CWE-200 | Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (c… |
| CVE-2026-61217 | 6.4 | 3.3 | Oracle Corporation | Oracle Security Service | CWE-290 | Vulnerability in the Oracle Security Service product of Oracle Fusion Middlew… |
| CVE-2026-60501 | 5.2 | 3.3 | Oracle Corporation | Service Delivery Platform | CWE-284 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-61084 | 4.4 | 3.3 | Oracle Corporation | Oracle GoldenGate | CWE-284 | Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions… |
| CVE-2026-60913 | 1.9 | 3.3 | Oracle Corporation | Oracle Property Manager | CWE-200 | Vulnerability in the Oracle Property Manager product of Oracle E-Business Sui… |
| CVE-2026-60172 | 6.3 | 3.2 | Oracle Corporation | Oracle Autonomous Health Framework | CWE-284 | Vulnerability in Oracle Autonomous Health Framework (component: Developer tri… |
| CVE-2026-61147 | 6.2 | 3.2 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-400 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-60337 | 4.7 | 3.2 | Oracle Corporation | Oracle Project Manufacturing | CWE-284 | Vulnerability in the Oracle Project Manufacturing product of Oracle E-Busines… |
| CVE-2026-61191 | 4.4 | 3.1 | Oracle Corporation | Oracle Agile Engineering Data Management | CWE-284 | Vulnerability in the Oracle Agile Engineering Data Management product of Orac… |
| CVE-2026-47016 | 1.9 | 3.1 | Oracle Corporation | Siebel CRM Integration | CWE-200 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-60833 | 7.0 | 3.1 | Oracle Corporation | Oracle Solaris | CWE-269 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Uti… |
| CVE-2026-61043 | 6.7 | 3.1 | Oracle Corporation | Oracle Production Scheduling | CWE-284 | Vulnerability in the Oracle Production Scheduling product of Oracle E-Busines… |
| CVE-2026-10679 | 5.5 | 3.1 | zephyrproject | zephyr | CWE-369 | Divide-by-zero in DesignWare SPI driver reachable from spi_transceive syscall… |
| CVE-2023-37508 | 2.3 | 3.0 | HCLSoftware | DevOps Plan | CWE-79 | HCL DevOps Plan is susceptible to a Cross-Site Scripting (XSS) vulnerability |
| CVE-2026-61028 | 1.9 | 3.0 | Oracle Corporation | Oracle Inventory Management | CWE-404 | Vulnerability in the Oracle Inventory Management product of Oracle E-Business… |
| CVE-2026-47395 | 5.5 | 3.0 | MervinPraison | PraisonAI | CWE-200 | PraisonAI CLI automatically resolves @url mentions in prompt text and can rea… |
| CVE-2026-60160 | 3.2 | 3.0 | Oracle Corporation | Oracle VM VirtualBox | CWE-200 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-61096 | 2.9 | 3.0 | Oracle Corporation | MySQL Server | CWE-284 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60703 | 7.1 | 2.7 | Oracle Corporation | Oracle Interaction Blending | CWE-284 | Vulnerability in the Oracle Interaction Blending product of Oracle E-Business… |
| CVE-2026-47000 | 3.5 | 2.8 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-352 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-61101 | 8.2 | 2.7 | Oracle Corporation | Oracle MES for Process Manufacturing | CWE-284 | Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E… |
| CVE-2026-47041 | 6.0 | 2.7 | Oracle Corporation | Oracle VM VirtualBox | CWE-400 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-15226 | 8.4 | 2.6 | — | snapd | CWE-250 | snapd snap-confine Sandbox Confinement Bypass via Omission of setuid Restrict… |
| CVE-2026-60685 | 6.1 | 2.7 | Oracle Corporation | Oracle iSupport | CWE-284 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (comp… |
| CVE-2026-60842 | 6.1 | 2.7 | Oracle Corporation | Oracle Knowledge Management | CWE-285 | Vulnerability in the Oracle Knowledge Management product of Oracle E-Business… |
| CVE-2026-62487 | 6.1 | 2.7 | Oracle Corporation | Oracle Contracts Integration | CWE-352 | Vulnerability in the Oracle Contracts Integration product of Oracle E-Busines… |
| CVE-2026-60321 | 5.7 | 2.6 | Oracle Corporation | Oracle Project Manufacturing | CWE-284 | Vulnerability in the Oracle Project Manufacturing product of Oracle E-Busines… |
| CVE-2026-61253 | 5.4 | 2.7 | Oracle Corporation | Oracle HRMS (Japanese) | CWE-352 | Vulnerability in the Oracle HRMS (Japanese) product of Oracle E-Business Suit… |
| CVE-2026-60149 | 5.2 | 2.6 | Oracle Corporation | Oracle Workflow | CWE-284 | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (comp… |
| CVE-2026-60191 | 4.1 | 2.6 | Oracle Corporation | MySQL Server | CWE-284 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-63358 | 8.4 | 2.5 | FileGator | FileGator | CWE-732 | FileGator privilege escalation |
| CVE-2026-60938 | 4.1 | 2.5 | Oracle Corporation | Oracle Labor Distribution | CWE-269 | Vulnerability in the Oracle Labor Distribution product of Oracle E-Business S… |
| CVE-2026-60761 | 6.5 | 2.5 | Oracle Corporation | Oracle Applications DBA | CWE-284 | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Sui… |
| CVE-2026-65065 | 5.5 | 2.5 | EGOR | Data::RoaringBitmap::Shared | CWE-732 | Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-read… |
| CVE-2026-61047 | 1.9 | 2.5 | Oracle Corporation | Oracle Production Scheduling | CWE-284 | Vulnerability in the Oracle Production Scheduling product of Oracle E-Busines… |
| CVE-2026-63729 | 6.8 | 2.3 | TeX Live | TeX Live | CWE-416 | TeX Live SyncTeX Parser Heap Use-After-Free via Malformed SyncTeX File |
| CVE-2026-60161 | 6.1 | 2.3 | Oracle Corporation | Oracle VM VirtualBox | CWE-362 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-56586 | 4.2 | 2.4 | HCLSoftware | IntelliOps Event Management | CWE-16 | HCL IEM was affected with X-Content-Type-Options Header Missing |
| CVE-2026-60896 | 3.6 | 2.3 | Oracle Corporation | Oracle Work in Process | CWE-200 | Vulnerability in the Oracle Work in Process product of Oracle E-Business Suit… |
| CVE-2026-60661 | 7.8 | 2.3 | Oracle Corporation | Oracle Solaris | CWE-269 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Fil… |
| CVE-2026-61061 | 7.0 | 2.3 | Oracle Corporation | Oracle JDeveloper | CWE-269 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (c… |
| CVE-2026-61120 | 7.0 | 2.3 | Oracle Corporation | Oracle HRMS (US) | CWE-269 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (com… |
| CVE-2026-47047 | 7.8 | 2.1 | Oracle Corporation | Oracle VM VirtualBox | CWE-269 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-47054 | 7.8 | 2.1 | Oracle Corporation | Oracle VM VirtualBox | CWE-269 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-61077 | 7.5 | 2.1 | Oracle Corporation | PeopleSoft Enterprise SCM Mobile Inventory Management | CWE-284 | Vulnerability in the PeopleSoft Enterprise SCM Mobile Inventory Management pr… |
| CVE-2026-61226 | 7.5 | 2.2 | Oracle Corporation | Oracle Communications Converged Application Server | CWE-284 | Vulnerability in the Oracle Communications Converged Application Server produ… |
| CVE-2026-61063 | 8.8 | 2.1 | Oracle Corporation | PeopleSoft Enterprise SCM Supplier Contract Management | CWE-269 | Vulnerability in the PeopleSoft Enterprise SCM Supplier Contract Management p… |
| CVE-2026-60454 | 7.8 | 2.1 | Oracle Corporation | Oracle HTTP Server | CWE-269 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (… |
| CVE-2026-60570 | 7.8 | 2.1 | Oracle Corporation | Oracle GoldenGate | CWE-284 | Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions… |
| CVE-2026-60409 | 5.7 | 2.0 | Oracle Corporation | TimesTen In-Memory Database | CWE-284 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen I… |
| CVE-2026-64614 | 3.8 | 2.1 | EGOR | Data::Deque::Shared | CWE-59 | Data::Deque::Shared versions before 0.06 for Perl create a world-readable mma… |
| CVE-2026-64615 | 3.3 | 2.1 | EGOR | Data::Graph::Shared | CWE-59 | Data::Graph::Shared versions before 0.04 for Perl create a world-readable mma… |
| CVE-2026-60383 | 8.4 | 2.0 | Oracle Corporation | Service Delivery Platform | CWE-284 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-62469 | 7.1 | 2.0 | Oracle Corporation | Oracle Human Resources | CWE-284 | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suit… |
| CVE-2026-60626 | 6.0 | 2.0 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-47055 | 3.2 | 2.0 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-60642 | 7.6 | 1.9 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-64617 | 3.8 | 1.9 | EGOR | Data::PubSub::Shared | CWE-59 | Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mm… |
| CVE-2026-65061 | 3.8 | 1.9 | EGOR | Data::ReqRep::Shared | CWE-59 | Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mm… |
| CVE-2026-65062 | 3.8 | 1.9 | EGOR | Data::SortedSet::Shared | CWE-59 | Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable… |
| CVE-2026-65063 | 3.8 | 1.9 | EGOR | Data::RadixTree::Shared | CWE-59 | Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable… |
| CVE-2026-65064 | 3.8 | 1.9 | EGOR | Data::HashMap::Shared | CWE-59 | Data::HashMap::Shared versions before 0.14 for Perl create a world-readable m… |
| CVE-2026-65066 | 3.8 | 1.9 | EGOR | Data::RingBuffer::Shared | CWE-59 | Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readabl… |
| CVE-2026-65067 | 3.8 | 1.9 | EGOR | Data::Intern::Shared | CWE-59 | Data::Intern::Shared versions before 0.02 for Perl create a world-readable mm… |
| CVE-2026-65068 | 3.8 | 1.9 | EGOR | Data::SpatialHash::Shared | CWE-59 | Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readab… |
| CVE-2026-64616 | 3.3 | 1.9 | EGOR | Data::NDArray::Shared | CWE-59 | Data::NDArray::Shared versions before 0.02 for Perl create a world-readable m… |
| CVE-2026-47044 | 5.5 | 1.9 | Oracle Corporation | Oracle VM VirtualBox | CWE-400 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-47007 | 7.3 | 1.8 | Oracle Corporation | Oracle Communications Pricing Design Center | CWE-284 | Vulnerability in the Oracle Communications Pricing Design Center product of O… |
| CVE-2026-12139 | 5.5 | 1.8 | Tanium | Connect | CWE-214 | Tanium addressed an information disclosure vulnerability in Connect. |
| CVE-2026-59846 | 3.9 | 1.8 | Red Hat | Red Hat Hardened Images | CWE-78 | Libssh: libssh: information disclosure via proxycommand %r username expansion |
| CVE-2026-60155 | 7.5 | 1.7 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-60159 | 7.5 | 1.7 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-60245 | 7.2 | 1.8 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60911 | 5.4 | 1.7 | Oracle Corporation | Oracle Property Manager | CWE-285 | Vulnerability in the Oracle Property Manager product of Oracle E-Business Sui… |
| CVE-2026-60957 | 5.4 | 1.7 | Oracle Corporation | Oracle Transportation Execution | CWE-269 | Vulnerability in the Oracle Transportation Execution product of Oracle E-Busi… |
| CVE-2026-60962 | 5.4 | 1.7 | Oracle Corporation | Oracle Flow Manufacturing | CWE-284 | Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business S… |
| CVE-2026-62574 | 7.8 | 1.6 | Oracle Corporation | Oracle Java SE | CWE-284 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM E… |
| CVE-2026-60601 | 4.4 | 1.6 | Oracle Corporation | PeopleSoft Enterprise FIN Common Objects | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Orac… |
| CVE-2026-60891 | 1.9 | 1.6 | Oracle Corporation | Oracle Work in Process | CWE-200 | Vulnerability in the Oracle Work in Process product of Oracle E-Business Suit… |
| CVE-2026-10680 | 7.6 | 1.5 | zephyrproject | zephyr | CWE-125 | Out-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling vi… |
| CVE-2026-60144 | 3.6 | 1.4 | Oracle Corporation | Oracle Workflow | CWE-284 | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (comp… |
| CVE-2026-60347 | 3.6 | 1.4 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-21953 | 3.3 | 1.4 | Oracle Corporation | Oracle Retail Xstore Point of Service | CWE-284 | Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle … |
| CVE-2026-62465 | 6.6 | 1.4 | Oracle Corporation | Oracle HRMS (US) | CWE-284 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (com… |
| CVE-2026-10677 | 6.5 | 1.3 | zephyrproject | zephyr | CWE-401 | Kernel heap memory leak in `z_vrfy_k_poll()` lets an unprivileged user thread… |
| CVE-2026-47714 | 6.1 | 1.3 | strukturag | libheif | CWE-190 | libheif has integer overflow in inline mask size calculation that causes unde… |
| CVE-2026-59845 | 5.9 | 1.4 | Red Hat | Red Hat Enterprise Linux 10 | CWE-390 | Libssh: libssh: denial of service via unchecked proxycommand fork() failure |
| CVE-2026-10674 | 5.5 | 1.3 | zephyrproject | zephyr | CWE-617 | DoS (hard fault) in NXP LPUART driver: unsupported runtime UART config leaves… |
| CVE-2026-47062 | 5.5 | 1.3 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-46991 | 4.4 | 1.3 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-56582 | 3.1 | 1.1 | HCLSoftware | MyCloud | CWE-327 | HCL MyCloud was affected with SSL/TLS Protocol Affected with LUCKY13 Vulnerab… |
| CVE-2026-47053 | 5.6 | 1.0 | Oracle Corporation | Oracle VM VirtualBox | CWE-285 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-61202 | 7.5 | 1.0 | Oracle Corporation | Oracle Solaris | CWE-284 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Uti… |
| CVE-2026-60407 | 5.6 | 1.0 | Oracle Corporation | TimesTen In-Memory Database | CWE-284 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen I… |
| CVE-2026-56581 | 2.6 | 1.0 | HCLSoftware | MyCloud | CWE-614 | HCL MyCloud was affected with Cookie Attribute Path Not Set |
| CVE-2026-16416 | 9.3 | 0.9 | Chrome | CWE-190 | Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allow… | |
| CVE-2024-5300 | 5.6 | 0.9 | — | snapd | CWE-212 | AppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauth… |
| CVE-2026-16414 | 7.8 | 0.7 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chromecast in Google Chrome pri… | |
| CVE-2026-60158 | 6.4 | 0.6 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-60338 | 3.6 | 0.6 | Oracle Corporation | Oracle Project Manufacturing | CWE-284 | Vulnerability in the Oracle Project Manufacturing product of Oracle E-Busines… |
| CVE-2026-61079 | 5.8 | 0.4 | Oracle Corporation | Oracle GoldenGate | CWE-20 | Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions… |
| CVE-2026-62563 | 5.4 | 0.4 | Oracle Corporation | Oracle Work in Process | CWE-285 | Vulnerability in the Oracle Work in Process product of Oracle E-Business Suit… |
| CVE-2026-47122 | 4.2 | 0.1 | sparkle-project | Sparkle | CWE-306 | Sparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connecti… |
| CVE-2026-16517 | 2.9 | 0.2 | Red Hat | Red Hat Hardened Images | CWE-190 | Libarchive: libarchive: signed integer overflow in archive_write_zip_header |
| CVE-2026-15811 | 5.8 | 0.0 | Red Hat | Red Hat Enterprise Linux 10 | CWE-212 | Kronosnet: kronosnet: encryption key exposure in memory after cryptographic c… |