boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, June 16, 2026 · all times UTC← 2026-06-15 · archive · 2026-06-17 →

Security Box Score — June 16, 2026

546 CVEs published, led by Oracle Corporation (240).

546 CVEs published June 16, 2026: 156 critical, 272 high, 101 medium, 17 low; 1 in the KEV catalog at press time; 16 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 146 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published43188779——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

419 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux9610638466431411120.27.8.0013-119 ▼
google63080568429281277760.78.1.0023+630 ▲
microsoft208744555131706286192.67.8.0044+69 ▲
red hat621568667111200.06.7.0030+57 ▲
apple146612142288710.65.7.0019-1 ▼
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
suse240400000.08.6.0021+2 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
netgear171700161000.04.3.0024+17 ▲
cisco4165470561062.57.3.1576+3 ▲
palo alto networks911127113218.25.9.0022+7 ▲
ivanti49450025555.68.8.5187+3 ▲
checkpoint3915303111.17.5.0410+3 ▲
fortinet29432028333.38.3.0076+1 ▲
ubiquiti584400300.08.9.0052+5 ▲
vmware3402207125.06.7.0036+3 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache6710115404323311.07.3.0052+63 ▲
mozilla49551118260900.07.3.0026+45 ▲
gitlab1118041224211.14.8.0024+11 ▲
docker250500000.08.8.0021+2 ▲
drupal0511304120.05.1.00260
github021100000.08.1.03470
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2422701321161842720.78.8.0040+242 ▲
adobe1291314507521921.55.5.0021+129 ▲
ibm11601329180600.07.5.0028+11 ▲
progress591710600.07.5.0036+5 ▲
solarwinds36231010466.77.8.6082+3 ▲
veeam142200100.09.0.0052+1 ▲
zohocorp020110000.07.1.01040
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5 ▲
d-link9110425300.05.5.0058+9 ▲
siemens780440000.07.5.0020+6 ▲
rockwell automation771510000.08.7.0030+7 ▲
abb550410000.07.2.0018+5 ▲
moxa550320000.07.0.0029+5 ▲
dahua330111000.06.9.0036+3 ▲
hitachi energy020020000.05.7.00140
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7172230391000.06.5.0023+71 ▲
openclaw61670352210000.07.0.0021+61 ▲
sourcecodester3658002434000.02.1.0026+36 ▲
edimax051032019100.07.4.00590
concrete cms2461111321000.06.2.0015+2 ▲
open ises044221210000.07.1.00210
helmholz04203930000.07.1.00260
mb connect line04203930000.07.1.00260

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9991100.010.0
CVE-2026-35273.954799.99.8
CVE-2026-9082.883299.89.8
CVE-2026-50751.837799.79.3
CVE-2026-48907.781099.510.0
CVE-2026-45498.630899.17.5
CVE-2026-49160.538398.97.5
CVE-2026-10523.518798.99.8
CVE-2026-28318.400198.57.5
CVE-2026-53435.376698.48.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9991KEV
CVE-2026-4890710.0.7810KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4508710.0.1296
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-2022310.0.0083
CVE-2026-4714010.0.0082
Most disclosures (vendor)
VendorCVEs
google798
linux522
oracle267
microsoft235
adobe129
red hat99
apache84
spring72
openclaw67
ibm60
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco10
apple7
google6
ivanti5
solarwinds4
berriai3
fortinet3
smartertools3
adobe2
Most-affected ecosystems
EcosystemAdvisories
Maven36
Packagist22
PyPI11
npm4
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2025-48595Google0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-20245Cisco0
CVE-2026-20262Cisco0
CVE-2026-28318SolarWinds0
CVE-2026-34926Trend Micro, Inc.0
CVE-2026-35273Oracle Corporation0
CVE-2026-41091Microsoft0
CVE-2026-45247Mirasvit0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171672
CVE-2021-27102n/a2021-11-171672
CVE-2021-27101n/a2021-11-171672
CVE-2021-27103n/a2021-11-171672
CVE-2021-21017Adobe2021-11-171672
CVE-2021-28550Adobe2021-11-171672
CVE-2021-42013Apache Software Foundation2021-11-171672
CVE-2021-41773Apache Software Foundation2021-11-171672
CVE-2021-30858Apple2021-11-171672
CVE-2021-30860Apple2021-11-171672

Transactions

EXPLOIT PUBLISHED — zephyrproject zephyr: 5 CVEs (CVE-2026-10635, CVE-2026-10636, CVE-2026-10637, CVE-2026-10639, CVE-2026-10640). Public exploit references added.

EXPLOIT PUBLISHED — leejet stable-diffusion.cpp: 4 CVEs (CVE-2026-47747, CVE-2026-47748, CVE-2026-47749, CVE-2026-47750). Public exploit references added.

EXPLOIT PUBLISHED — Red Hat Enterprise Linux 10: 3 CVEs (CVE-2026-1764, CVE-2026-1766, CVE-2026-1767). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-44587 (carrierwaveuploader carrierwave). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-46448 (OpenStack Nova). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48779 (websockets ws). Public exploit reference added.

DUE DATE PASSED — CVE-2026-35273 (Oracle Corporation PeopleSoft Enterprise PeopleTools). CISA remediation deadline was June 15, 2026; still in catalog.

Yesterday's Results

How to read these box scores · glossary

546 CVEs published. 25 box scores and 375 table rows below; the remaining 146 continue on page 2 — every CVE is listed, nothing truncated.

joomlacontenteditor.net Joomla Content Editor (JCE) extension for Joomla — Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .7810   99.5   YES
AFFECTED
  Product                                           Versions          Fixed
  Joomla Content Editor (JCE) extension for Joomla  1.0.0-2.9.99.4 –  —
TIMELINE
  May 26  Reserved by CNA
  Jun 16  Added to CISA KEV, due Jun 19
  Jun 16  Published (CNA: Joomla)
CWE-284 · CNA: Joomla · CVSS v4.0 · 3 references · NVD status: Analyzed · KEV due June 19, 2026
Microsoft Defender Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   H   L   N  U  H  H  H    7.0   .1136   95.6     —
AFFECTED
  Product                              Versions   Fixed
  Microsoft Malware Protection Engine  1.1.0.0 –  —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 16  Published (CNA: microsoft)
CWE-59 · CNA: microsoft · CVSS v3.1 · 2 references · NVD status: Modified
TP-Link Systems Inc. TL-WR940N v6 — OS Command Injection in IPv6 PPPoE Configuration in TP-Link TL-WR940N
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   H   N   H   H   H    8.5   .0279   85.3     —
AFFECTED
  Product       Versions     Fixed
  TL-WR940N v6  unspecified  —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 16  Published (CNA: TPLink)
CWE-78 · CNA: TPLink · CVSS v4.0 · 3 references · NVD status: Analyzed
TP-Link Systems Inc. TL-WR940N v6 — OS Command Injection in BigPond Cable (BPA) Configuration in TP-Link TL-WR940N
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   H   N   H   H   H    8.5   .0279   85.3     —
AFFECTED
  Product       Versions     Fixed
  TL-WR940N v6  unspecified  —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 16  Published (CNA: TPLink)
CWE-78 · CNA: TPLink · CVSS v4.0 · 3 references · NVD status: Analyzed
Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origi…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  N  N    7.4   .0191   78.2     —
AFFECTED
  Product                               Versions     Fixed
  Adobe Acrobat PDF Extension (Chrome)  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 16  Published (CNA: adobe)
CWE-79 · CNA: adobe · CVSS v3.1 · 1 reference · NVD status: Analyzed
Radiflow iSAP Smart Collector — OS Commands Executed with Administrative Permissions in Radiflow iSAP Smart Collector
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0092   57.6     —
AFFECTED
  Product               Versions  Fixed
  iSAP Smart Collector  3.07-1 –  —
TIMELINE
  Jan 7   Reserved by CNA
  Jun 16  Published (CNA: ENISA)
CWE-78 · CNA: ENISA · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
Red Hat Red Hat Ansible Automation Platform 2 — Galaxy_ng: shell injection in legacy role import via unsanitized git ref names
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0089   56.6     —
AFFECTED
  Product                                Versions     Fixed
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
TIMELINE
  Jun 16  Reserved by CNA
  Jun 16  Published (CNA: redhat)
CWE-78 · CNA: redhat · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
Premmerce Dev Tools <= 2.0 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via Plugin Creation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0085   55.3     —
AFFECTED
  Product              Versions     Fixed
  Premmerce Dev Tools  unspecified  —
TIMELINE
  Apr 23  Reserved by CNA
  Jun 16  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
websockets ws — ws: Memory exhaustion DoS from tiny fragments and data chunks
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0081   54.2     —
AFFECTED
  Product  Versions             Fixed
  ws       >= 1.1.0, < 5.2.5 –  —
TIMELINE
  May 22  Reserved by CNA
  Jun 16  Public exploit reference published
  Jun 16  Published (CNA: GitHub_M)
CWE-400, CWE-770 · CNA: GitHub_M · CVSS v3.1 · 28 references · NVD status: Modified
TURCK TBEN-LL-SE-M2 — Command Injection via name parameter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0077   52.9     —
AFFECTED
  Product        Versions  Fixed
  TBEN-LL-SE-M2  0.0.0 –   —
  TBEN-L4-SE-M2  0.0.0 –   —
  TBEN-L5-SE-M2  0.0.0 –   —
TIMELINE
  Apr 2   Reserved by CNA
  Jun 16  Published (CNA: CERTVDE)
CWE-78 · CNA: CERTVDE · CVSS v4.0 · 1 reference · NVD status: Deferred
ServerCo getssl ACME shell script path injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  N    7.4   .0076   52.4     —
AFFECTED
  Product  Versions     Fixed
  getssl   unspecified  —
TIMELINE
  May 31  Reserved by CNA
  Jun 16  Published (CNA: runZero)
CWE-73 · CNA: runZero · CVSS v3.1 · 5 references · NVD status: Awaiting Analysis
Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0072   51.2     —
AFFECTED
  Product      Versions     Fixed
  Rocket.Chat  unspecified  —
TIMELINE
  May 26  Reserved by CNA
  Jun 16  Published (CNA: hackerone)
CWE-287 · CNA: hackerone · CVSS v3.0 · 2 references · NVD status: Analyzed
Oracle Corporation PeopleSoft Enterprise PT PeopleTools — Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Performa…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0064   48.1     —
AFFECTED
  Product                               Versions  Fixed
  PeopleSoft Enterprise PT PeopleTools  8.61 –    —
TIMELINE
  Apr 1   Reserved by CNA
  Jun 16  Published (CNA: oracle)
CWE-306 · CNA: oracle · CVSS v3.1 · 1 reference · NVD status: Analyzed
truelockmc streambert — Streambert: Arbitrary File Write (Zip Slip) via Subtitle Extraction
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  N  H  H   10.0   .0062   47.1     —
AFFECTED
  Product     Versions   Fixed
  streambert  < 2.5.0 –  —
TIMELINE
  May 20  Reserved by CNA
  Jun 16  Published (CNA: GitHub_M)
CWE-20, CWE-22 · CNA: GitHub_M · CVSS v3.1 · 2 references · NVD status: Deferred
Oracle Corporation WebLogic Server — Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versi…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0056   44.3     —
AFFECTED
  Product          Versions      Fixed
  WebLogic Server  12.2.1.4.0 –  —
TIMELINE
  Apr 1   Reserved by CNA
  Jun 16  Published (CNA: oracle)
CWE-502 · CNA: oracle · CVSS v3.1 · 1 reference · NVD status: Analyzed
Red Hat Red Hat Enterprise Linux 10 — Pacemaker: pacemaker: denial of service via integer overflow in remote message decompression
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  H    8.6   .0056   44.1     —
AFFECTED
  Product                                                                Versions     Fixed
  Red Hat Enterprise Linux 10                                            unspecified  0:3.0.1-5.el10_2.1
  Red Hat Enterprise Linux 10.0 Extended Update Support                  unspecified  0:3.0.0-5.3.el10_0
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:1.1.23-1.el7_9.2
  Red Hat Enterprise Linux 8                                             unspecified  0:2.1.7-5.6.el8_10
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  0:2.0.5-9.el8_4.12
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  0:2.0.5-9.el8_4.12
  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support  unspecified  0:2.1.2-4.el8_6.11
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On  unspecified  0:2.1.2-4.el8_6.11
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service         unspecified  0:2.1.5-9.7.el8_8
  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions         unspecified  0:2.1.5-9.7.el8_8
  + 6 more
TIMELINE
  Jun 2   Reserved by CNA
  Jun 16  Published (CNA: redhat)
CWE-190 · CNA: redhat · CVSS v3.1 · 16 references · NVD status: Awaiting Analysis
BoldThemes Nifty — WordPress Nifty theme <= 1.4.1 - PHP Object Injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0056   43.8     —
AFFECTED
  Product  Versions  Fixed
  Nifty    n/a –     1.4.2
TIMELINE
  Feb 19  Reserved by CNA
  Jun 16  Published (CNA: Patchstack)
CWE-502 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
AivahThemes Car Zone — WordPress Car Zone theme <= 3.7 - Arbitrary File Deletion vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  N  N  H    8.6   .0053   42.6     —
AFFECTED
  Product   Versions  Fixed
  Car Zone  n/a –     —
TIMELINE
  Dec 29  Reserved by CNA
  Jun 16  Published (CNA: Patchstack)
CWE-22 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
ThemeREX Hot Coffee — WordPress Hot Coffee theme <= 1.7 - PHP Object Injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0053   42.2     —
AFFECTED
  Product     Versions  Fixed
  Hot Coffee  n/a –     —
TIMELINE
  Dec 29  Reserved by CNA
  Jun 16  Published (CNA: Patchstack)
CWE-502 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
ThemeREX SeaFood Company — WordPress SeaFood Company theme <= 1.4 - PHP Object Injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0053   42.2     —
AFFECTED
  Product          Versions  Fixed
  SeaFood Company  n/a –     —
TIMELINE
  Dec 29  Reserved by CNA
  Jun 16  Published (CNA: Patchstack)
CWE-502 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
Linux Linux — net/sched: fix pedit partial COW leading to page cache corruption
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0053   42.1     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    abe35bf3be51482593076d516a680d79e5fbc8e1 –  —
  Linux    5.18 –                                      5.10.260
TIMELINE
  May 13  Reserved by CNA
  Jun 16  Published (CNA: Linux)
CWE-787, CWE-190 · CNA: Linux · CVSS v3.1 · 44 references · NVD status: Modified
Oracle Corporation MySQL Shell — Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported vers…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0052   41.9     —
AFFECTED
  Product      Versions          Fixed
  MySQL Shell  2026.2.0+9.6.1 –  —
TIMELINE
  May 18  Reserved by CNA
  Jun 16  Published (CNA: oracle)
CWE-94 · CNA: oracle · CVSS v3.1 · 1 reference · NVD status: Analyzed
https://wpreviewslider.com/ WP Review Slider Pro — WP Review Slider Pro <= 12.6.8 - Authenticated (Subscriber+) Arbitrary File Deletion via 'myaction' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  H    8.1   .0052   41.8     —
AFFECTED
  Product               Versions     Fixed
  WP Review Slider Pro  unspecified  —
TIMELINE
  May 12  Reserved by CNA
  Jun 16  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
Oracle Corporation Identity Manager — Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Suppo…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0052   41.7     —
AFFECTED
  Product           Versions      Fixed
  Identity Manager  12.2.1.4.0 –  —
TIMELINE
  May 18  Reserved by CNA
  Jun 16  Published (CNA: oracle)
CWE-306 · CNA: oracle · CVSS v3.1 · 1 reference · NVD status: Analyzed
Oracle Corporation Identity Manager — Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Core). Supported vers…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0052   41.7     —
AFFECTED
  Product           Versions      Fixed
  Identity Manager  12.2.1.4.0 –  —
TIMELINE
  Apr 1   Reserved by CNA
  Jun 16  Published (CNA: oracle)
CWE-284 · CNA: oracle · CVSS v3.1 · 1 reference · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-353129.841.7Oracle CorporationOracle Virtual DirectoryCWE-284Vulnerability in the Oracle Virtual Directory product of Oracle Fusion Middle…
CVE-2026-467739.841.7Oracle CorporationOracle Unified DirectoryCWE-284Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-467749.841.7Oracle CorporationOracle Unified DirectoryCWE-284Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-468579.841.0Oracle CorporationOracle Enterprise Manager Base PlatformCWE-284Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-468599.841.0Oracle CorporationOracle Agile PLMCWE-287Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone…
CVE-2026-352709.140.3Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-122928.140.1MozillaFirefoxCWE-119Incorrect boundary conditions in the Web Audio component
CVE-2026-3529210.039.5Oracle CorporationWebLogic ServerCWE-306Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2026-3530110.039.5Oracle CorporationWebLogic ServerCWE-306Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2026-4679810.039.5Oracle CorporationOracle WebCenter SitesCWE-306Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-4680010.039.5Oracle CorporationOracle WebCenter SitesCWE-306Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-352869.839.4Oracle CorporationOracle WebCenter ContentCWE-306Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-352939.839.4Oracle CorporationOracle WebCenter SitesCWE-306Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-352969.839.4Oracle CorporationOracle WebCenter SitesCWE-306Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-353109.839.4Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-353199.839.4Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-467839.839.4Oracle CorporationWebCenter Content: ImagingCWE-306Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd…
CVE-2026-467979.839.4Oracle CorporationOracle WebCenter SitesCWE-284Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-468019.839.4Oracle CorporationOracle WebCenter SitesCWE-306Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-468789.839.4Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-284Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-468799.839.4Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-306Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-468809.839.4Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-284Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-468909.839.5Oracle CorporationSiebel Apps - MarketingCWE-284Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co…
CVE-2026-469059.839.4Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-306Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-469099.839.4Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-284Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-468539.639.4Oracle CorporationOracle Enterprise Manager Base PlatformCWE-79Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-352809.939.4Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-352819.939.4Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-122258.739.3syracom AGSecure Login (2FA) for JiraCWE-288syracom Secure Login (2FA) for Confluence allows 2FA bypass via spoofed User-…
CVE-2026-123288.139.0MozillaFirefoxCWE-120Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbi…
CVE-2026-3530710.038.8Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-3530810.038.8Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-4680310.038.8Oracle CorporationOracle WebCenter PortalCWE-306Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-353049.838.8Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-468459.838.8Oracle CorporationOracle WebCenter PortalCWE-306Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-468849.838.8Oracle CorporationSiebel Apps - MarketingCWE-284Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co…
CVE-2026-468879.838.8Oracle CorporationSiebel Apps - MarketingCWE-284Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co…
CVE-2026-468899.838.8Oracle CorporationSiebel Apps - MarketingCWE-284Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co…
CVE-2025-691778.138.9THEMELOGIRoneousCWE-98WordPress Roneous theme <= 2.1.5 - Local File Inclusion vulnerability
CVE-2026-4677810.038.8Oracle CorporationOracle WebCenter Enterprise CaptureCWE-306Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-4678110.038.8Oracle CorporationOracle WebCenter Enterprise CaptureCWE-306Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-353099.838.8Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-467669.838.8Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-467999.838.8Oracle CorporationOracle WebCenter SitesCWE-306Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-468139.838.8Oracle CorporationOracle WebCenter ContentCWE-306Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-468609.838.8Oracle CorporationMySQL RouterCWE-284Vulnerability in the MySQL Router product of Oracle MySQL (component: Router:…
CVE-2026-468819.838.8Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-284Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-468829.838.8Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-284Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-468839.838.8Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-284Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-469029.838.8Oracle CorporationOracle Enterprise Command Center FrameworkCWE-284Vulnerability in the Oracle Enterprise Command Center Framework product of Or…
CVE-2026-469049.838.8Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-284Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-468569.638.8Oracle CorporationOracle Enterprise Manager Base PlatformCWE-79Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-108298.638.7MoxaNPort W2150A-W4/W2250A-W4 SeriesCWE-121A stack-based buffer overflow vulnerability has been found in the NPort W2150…
CVE-2026-81767.538.7latepointLatePoint – Calendar Booking Plugin for Appointments and EventsCWE-269LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administr…
CVE-2026-468637.538.6Oracle CorporationMySQL ServerCWE-400Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com…
CVE-2026-122568.838.5ThemeFusionAvadaCWE-502WordPress Avada theme <= 3.15.3 - PHP Object Injection vulnerability
CVE-2025-691317.538.4extendonsWordPress & WooCommerce Scraper Plugin, Import Data from Any SiteCWE-22WordPress WordPress & WooCommerce Scraper Plugin, Import Data from Any Site p…
CVE-2026-352989.138.1Oracle CorporationWebLogic ServerCWE-284Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2026-468627.538.1Oracle CorporationMySQL RouterCWE-400Vulnerability in the MySQL Router product of Oracle MySQL (component: Router:…
CVE-2026-468759.138.0Oracle CorporationOracle Enterprise Manager Base PlatformCWE-284Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-468969.138.0Oracle CorporationOracle Enterprise Command Center FrameworkCWE-284Vulnerability in the Oracle Enterprise Command Center Framework product of Or…
CVE-2026-469459.138.0Oracle CorporationOracle iSupportCWE-284Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (comp…
CVE-2026-469469.138.0Oracle CorporationOracle iSupportCWE-284Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (comp…
CVE-2026-468518.137.8Oracle CorporationPeopleSoft Enterprise CS Campus CommunityCWE-94Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Ora…
CVE-2026-469449.137.4Oracle CorporationOracle iSupportCWE-284Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (comp…
CVE-2026-353267.237.4Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-467697.237.4Oracle CorporationOracle Application Development Framework (ADF)CWE-284Vulnerability in the Oracle Application Development Framework (ADF) product o…
CVE-2026-468677.237.4Oracle CorporationOracle Enterprise Manager Base PlatformCWE-269Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-468687.237.4Oracle CorporationOracle Enterprise Manager Base PlatformCWE-284Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-469227.237.4Oracle CorporationOracle HR IntelligenceCWE-269Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suit…
CVE-2026-469387.237.4Oracle CorporationOracle Cost ManagementCWE-284Vulnerability in the Oracle Cost Management product of Oracle E-Business Suit…
CVE-2026-469567.237.4Oracle CorporationOracle Property ManagerCWE-284Vulnerability in the Oracle Property Manager product of Oracle E-Business Sui…
CVE-2026-469607.237.4Oracle CorporationOracle Project Portfolio AnalysisCWE-284Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Bu…
CVE-2026-469697.237.4Oracle CorporationOracle Financials for EMEACWE-284Vulnerability in the Oracle Financials for EMEA product of Oracle E-Business …
CVE-2026-469707.237.4Oracle CorporationOracle HR IntelligenceCWE-269Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suit…
CVE-2024-249098.837.1DellOpenManageCWE-77Dell OpenManage Integration with Microsoft Windows Admin Center contains a Re…
CVE-2026-468589.137.0Oracle CorporationAPM - Application Performance ManagementCWE-284Vulnerability in the APM - Application Performance Management product of Orac…
CVE-2026-487779.336.9gtsteffaniakfilebrowserCWE-22FileBrowser Quantum: Path Traversal in public share PATCH allows file ops out…
CVE-2026-468559.936.5Oracle CorporationOracle Enterprise Manager Base PlatformCWE-284Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-352658.836.6Oracle CorporationIdentity ManagerCWE-306Vulnerability in the Identity Manager product of Oracle Fusion Middleware (co…
CVE-2026-352678.836.5Oracle CorporationIdentity ManagerCWE-306Vulnerability in the Identity Manager product of Oracle Fusion Middleware (co…
CVE-2026-06478.836.0Rockwell AutomationFLEX I/O EtherNet/IP AdaptersCWE-306Rockwell Automation FLEX I/O Dual-port EtherNet/IP Adapters – Multiple Vulner…
CVE-2025-589248.136.1ThemeREX GroupGeyaCWE-98WordPress Geya theme <= 1.15 - Local File Inclusion vulnerability
CVE-2025-691058.136.1ThemeREXModerneeCWE-98WordPress Modernee theme <= 1.6.0 - Local File Inclusion vulnerability
CVE-2025-691078.136.1ThemeREXRosaleenCWE-98WordPress Rosaleen theme <= 2.8 - Local File Inclusion vulnerability
CVE-2025-691098.136.1ThemeREXRaider SpiritCWE-98WordPress Raider Spirit theme <= 1.1.2 - Local File Inclusion vulnerability
CVE-2025-691128.136.1ThemeREXPlantyCWE-98WordPress Planty theme <= 1.14.0 - Local File Inclusion vulnerability
CVE-2025-691138.136.1ThemeREXNexioCWE-98WordPress Nexio theme <= 1.10.0 - Local File Inclusion vulnerability
CVE-2025-691148.136.1ThemeREXMaxiNetCWE-98WordPress MaxiNet theme <= 1.2.10 - Local File Inclusion vulnerability
CVE-2025-691168.136.1ThemeREXIonaCWE-98WordPress Iona theme <= 1.0.8 - Local File Inclusion vulnerability
CVE-2025-691198.136.1ThemeREXCorbesierCWE-98WordPress Corbesier theme <= 1.15.0 - Local File Inclusion vulnerability
CVE-2025-691218.136.1ThemeREXDeliciosaCWE-98WordPress Deliciosa theme <= 1.10.0 - Local File Inclusion vulnerability
CVE-2025-691248.136.1ThemeREXEspecioCWE-98WordPress Especio theme <= 1.0 - Local File Inclusion vulnerability
CVE-2025-691368.136.1THEMELOGIWaniumCWE-98WordPress Wanium theme <= 1.9.8 - Local File Inclusion vulnerability
CVE-2025-691428.136.1ThemeREXAbelleCWE-98WordPress Abelle theme <= 1.22 - Local File Inclusion vulnerability
CVE-2025-691438.136.1ThemeREXMissionCWE-98WordPress Mission theme <= 1.22 - Local File Inclusion vulnerability
CVE-2025-691478.136.1ThemeREXPutterCWE-98WordPress Putter theme <= 1.17 - Local File Inclusion vulnerability
CVE-2025-691498.136.1ThemeREXTop DogCWE-98WordPress Top Dog theme <= 1.0.5 - Local File Inclusion vulnerability
CVE-2025-691508.136.1ThemeREXMedeusCWE-98WordPress Medeus theme <= 1.14 - Local File Inclusion vulnerability
CVE-2025-691598.136.1ThemeREXPrintoCWE-98WordPress Printo theme <= 1.11 - Local File Inclusion vulnerability
CVE-2025-691608.136.1ThemeREXGitaCWE-98WordPress Gita theme <= 1.11 - Local File Inclusion vulnerability
CVE-2025-691628.136.1ThemeREXGreckoCWE-98WordPress Grecko theme <= 5.17 - Local File Inclusion vulnerability
CVE-2025-691638.136.1ThemeREXWineShopCWE-98WordPress WineShop theme <= 3.17 - Local File Inclusion vulnerability
CVE-2025-691658.136.1ThemeREXChoreoCWE-98WordPress Choreo theme <= 1.6 - Local File Inclusion vulnerability
CVE-2025-691678.136.1ThemeREXErosCWE-98WordPress Eros theme <= 1.3 - Local File Inclusion vulnerability
CVE-2025-691688.136.1ThemeREXSpikeCWE-98WordPress Spike theme <= 1.2 - Local File Inclusion vulnerability
CVE-2025-691788.136.1CactusThemesTruemagCWE-98WordPress Truemag theme <= 4.3.14.2 - Local File Inclusion vulnerability
CVE-2026-467779.136.0Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-467949.935.7Oracle CorporationIdentity Manager ConnectorCWE-269Vulnerability in the Identity Manager Connector product of Oracle Fusion Midd…
CVE-2026-468648.835.8Oracle CorporationOracle Enterprise Manager Base PlatformCWE-284Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-2547010.035.4ACPTACPT (Pro) - Custom Post Types Plugin for WordPressCWE-94WordPress ACPT (Pro) - Custom Post Types plugin for WordPress plugin <= 2.0.4…
CVE-2026-467849.135.2Oracle CorporationWebCenter Content: ImagingCWE-284Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd…
CVE-2025-600858.135.0ThemeREX GroupLearnifyCWE-98WordPress Learnify theme <= 1.15.0 - Local File Inclusion vulnerability
CVE-2026-348948.135.0WebGeniusLabIntegrio CoreCWE-98WordPress Integrio Core plugin < 1.2.8 - Local File Inclusion vulnerability
CVE-2026-395228.135.0Elated-ThemesSoleneCWE-98WordPress Solene theme <= 3.4 - Local File Inclusion vulnerability
CVE-2026-395498.135.0Elated-ThemesAperitifCWE-98WordPress Aperitif theme <= 1.5 - Local File Inclusion vulnerability
CVE-2026-395688.135.0Elated-ThemesMr. SEOCWE-98WordPress Mr. SEO theme <= 2.0 - Local File Inclusion vulnerability
CVE-2026-467899.634.3Oracle CorporationOracle WebCenter ContentCWE-306Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-352768.134.4Oracle CorporationPeopleSoft Enterprise PT PeopleToolsCWE-306Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle P…
CVE-2026-467917.534.2Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-352839.933.9Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-352849.933.9Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-352859.933.9Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-352949.933.9Oracle CorporationIdentity Manager ConnectorCWE-284Vulnerability in the Identity Manager Connector product of Oracle Fusion Midd…
CVE-2026-353139.933.9Oracle CorporationOracle Access ManagerCWE-284Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-353169.933.9Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-353219.933.9Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-353239.933.9Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-468329.933.9Oracle CorporationOracle Enterprise Manager Base PlatformCWE-284Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-468389.933.9Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-468479.933.9Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-468549.933.9Oracle CorporationOracle Enterprise Manager Base PlatformCWE-284Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-468959.933.9Oracle CorporationOracle Enterprise Command Center FrameworkCWE-269Vulnerability in the Oracle Enterprise Command Center Framework product of Or…
CVE-2026-469079.933.9Oracle CorporationJD Edwards EnterpriseOne Order PromisingCWE-284Vulnerability in the JD Edwards EnterpriseOne Order Promising product of Orac…
CVE-2026-469089.933.9Oracle CorporationJD Edwards EnterpriseOne Accounts PayableCWE-284Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product of Ora…
CVE-2026-469189.933.9Oracle CorporationOracle Process Manufacturing Product DevelopmentCWE-284Vulnerability in the Oracle Process Manufacturing Product Development product…
CVE-2026-469339.933.9Oracle CorporationOracle Applications ManagerCWE-269Vulnerability in the Oracle Applications Manager product of Oracle E-Business…
CVE-2026-352998.833.9Oracle CorporationWebLogic ServerCWE-306Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2026-353038.833.9Oracle CorporationWebLogic ServerCWE-306Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2026-353158.833.9Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-353178.833.9Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-353228.833.9Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-353258.833.9Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-468868.833.9Oracle CorporationSiebel Apps - MarketingCWE-284Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co…
CVE-2026-469298.833.9Oracle CorporationOracle Cost ManagementCWE-269Vulnerability in the Oracle Cost Management product of Oracle E-Business Suit…
CVE-2026-469318.833.9Oracle CorporationOracle Enterprise Asset ManagementCWE-284Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-B…
CVE-2026-469378.833.9Oracle CorporationOracle iSetupCWE-269Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (compon…
CVE-2026-469408.833.9Oracle CorporationOracle Cost ManagementCWE-269Vulnerability in the Oracle Cost Management product of Oracle E-Business Suit…
CVE-2026-469428.833.9Oracle CorporationOracle Process Manufacturing Process PlanningCWE-269Vulnerability in the Oracle Process Manufacturing Process Planning product of…
CVE-2026-469478.833.9Oracle CorporationOracle Advanced Outbound TelephonyCWE-284Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-B…
CVE-2026-469508.833.9Oracle CorporationOracle Advanced Outbound TelephonyCWE-284Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-B…
CVE-2026-469518.833.9Oracle CorporationOracle QualityCWE-269Vulnerability in the Oracle Quality product of Oracle E-Business Suite (compo…
CVE-2026-469618.833.9Oracle CorporationOracle Project Portfolio AnalysisCWE-269Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Bu…
CVE-2026-469658.833.9Oracle CorporationOracle Universal Work QueueCWE-284Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business…
CVE-2026-469738.833.9Oracle CorporationOracle Outsourced Mfg for Discrete IndustriesCWE-269Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of…
CVE-2026-123278.133.5MozillaFirefoxCWE-119Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firef…
CVE-2026-352898.133.6Oracle CorporationPeopleSoft Enterprise PT PeopleToolsCWE-306Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle P…
CVE-2025-691037.533.6UtillzBrikkCWE-862WordPress Brikk theme <= 3.0.0 - Arbitrary Content Deletion vulnerability
CVE-2026-468099.133.4Oracle CorporationOracle WebCenter SitesCWE-284Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-469309.133.3Oracle CorporationOracle In-Memory Cost Management for Discrete IndustriesCWE-284Vulnerability in the Oracle In-Memory Cost Management for Discrete Industries…
CVE-2026-469499.133.3Oracle CorporationOracle Advanced Outbound TelephonyCWE-284Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-B…
CVE-2026-468529.933.1Oracle CorporationOracle Enterprise Manager Base PlatformCWE-269Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-353118.833.1Oracle CorporationWebLogic ServerCWE-284Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2026-468858.833.1Oracle CorporationSiebel CRM IntegrationCWE-269Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com…
CVE-2026-469218.833.1Oracle CorporationSiebel CRM Cloud ApplicationsCWE-269Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-95075.133.2EnhancesoftosTicketCWE-38Session fixation vulnerability in Enhancesoft's osTicket
CVE-2026-352829.933.1Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-467659.933.1Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-467679.933.1Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-467799.933.1Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-467829.933.1Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-467929.933.1Oracle CorporationIdentity Manager ConnectorCWE-284Vulnerability in the Identity Manager Connector product of Oracle Fusion Midd…
CVE-2026-467939.933.1Oracle CorporationIdentity Manager ConnectorCWE-284Vulnerability in the Identity Manager Connector product of Oracle Fusion Midd…
CVE-2026-468029.933.1Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-468149.933.1Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-468449.933.1Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-469009.933.1Oracle CorporationOracle Enterprise Command Center FrameworkCWE-269Vulnerability in the Oracle Enterprise Command Center Framework product of Or…
CVE-2026-469639.933.1Oracle CorporationOracle Universal Work QueueCWE-284Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business…
CVE-2026-469649.933.1Oracle CorporationOracle Universal Work QueueCWE-269Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business…
CVE-2026-353188.833.1Oracle CorporationOracle WebCenter SitesCWE-284Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-353248.833.1Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-467808.833.1Oracle CorporationWebCenter Content: ImagingCWE-306Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd…
CVE-2026-469038.833.1Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-269Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-469528.833.1Oracle CorporationOracle QualityCWE-269Vulnerability in the Oracle Quality product of Oracle E-Business Suite (compo…
CVE-2026-469628.833.1Oracle CorporationOracle Project Portfolio AnalysisCWE-269Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Bu…
CVE-2026-469678.833.1Oracle CorporationOracle Public Sector Financials (International)CWE-284Vulnerability in the Oracle Public Sector Financials (International) product …
CVE-2026-472776.532.7runtipiruntipiCWE-22Runtipi: Unauthenticated arbitrary file read through app-store logo symlinks
CVE-2026-467888.432.6Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-122908.132.5MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-468929.132.5Oracle CorporationJD Edwards EnterpriseOne Human Resources ManagementCWE-284Vulnerability in the JD Edwards EnterpriseOne Human Resources Management prod…
CVE-2026-23816.532.5woocommerceWooCommerce Stripe Payment GatewayCWE-862WooCommerce Stripe Payment Gateway <= 10.7.0 - Missing Authorization to Unaut…
CVE-2026-122898.832.4MozillaFirefoxCWE-269Privilege escalation in the Graphics: WebRender component
CVE-2026-395578.132.3Elated-ThemesNeoBeatCWE-502WordPress NeoBeat theme <= 1.7 - PHP Object Injection vulnerability
CVE-2026-122959.632.1MozillaFirefoxCWE-693Sandbox escape in the DOM: Navigation component
CVE-2026-122969.632.1MozillaFirefoxCWE-693Sandbox escape in the Security: Process Sandboxing component
CVE-2026-122979.632.1MozillaFirefoxCWE-119Sandbox escape due to incorrect boundary conditions in the Networking component
CVE-2026-468668.232.1Oracle CorporationOracle Enterprise Manager Base PlatformCWE-400Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-467959.331.9Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-468059.331.9Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-352598.831.7Oracle CorporationWebLogic ServerCWE-601Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2026-352628.331.5Oracle CorporationOracle Data IntegratorCWE-284Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middlewa…
CVE-2026-352748.231.1Oracle CorporationPeopleSoft Enterprise PT PeopleToolsCWE-306Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle P…
CVE-2026-122918.830.9MozillaFirefoxCWE-416Use-after-free in the Networking: HTTP component
CVE-2026-395299.830.2ThemeREX GroupElementraCWE-502WordPress Elementra theme <= 1.0.9 - PHP Object Injection vulnerability
CVE-2026-541949.830.2ThemeFusionFusion BuilderCWE-502WordPress Fusion Builder plugin <= 3.15.4 - PHP Object Injection vulnerability
CVE-2026-468498.130.2Oracle CorporationPeopleSoft Enterprise CS Student FinancialsCWE-284Vulnerability in the PeopleSoft Enterprise CS Student Financials product of O…
CVE-2026-352798.130.1Oracle CorporationPeopleSoft Enterprise PT PeopleToolsCWE-306Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle P…
CVE-2026-469278.130.1Oracle CorporationOracle ReceivablesCWE-284Vulnerability in the Oracle Receivables product of Oracle E-Business Suite (c…
CVE-2026-123057.530.1MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-353209.030.1Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-394389.329.9Emraan CheemaListingProCWE-89WordPress ListingPro plugin <= 2.9.10 - SQL Injection vulnerability
CVE-2026-467768.629.8Oracle CorporationOracle Unified DirectoryCWE-284Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-491138.529.8THEMECOCornerstoneCWE-94WordPress Cornerstone plugin < 7.8.8 - Arbitrary Code Execution vulnerability
CVE-2026-106407.129.7zephyrprojectzephyrCWE-416Use-after-free reading `net_pkt` `iface` after send in IPv6 Neighbor Discover…
CVE-2026-468979.929.5Oracle CorporationOracle Enterprise Command Center FrameworkCWE-284Vulnerability in the Oracle Enterprise Command Center Framework product of Or…
CVE-2026-469019.929.5Oracle CorporationOracle Enterprise Command Center FrameworkCWE-269Vulnerability in the Oracle Enterprise Command Center Framework product of Or…
CVE-2026-122949.629.0MozillaFirefoxCWE-693Sandbox escape in the DOM: Workers component
CVE-2026-123268.129.0MozillaFirefoxCWE-119Memory safety bugs fixed in Firefox 152 and Thunderbird 152
CVE-2026-352639.928.8Oracle CorporationWebLogic ServerCWE-284Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2026-469199.828.9Oracle CorporationSiebel CRM Cloud ApplicationsCWE-284Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-468619.628.9Oracle CorporationMySQL NDB ClusterCWE-284Vulnerability in the MySQL NDB Cluster product of Oracle MySQL (component: Cl…
CVE-2026-469327.128.7Oracle CorporationOracle Enterprise Asset ManagementCWE-284Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-B…
CVE-2026-468988.128.5Oracle CorporationOracle Enterprise Command Center FrameworkCWE-284Vulnerability in the Oracle Enterprise Command Center Framework product of Or…
CVE-2026-537769.328.4PerryTSperryCWE-613Perry < 0.5.1166 JWT Expiration Bypass via verify_decode
CVE-2026-4684610.028.1Oracle CorporationOracle WebCenter PortalCWE-306Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-449328.828.1SUSEwickedCWE-78indirect remote shell command injection via unsanitized DHCP options in wicked
CVE-2026-497729.328.1Liquid Web / StellarWPThe Events CalendarCWE-89WordPress The Events Calendar plugin 6.15.12-6.16.2 - SQL Injection vulnerabi…
CVE-2026-469109.128.1Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-20Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-352697.528.0Oracle CorporationIdentity ManagerCWE-284Vulnerability in the Identity Manager product of Oracle Fusion Middleware (co…
CVE-2026-353069.327.9Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-467968.028.0Oracle CorporationOracle WebCenter SitesCWE-601Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-106387.527.8zephyrprojectzephyrCWE-416Use-after-free in Zephyr ICMPv6 RX path when updating statistics after sendin…
CVE-2026-394336.527.8mojoomlaWPAMSCWE-862WordPress WPAMS plugin < 49.5.3 - Arbitrary Content Deletion vulnerability
CVE-2026-352916.627.6Oracle CorporationWebLogic ServerCWE-269Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2025-691188.127.4ThemeREXCopyPressCWE-98WordPress CopyPress theme <= 1.4.5 - Local File Inclusion vulnerability
CVE-2025-691258.127.4ThemeREXFood DropCWE-98WordPress Food Drop theme <= 1.3 - Local File Inclusion vulnerability
CVE-2025-691418.127.4ThemeREXKelly YoungCWE-98WordPress Kelly Young theme <= 1.1.0 - Local File Inclusion vulnerability
CVE-2025-691468.127.4ThemeREXDomCWE-98WordPress Dom theme <= 1.24 - Local File Inclusion vulnerability
CVE-2025-691768.127.4ThemeREXITacticsCWE-98WordPress ITactics theme <= 1.0 - Local File Inclusion vulnerability
CVE-2026-84448.827.2https://wpreviewslider.com/WP Review Slider ProCWE-89WP Review Slider Pro <= 12.6.8 - Authenticated (Subscriber+) SQL Injection vi…
CVE-2026-538537.627.3OpenClawOpenClawCWE-693OpenClaw < 2026.5.12 - Argument Pattern Bypass in Exec Allowlist via Linux an…
CVE-2026-273959.827.0SchioccoSupport BoardCWE-266WordPress Support Board plugin < 3.8.9 - Privilege Escalation vulnerability
CVE-2026-468999.626.9Oracle CorporationOracle Enterprise Command Center FrameworkCWE-269Vulnerability in the Oracle Enterprise Command Center Framework product of Or…
CVE-2026-469398.126.9Oracle CorporationOracle Configure to OrderCWE-284Vulnerability in the Oracle Configure to Order product of Oracle E-Business S…
CVE-2026-06468.726.8Rockwell AutomationFLEX I/O EtherNet/IP AdaptersCWE-401Rockwell Automation FLEX I/O Dual-port EtherNet/IP Adapters – Multiple Vulner…
CVE-2026-469537.226.4Oracle CorporationOracle HRMS (UK)CWE-269Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (com…
CVE-2026-469767.226.4Oracle CorporationOracle Public Sector PayrollCWE-284Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Busines…
CVE-2026-353059.326.2Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-348938.126.2WebGeniusLabThegov CoreCWE-98WordPress Thegov Core plugin < 2.0.23 - Local File Inclusion vulnerability
CVE-2026-348958.126.2WebGeniusLabSoftlab CoreCWE-98WordPress Softlab Core plugin < 1.2.11 - Local File Inclusion vulnerability
CVE-2026-395478.126.2Select-ThemesGetawayCWE-98WordPress Getaway theme < 1.8 - Local File Inclusion vulnerability
CVE-2026-469069.626.2Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-284Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-468918.126.2Oracle CorporationJD Edwards EnterpriseOne Accounts PayableCWE-284Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product of Ora…
CVE-2026-467905.326.1Oracle CorporationOracle WebCenter ContentCWE-200Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-84438.825.9https://wpreviewslider.com/WP Review Slider ProCWE-89WP Review Slider Pro <= 12.6.8 - Authenticated (Subscriber+) SQL Injection vi…
CVE-2026-486169.325.6Rocket.ChatRocket.ChatCWE-284Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.…
CVE-2026-468088.725.6Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-51496.525.1romethemeRTMKitCWE-863RTMKit <= 2.0.7 - Authenticated (Contributor+) Missing Authorization to Arbit…
CVE-2026-468048.724.9Oracle CorporationOracle WebCenter ContentCWE-269Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-487979.324.7mcp-tool-shop-orgbackpropagateCWE-358Backpropagate: backprop ui --auth and backprop ui --share do not enforce auth…
CVE-2026-352718.724.7Oracle CorporationPeopleSoft Enterprise PT PeopleToolsCWE-284Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle P…
CVE-2026-468068.224.7Oracle CorporationOracle WebCenter ContentCWE-601Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-487459.324.5traccartraccar-clientCWE-940Traccar Client: silent configuration hijack via unverified deep link redirect…
CVE-2026-69645.324.6j_3rkVideo Conferencing with ZoomCWE-862Video Conferencing with Zoom <= 4.6.7 - Missing Authorization to Unauthentica…
CVE-2026-487826.824.4pydanticpydantic-aiCWE-918pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local N…
CVE-2026-407398.124.2Mikado-ThemesLuxeDriveCWE-502WordPress LuxeDrive theme <= 1.4 - PHP Object Injection vulnerability
CVE-2026-407518.124.2Mikado-ThemesAshtangaCWE-502WordPress Ashtanga theme <= 1.2 - PHP Object Injection vulnerability
CVE-2026-407588.124.2Elated-ThemesLéonieCWE-502WordPress Léonie theme <= 1.2.1 - PHP Object Injection vulnerability
CVE-2026-407598.124.2Mikado-ThemesEsméeCWE-502WordPress Esmée theme <= 1.4 - PHP Object Injection vulnerability
CVE-2026-469158.524.0Oracle CorporationOracle Complex Maintenance, Repair and OverhaulCWE-284Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product …
CVE-2026-72738.823.7ZyxelGS1900-48HPv2 firmwareCWE-121A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS190…
CVE-2026-123295.323.5MozillaFirefoxCWE-119Memory safety bug fixed in Thunderbird ESR 140.12
CVE-2026-490809.323.3TMSwpDataTablesCWE-89WordPress wpDataTables plugin <= 7.3.6 - SQL Injection vulnerability
CVE-2026-468708.523.3Oracle CorporationMySQL ShellCWE-284Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell fo…
CVE-2026-352957.523.3Oracle CorporationOracle WebCenter SitesCWE-306Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-469347.523.3Oracle CorporationOracle Complex Maintenance, Repair and OverhaulCWE-269Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product …
CVE-2026-469357.523.3Oracle CorporationOracle Complex Maintenance, Repair and OverhaulCWE-269Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product …
CVE-2026-469577.523.3Oracle CorporationOracle iSupplier PortalCWE-284Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Sui…
CVE-2026-469667.523.3Oracle CorporationOracle Universal Work QueueCWE-269Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business…
CVE-2026-108286.923.2MoxaNPort W2150A-W4/W2250A-W4 SeriesCWE-134A format string vulnerability has been found in the "alias" parameter of the …
CVE-2026-469168.822.8Oracle CorporationOracle Process Manufacturing Product DevelopmentCWE-269Vulnerability in the Oracle Process Manufacturing Product Development product…
CVE-2026-469288.822.8Oracle CorporationOracle Spares ManagementCWE-269Vulnerability in the Oracle Spares Management product of Oracle E-Business Su…
CVE-2026-394438.122.9PressLayoutsEmallShopCWE-502WordPress EmallShop theme <= 2.4.21 - PHP Object Injection vulnerability
CVE-2026-394468.122.9PressLayoutsKapeeCWE-502WordPress Kapee theme < 1.7.0 - PHP Object Injection vulnerability
CVE-2026-395398.122.9Edge-ThemesAlloggio - Hotel BookingCWE-502WordPress Alloggio - Hotel Booking theme <= 2.1.2 - PHP Object Injection vuln…
CVE-2026-395548.122.9Elated-ThemesFidalgoCWE-502WordPress Fidalgo theme <= 1.2.2 - PHP Object Injection vulnerability
CVE-2026-395678.122.9Select-ThemesSantéCWE-502WordPress Santé theme <= 1.5.1 - PHP Object Injection vulnerability
CVE-2026-106363.722.9zephyrprojectzephyrCWE-416Use-after-free in Zephyr IPv4 IGMP send path (`igmp_send`)
CVE-2026-4697810.022.8Oracle CorporationOracle SolarisCWE-284Vulnerability in the Oracle Solaris product of Oracle Systems (component: Rem…
CVE-2026-353147.322.8Oracle CorporationOracle Access ManagerCWE-284Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-122985.422.6MozillaFirefoxCWE-125Memory safety bug fixed in Firefox 152
CVE-2026-122995.422.6MozillaFirefoxCWE-843JIT miscompilation in the DOM: Core & HTML component
CVE-2026-352588.722.6Oracle CorporationWebLogic ServerCWE-601Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2026-394907.522.6artbeesJupiterX CoreCWE-862WordPress JupiterX Core plugin <= 4.14.1 - Broken Access Control vulnerability
CVE-2026-122939.822.3MozillaFirefoxCWE-416Use-after-free in the Graphics: WebGPU component
CVE-2026-113178.722.2Rockwell AutomationCompactLogix, ControlLogixCWE-404Rockwell Automation Logix 5370 and 5570 Controllers Vulnerable To Denial of S…
CVE-2026-468939.922.2Oracle CorporationJD Edwards EnterpriseOne General LedgerCWE-269Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracl…
CVE-2026-469728.822.2Oracle CorporationOracle Outsourced Mfg for Discrete IndustriesCWE-269Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of…
CVE-2026-353028.322.2Oracle CorporationWebLogic ServerCWE-601Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2026-106377.121.9zephyrprojectzephyrCWE-416Use-after-free of `net_pkt` in IPv6 MLD send path triggerable by a link-local…
CVE-2025-691376.521.9JthemesGenemyCWE-862WordPress Genemy theme <= 1.6.6 - Broken Access Control vulnerability
CVE-2026-121056.521.9DevolutionsDevolutions ServerCWE-862Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an a…
CVE-2026-93076.321.8Rockwell AutomationCompactLogix 5370CWE-497Rockwell Automation CompactLogix 5370 Controllers – Multiple Vulnerabilities
CVE-2026-107488.621.6SonatypeNexus RepositoryCWE-502Nexus Repository 3 - Remote Code Execution via License Deserialization
CVE-2026-490577.521.6EyeCix TechnologiesJobSearchCWE-862WordPress JobSearch plugin <= 3.2.7 - Broken Access Control vulnerability
CVE-2026-469796.521.3Oracle CorporationPeopleSoft Enterprise CS Campus CommunityCWE-284Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Ora…
CVE-2026-108316.921.1MoxaNPort 6000 SeriesCWE-862Improper Authorization of Break Signal Commands in Devices
CVE-2026-469208.121.1Oracle CorporationSiebel CRM Cloud ApplicationsCWE-284Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2025-130369.220.9Rockwell AutomationFactoryTalk Historian SECWE-362Rockwell Automation FactoryTalk Historian Site Edition - Authentication Bypass
CVE-2026-123177.520.7MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-01328.820.5GoogleAndroidCWE-122In Modem, there is a possible out of bounds write due to a heap buffer overfl…
CVE-2026-01498.820.5GoogleAndroidCWE-122In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap…
CVE-2026-123487.420.2The Browser Company of New York`Arc SearchCWE-1021Address Bar Spoofing in Arc Search for Android (window.open race condition)
CVE-2026-468729.020.2Oracle CorporationOracle Enterprise Manager Base PlatformCWE-284Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-497749.919.9Filipe NascRD StationCWE-94WordPress RD Station plugin <= 5.6.0 - Remote Code Execution (RCE) vulnerability
CVE-2026-395818.519.8activity-log.comWP Sessions Time Monitoring Full AutomaticCWE-89WordPress WP Sessions Time Monitoring Full Automatic plugin <= 1.1.4 - SQL In…
CVE-2026-01269.819.6GoogleAndroidCWE-787In WC-Radio, there is a possible out of bounds write due to a missing bounds …
CVE-2026-01398.819.6GoogleAndroidCWE-119In Modem, there is a possible out of bounds write due to a missing bounds che…
CVE-2026-01468.819.6GoogleAndroidCWE-120In mfc_core_get_dec_metadata_sei_nal of mfc_core_reg_api.c, there is a possib…
CVE-2026-01478.819.6GoogleAndroidCWE-120In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a …
CVE-2026-01488.819.6GoogleAndroidCWE-190In multiple functions of VideoRtpPayloadDecoderNode.cpp, there is a possible …
CVE-2026-538438.719.4OpenClawOpenClawCWE-613OpenClaw < 2026.5.26 - Node Token Revocation Bypass via Pairing-Scoped Device…
CVE-2026-407509.919.2themagnifico52Kids Online StoreCWE-434WordPress Kids Online Store theme <= 0.8.9 - Arbitrary File Upload vulnerability
CVE-2026-541976.519.1WpmetGetGenieCWE-201WordPress GetGenie plugin <= 4.4.1 - Sensitive Data Exposure vulnerability
CVE-2026-464488.519.0OpenStackNovaCWE-669In OpenStack Nova before 33.0.2, the server create API does not strip certain…
CVE-2026-352616.519.0Oracle CorporationOracle Access ManagerCWE-287Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-468106.519.0Oracle CorporationIdentity ManagerCWE-284Vulnerability in the Identity Manager product of Oracle Fusion Middleware (co…
CVE-2026-538667.618.7OpenClawOpenClawCWE-862OpenClaw < 2026.5.12 - Allowlist Bypass in Shell Inline-Command Parsing
CVE-2026-353277.618.6Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-395785.518.6Elated-ThemesValianceCWE-502WordPress Valiance theme <= 1.2 - PHP Object Injection vulnerability
CVE-2026-469119.618.3Oracle CorporationJD Edwards EnterpriseOne Project CostingCWE-284Vulnerability in the JD Edwards EnterpriseOne Project Costing product of Orac…
CVE-2026-469129.318.4Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-200Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-538498.618.3OpenClawOpenClawCWE-290OpenClaw < 2026.5.7 - Privilege Escalation via Mutable Discord Display Names …
CVE-2026-469258.318.0Oracle CorporationSiebel CRM Cloud ApplicationsCWE-284Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-123187.317.7MozillaFirefoxCWE-119Incorrect boundary conditions in the Libraries component in NSS
CVE-2026-468716.517.5Oracle CorporationMySQL ShellCWE-284Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell fo…
CVE-2026-123065.317.4MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-123075.317.4MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-123085.317.4MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-121174.317.4DevolutionsDevolutions ServerCWE-200Improper access control in the social login connection endpoint in Devolution…
CVE-2026-538557.617.4OpenClawOpenClawCWE-184OpenClaw < 2026.4.2 - Shell Positional Parameters Bypass in Inline-Eval Checks
CVE-2026-541906.517.2AwesomemotiveEnvira Photo GalleryCWE-862WordPress Envira Photo Gallery plugin <= 1.12.5 - Broken Access Control vulne…
CVE-2026-01276.516.5GoogleAndroidCWE-125In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is …
CVE-2026-01366.516.5GoogleAndroidCWE-120In Modem, there is a possible out of bounds read due to a missing bounds chec…
CVE-2026-01446.516.5GoogleAndroidCWE-120In writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety is…
CVE-2026-123107.516.3MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-123127.516.3MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-123147.516.3MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-123005.316.4MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-123015.316.4MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-123159.116.2MozillaFirefoxCWE-693Mitigation bypass in the DOM: Security component
CVE-2026-395808.116.1Select-ThemesMicdropCWE-502WordPress Micdrop theme <= 1.3.1 - PHP Object Injection vulnerability
CVE-2026-407368.116.1Edge-ThemesLauritsCWE-502WordPress Laurits theme <= 1.5.1 - PHP Object Injection vulnerability
CVE-2026-407548.116.1Elated-ThemesRoisinCWE-502WordPress Roisin theme <= 1.4 - PHP Object Injection vulnerability
CVE-2026-407558.116.1Mikado-ThemesTechLinkCWE-502WordPress TechLink theme <= 1.3 - PHP Object Injection vulnerability
CVE-2026-407608.116.1Edge-ThemesBeholdCWE-502WordPress Behold theme <= 1.5 - PHP Object Injection vulnerability
CVE-2026-407618.116.1Edge-ThemesValeskaCWE-502WordPress Valeska theme <= 1.2.2 - PHP Object Injection vulnerability
CVE-2026-538615.316.0OpenClawOpenClawCWE-184OpenClaw < 2026.5.6 - Allowlist Bypass via Combined POSIX Inline Flags on macOS
CVE-2026-123026.515.8MozillaFirefoxCWE-693Mitigation bypass in the DOM: Security component
CVE-2026-487888.215.7umputunremark42CWE-79Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing
CVE-2026-469587.515.8Oracle CorporationOracle Subledger AccountingCWE-269Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business…
CVE-2026-469597.515.8Oracle CorporationOracle Subledger AccountingCWE-269Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business…
CVE-2026-469717.515.8Oracle CorporationOracle HR IntelligenceCWE-269Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suit…
CVE-2026-17678.115.6Red HatRed Hat Enterprise Linux 10CWE-805Localsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer ove…
CVE-2026-538647.615.6OpenClawOpenClawCWE-184OpenClaw < 2026.5.26 - Insufficient Environment Variable Sanitization in Node…
CVE-2026-123169.115.5MozillaFirefoxCWE-693Mitigation bypass in the DOM: Security component
CVE-2026-468126.115.5Oracle CorporationOracle Access ManagerCWE-284Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-538546.015.5OpenClawOpenClawCWE-863OpenClaw < 2026.4.25 - Privilege Escalation via ownerAllowFrom Wildcard Inher…
CVE-2026-527159.315.2Eyal FitoussiGEO my WordPressCWE-89WordPress GEO my WordPress plugin <= 4.5.5 - SQL Injection vulnerability
CVE-2026-108257.114.8MoxaNPort 6000-G2 SeriesCWE-1287Improper JSON Input Validation in WebSocket API Leads to Denial of Service
CVE-2025-691047.114.4jkdevstudioQreatixCWE-79WordPress Qreatix theme <= 1.9.4 - Cross Site Scripting (XSS) vulnerability
CVE-2025-142728.314.1Rockwell AutomationFactoryTalk Analytics PavilionXCWE-862Rockwell Automation FactoryTalk Analytics PavilionX
CVE-2026-123096.514.2MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-395749.314.1RealMag777InPost GalleryCWE-89WordPress InPost Gallery plugin <= 2.1.4.6 - SQL Injection vulnerability
CVE-2026-118904.314.1DevolutionsDevolutions ServerCWE-882Improper access control in PAM account discovery results in Devolutions Serve…

Results continue: ranks 401–546.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-16 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.