boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, June 16, 2026 · all times UTC← 2026-06-15 · archive · 2026-06-17 →

546 CVEs published, led by Oracle Corporation (240).

546 CVEs published June 16, 2026: 156 critical, 272 high, 101 medium, 17 low; 1 in the KEV catalog at press time; 14 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 146 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published4321875810682564
KEV catalog size1671

417 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux9710658466431212730.37.8.0013-118 ▼
google63080468425281277460.78.1.0023+630 ▲
microsoft208753555131706380273.67.8.0045+69 ▲
red hat62126857556400.07.0.0028+58 ▲
apple146101636294711.55.7.0023+1 ▲
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
suse240400000.08.6.0021+2 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
netgear171700161800.04.3.0024+17 ▲
cisco4173250961058.87.0.1247+3 ▲
palo alto networks911017114218.24.8.0022+8 ▲
ivanti49230033555.68.8.5187+3 ▲
checkpoint3915303111.17.5.0410+3 ▲
ubiquiti584400400.08.9.0052+5 ▲
fortinet28132028337.57.3.0066+1 ▲
zyxel3401301100.06.5.0020+3 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache679915404124011.07.3.0052+63 ▲
mozilla495511182601300.07.3.0026+45 ▲
gitlab1120041224210.04.8.0024+11 ▲
docker250500100.08.8.0021+2 ▲
drupal0511305120.05.1.00260
github021100000.08.1.03470
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2432701311161844020.78.8.0040+243 ▲
adobe1291334497527532.35.5.0021+129 ▲
ibm11601329180700.07.5.0028+11 ▲
progress591710900.07.5.0036+5 ▲
solarwinds36121011466.77.5.3995+3 ▲
veeam142200400.09.0.0046+1 ▲
zohocorp020110000.07.1.01040
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5 ▲
d-link91204252618.35.5.0058+9 ▲
siemens780440100.07.5.0020+6 ▲
rockwell automation771510000.08.7.0030+7 ▲
abb550410000.07.2.0018+5 ▲
moxa550320000.07.0.0029+5 ▲
dahua330111200.06.9.0036+3 ▲
hitachi energy020020000.05.7.00140
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7172230391000.06.5.0023+71 ▲
openclaw61670352210000.07.0.0021+61 ▲
sourcecodester3658002434000.02.1.0026+36 ▲
edimax051032019100.07.4.00590
concrete cms2461111321000.06.2.0015+2 ▲
open ises044221210000.07.1.00210
helmholz04203930000.07.1.00260
mb connect line04203930000.07.1.00260

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2008-4250.987599.9
CVE-2026-35273.954799.99.8
CVE-2026-0257.939199.8
CVE-2010-0249.918899.8
CVE-2026-9082.883299.89.8
CVE-2009-3459.865899.7
CVE-2025-34291.838499.7
CVE-2026-42271.830199.6
CVE-2026-50751.825599.69.3
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-2022310.0.0083
CVE-2026-4714010.0.0082
Most disclosures (vendor)
VendorCVEs
google798
linux523
oracle268
microsoft239
adobe130
red hat99
apache84
spring72
openclaw67
ibm60
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco10
apple7
google6
ivanti5
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven36
Packagist22
PyPI11
npm4
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-34291Langflow0
CVE-2025-48595Google0
CVE-2026-0257Palo Alto Networks0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171672
CVE-2021-27102Accellion2021-11-171672
CVE-2021-27101Accellion2021-11-171672
CVE-2021-27103Accellion2021-11-171672
CVE-2021-21017Adobe2021-11-171672
CVE-2021-28550Adobe2021-11-171672
CVE-2021-42013Apache2021-11-171672
CVE-2021-41773Apache2021-11-171672
CVE-2021-30858Apple2021-11-171672
CVE-2021-30860Apple2021-11-171672

Transactions

EXPLOIT PUBLISHED — zephyrproject zephyr: 5 CVEs (CVE-2026-10635, CVE-2026-10636, CVE-2026-10637, CVE-2026-10639, CVE-2026-10640). Public exploit references added.

EXPLOIT PUBLISHED — leejet stable-diffusion.cpp: 4 CVEs (CVE-2026-47747, CVE-2026-47748, CVE-2026-47749, CVE-2026-47750). Public exploit references added.

EXPLOIT PUBLISHED — Red Hat Enterprise Linux 10: 3 CVEs (CVE-2026-1764, CVE-2026-1766, CVE-2026-1767). Public exploit references added.

EXPLOIT PUBLISHEDCVE-2026-44587 (carrierwaveuploader carrierwave). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-46448 (OpenStack Nova). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48779 (websockets ws). Public exploit reference added.

DUE DATE PASSEDCVE-2026-35273 (Oracle Corporation PeopleSoft Enterprise PeopleTools). CISA remediation deadline was June 15, 2026; still in catalog.

Yesterday's Results

How to read these box scores · glossary

546 CVEs published. 25 box scores and 375 table rows below; the remaining 146 continue on page 2 — every CVE is listed, nothing truncated.

joomlacontenteditor.net Joomla Content Editor (JCE) extension for Joomla — Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .6883   99.3   YES
AFFECTED
  Product                                           Versions          Fixed
  Joomla Content Editor (JCE) extension for Joomla  1.0.0-2.9.99.4 –  —
TIMELINE
  May 26  Reserved by CNA
  Jun 16  Added to CISA KEV, due Jun 19
  Jun 16  Published (CNA: Joomla)
CWE-284 · CNA: Joomla · CVSS v4.0 · 3 references · NVD status: Analyzed · KEV due June 19, 2026
Microsoft Defender Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   H   L   N  U  H  H  H    7.0   .1075   95.5     —
AFFECTED
  Product                              Versions   Fixed
  Microsoft Malware Protection Engine  1.1.0.0 –  —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 16  Published (CNA: microsoft)
CWE-59 · CNA: microsoft · CVSS v3.1 · 2 references · NVD status: Modified
TP-Link Systems Inc. TL-WR940N v6 — OS Command Injection in IPv6 PPPoE Configuration in TP-Link TL-WR940N
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   H   N   H   H   H    8.5   .0279   85.3     —
AFFECTED
  Product       Versions     Fixed
  TL-WR940N v6  unspecified  —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 16  Published (CNA: TPLink)
CWE-78 · CNA: TPLink · CVSS v4.0 · 3 references · NVD status: Analyzed
TP-Link Systems Inc. TL-WR940N v6 — OS Command Injection in BigPond Cable (BPA) Configuration in TP-Link TL-WR940N
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   H   N   H   H   H    8.5   .0279   85.3     —
AFFECTED
  Product       Versions     Fixed
  TL-WR940N v6  unspecified  —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 16  Published (CNA: TPLink)
CWE-78 · CNA: TPLink · CVSS v4.0 · 3 references · NVD status: Analyzed
Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origi…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  N  N    7.4   .0191   78.1     —
AFFECTED
  Product                               Versions     Fixed
  Adobe Acrobat PDF Extension (Chrome)  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 16  Published (CNA: adobe)
CWE-79 · CNA: adobe · CVSS v3.1 · 1 reference · NVD status: Analyzed
Radiflow iSAP Smart Collector — OS Commands Executed with Administrative Permissions in Radiflow iSAP Smart Collector
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0092   57.5     —
AFFECTED
  Product               Versions  Fixed
  iSAP Smart Collector  3.07-1 –  —
TIMELINE
  Jan 7   Reserved by CNA
  Jun 16  Published (CNA: ENISA)
CWE-78 · CNA: ENISA · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
Red Hat Red Hat Ansible Automation Platform 2 — Galaxy_ng: shell injection in legacy role import via unsanitized git ref names
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0089   56.5     —
AFFECTED
  Product                                Versions     Fixed
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
TIMELINE
  Jun 16  Reserved by CNA
  Jun 16  Published (CNA: redhat)
CWE-78 · CNA: redhat · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
Premmerce Dev Tools <= 2.0 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via Plugin Creation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0085   55.2     —
AFFECTED
  Product              Versions     Fixed
  Premmerce Dev Tools  unspecified  —
TIMELINE
  Apr 23  Reserved by CNA
  Jun 16  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
websockets ws — ws: Memory exhaustion DoS from tiny fragments and data chunks
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0078   53.2     —
AFFECTED
  Product  Versions             Fixed
  ws       >= 1.1.0, < 5.2.5 –  —
TIMELINE
  May 22  Reserved by CNA
  Jun 16  Public exploit reference published
  Jun 16  Published (CNA: GitHub_M)
CWE-400, CWE-770 · CNA: GitHub_M · CVSS v3.1 · 26 references · NVD status: Modified
TURCK TBEN-LL-SE-M2 — Command Injection via name parameter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0077   52.8     —
AFFECTED
  Product        Versions  Fixed
  TBEN-LL-SE-M2  0.0.0 –   —
  TBEN-L4-SE-M2  0.0.0 –   —
  TBEN-L5-SE-M2  0.0.0 –   —
TIMELINE
  Apr 2   Reserved by CNA
  Jun 16  Published (CNA: CERTVDE)
CWE-78 · CNA: CERTVDE · CVSS v4.0 · 1 reference · NVD status: Deferred
ServerCo getssl ACME shell script path injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  N    7.4   .0076   52.3     —
AFFECTED
  Product  Versions     Fixed
  getssl   unspecified  —
TIMELINE
  May 31  Reserved by CNA
  Jun 16  Published (CNA: runZero)
CWE-73 · CNA: runZero · CVSS v3.1 · 5 references · NVD status: Awaiting Analysis
Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0072   51.2     —
AFFECTED
  Product      Versions     Fixed
  Rocket.Chat  unspecified  —
TIMELINE
  May 26  Reserved by CNA
  Jun 16  Published (CNA: hackerone)
CWE-287 · CNA: hackerone · CVSS v3.0 · 2 references · NVD status: Analyzed
Oracle Corporation PeopleSoft Enterprise PT PeopleTools — Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Performa…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0064   48.1     —
AFFECTED
  Product                               Versions  Fixed
  PeopleSoft Enterprise PT PeopleTools  8.61 –    —
TIMELINE
  Apr 1   Reserved by CNA
  Jun 16  Published (CNA: oracle)
CWE-306 · CNA: oracle · CVSS v3.1 · 1 reference · NVD status: Analyzed
truelockmc streambert — Streambert: Arbitrary File Write (Zip Slip) via Subtitle Extraction
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  N  H  H   10.0   .0062   47.1     —
AFFECTED
  Product     Versions   Fixed
  streambert  < 2.5.0 –  —
TIMELINE
  May 20  Reserved by CNA
  Jun 16  Published (CNA: GitHub_M)
CWE-20, CWE-22 · CNA: GitHub_M · CVSS v3.1 · 2 references · NVD status: Deferred
Oracle Corporation WebLogic Server — Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versi…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0056   44.4     —
AFFECTED
  Product          Versions      Fixed
  WebLogic Server  12.2.1.4.0 –  —
TIMELINE
  Apr 1   Reserved by CNA
  Jun 16  Published (CNA: oracle)
CWE-502 · CNA: oracle · CVSS v3.1 · 1 reference · NVD status: Analyzed
Red Hat Red Hat Enterprise Linux 10 — Pacemaker: pacemaker: denial of service via integer overflow in remote message decompression
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  H    8.6   .0056   44.2     —
AFFECTED
  Product                                                                Versions     Fixed
  Red Hat Enterprise Linux 10                                            unspecified  0:3.0.1-5.el10_2.1
  Red Hat Enterprise Linux 10.0 Extended Update Support                  unspecified  0:3.0.0-5.3.el10_0
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:1.1.23-1.el7_9.2
  Red Hat Enterprise Linux 8                                             unspecified  0:2.1.7-5.6.el8_10
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  0:2.0.5-9.el8_4.12
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  0:2.0.5-9.el8_4.12
  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support  unspecified  0:2.1.2-4.el8_6.11
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On  unspecified  0:2.1.2-4.el8_6.11
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service         unspecified  0:2.1.5-9.7.el8_8
  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions         unspecified  0:2.1.5-9.7.el8_8
  + 6 more
TIMELINE
  Jun 2   Reserved by CNA
  Jun 16  Published (CNA: redhat)
CWE-190 · CNA: redhat · CVSS v3.1 · 16 references · NVD status: Awaiting Analysis
BoldThemes Nifty — WordPress Nifty theme <= 1.4.1 - PHP Object Injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0056   44.0     —
AFFECTED
  Product  Versions  Fixed
  Nifty    n/a –     1.4.2
TIMELINE
  Feb 19  Reserved by CNA
  Jun 16  Published (CNA: Patchstack)
CWE-502 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
AivahThemes Car Zone — WordPress Car Zone theme <= 3.7 - Arbitrary File Deletion vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  N  N  H    8.6   .0053   42.8     —
AFFECTED
  Product   Versions  Fixed
  Car Zone  n/a –     —
TIMELINE
  Dec 29  Reserved by CNA
  Jun 16  Published (CNA: Patchstack)
CWE-22 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
ThemeREX Hot Coffee — WordPress Hot Coffee theme <= 1.7 - PHP Object Injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0053   42.3     —
AFFECTED
  Product     Versions  Fixed
  Hot Coffee  n/a –     —
TIMELINE
  Dec 29  Reserved by CNA
  Jun 16  Published (CNA: Patchstack)
CWE-502 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
ThemeREX SeaFood Company — WordPress SeaFood Company theme <= 1.4 - PHP Object Injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0053   42.3     —
AFFECTED
  Product          Versions  Fixed
  SeaFood Company  n/a –     —
TIMELINE
  Dec 29  Reserved by CNA
  Jun 16  Published (CNA: Patchstack)
CWE-502 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
Linux Linux — net/sched: fix pedit partial COW leading to page cache corruption
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0053   42.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    abe35bf3be51482593076d516a680d79e5fbc8e1 –  —
  Linux    5.18 –                                      5.10.260
TIMELINE
  May 13  Reserved by CNA
  Jun 16  Published (CNA: Linux)
CWE-190, CWE-787 · CNA: Linux · CVSS v3.1 · 44 references · NVD status: Modified
Oracle Corporation MySQL Shell — Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported vers…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0052   42.1     —
AFFECTED
  Product      Versions          Fixed
  MySQL Shell  2026.2.0+9.6.1 –  —
TIMELINE
  May 18  Reserved by CNA
  Jun 16  Published (CNA: oracle)
CWE-94 · CNA: oracle · CVSS v3.1 · 1 reference · NVD status: Analyzed
Oracle Corporation Identity Manager — Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Suppo…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0052   41.9     —
AFFECTED
  Product           Versions      Fixed
  Identity Manager  12.2.1.4.0 –  —
TIMELINE
  May 18  Reserved by CNA
  Jun 16  Published (CNA: oracle)
CWE-306 · CNA: oracle · CVSS v3.1 · 1 reference · NVD status: Analyzed
Oracle Corporation Identity Manager — Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Core). Supported vers…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0052   41.9     —
AFFECTED
  Product           Versions      Fixed
  Identity Manager  12.2.1.4.0 –  —
TIMELINE
  Apr 1   Reserved by CNA
  Jun 16  Published (CNA: oracle)
CWE-284 · CNA: oracle · CVSS v3.1 · 1 reference · NVD status: Analyzed
Oracle Corporation Oracle Virtual Directory — Vulnerability in the Oracle Virtual Directory product of Oracle Fusion Middleware (component: Virtual Direc…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0052   41.9     —
AFFECTED
  Product                   Versions      Fixed
  Oracle Virtual Directory  12.2.1.4.0 –  —
TIMELINE
  Apr 1   Reserved by CNA
  Jun 16  Published (CNA: oracle)
CWE-284 · CNA: oracle · CVSS v3.1 · 1 reference · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-467739.841.9Oracle CorporationOracle Unified DirectoryCWE-284Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-467749.841.9Oracle CorporationOracle Unified DirectoryCWE-284Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-468579.841.2Oracle CorporationOracle Enterprise Manager Base PlatformCWE-284Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-468599.841.2Oracle CorporationOracle Agile PLMCWE-287Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone…
CVE-2026-84428.140.8https://wpreviewslider.com/WP Review Slider ProCWE-22WP Review Slider Pro <= 12.6.8 - Authenticated (Subscriber+) Arbitrary File D…
CVE-2026-352709.140.5Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-122928.140.4MozillaFirefoxCWE-119Incorrect boundary conditions in the Web Audio component
CVE-2026-3529210.039.8Oracle CorporationWebLogic ServerCWE-306Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2026-3530110.039.8Oracle CorporationWebLogic ServerCWE-306Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2026-4679810.039.8Oracle CorporationOracle WebCenter SitesCWE-306Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-4680010.039.8Oracle CorporationOracle WebCenter SitesCWE-306Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-352869.839.7Oracle CorporationOracle WebCenter ContentCWE-306Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-352939.839.7Oracle CorporationOracle WebCenter SitesCWE-306Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-352969.839.7Oracle CorporationOracle WebCenter SitesCWE-306Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-353109.839.7Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-353199.839.7Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-467839.839.7Oracle CorporationWebCenter Content: ImagingCWE-306Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd…
CVE-2026-467979.839.7Oracle CorporationOracle WebCenter SitesCWE-284Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-468019.839.7Oracle CorporationOracle WebCenter SitesCWE-306Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-468789.839.7Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-284Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-468799.839.7Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-306Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-468809.839.7Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-284Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-468909.839.8Oracle CorporationSiebel Apps - MarketingCWE-284Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co…
CVE-2026-469059.839.7Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-306Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-469099.839.7Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-284Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-468539.639.7Oracle CorporationOracle Enterprise Manager Base PlatformCWE-79Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-352809.939.7Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-352819.939.7Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-122258.739.6syracom AGSecure Login (2FA) for JiraCWE-288syracom Secure Login (2FA) for Confluence allows 2FA bypass via spoofed User-…
CVE-2026-123288.139.3MozillaFirefoxCWE-120Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbi…
CVE-2026-3530710.039.1Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-3530810.039.1Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-4680310.039.1Oracle CorporationOracle WebCenter PortalCWE-306Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-353049.839.1Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-468459.839.1Oracle CorporationOracle WebCenter PortalCWE-306Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-468849.839.1Oracle CorporationSiebel Apps - MarketingCWE-284Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co…
CVE-2026-468879.839.1Oracle CorporationSiebel Apps - MarketingCWE-284Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co…
CVE-2026-468899.839.1Oracle CorporationSiebel Apps - MarketingCWE-284Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co…
CVE-2025-691778.139.2THEMELOGIRoneousCWE-98WordPress Roneous theme <= 2.1.5 - Local File Inclusion vulnerability
CVE-2026-4677810.039.1Oracle CorporationOracle WebCenter Enterprise CaptureCWE-306Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-4678110.039.1Oracle CorporationOracle WebCenter Enterprise CaptureCWE-306Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-353099.839.1Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-467669.839.1Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-467999.839.1Oracle CorporationOracle WebCenter SitesCWE-306Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-468139.839.1Oracle CorporationOracle WebCenter ContentCWE-306Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-468609.839.1Oracle CorporationMySQL RouterCWE-284Vulnerability in the MySQL Router product of Oracle MySQL (component: Router:…
CVE-2026-468819.839.1Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-284Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-468829.839.1Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-284Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-468839.839.1Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-284Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-469029.839.1Oracle CorporationOracle Enterprise Command Center FrameworkCWE-284Vulnerability in the Oracle Enterprise Command Center Framework product of Or…
CVE-2026-469049.839.1Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-284Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-468569.639.1Oracle CorporationOracle Enterprise Manager Base PlatformCWE-79Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-108298.639.0MoxaNPort W2150A-W4/W2250A-W4 SeriesCWE-121A stack-based buffer overflow vulnerability has been found in the NPort W2150…
CVE-2026-81767.539.0latepointLatePoint – Calendar Booking Plugin for Appointments and EventsCWE-269LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administr…
CVE-2026-468637.538.9Oracle CorporationMySQL ServerCWE-400Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com…
CVE-2026-122568.838.8ThemeFusionAvadaCWE-502WordPress Avada theme <= 3.15.3 - PHP Object Injection vulnerability
CVE-2025-691317.538.7extendonsWordPress & WooCommerce Scraper Plugin, Import Data from Any SiteCWE-22WordPress WordPress & WooCommerce Scraper Plugin, Import Data from Any Site p…
CVE-2026-352989.138.4Oracle CorporationWebLogic ServerCWE-284Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2026-468627.538.4Oracle CorporationMySQL RouterCWE-400Vulnerability in the MySQL Router product of Oracle MySQL (component: Router:…
CVE-2026-468759.138.4Oracle CorporationOracle Enterprise Manager Base PlatformCWE-284Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-468969.138.4Oracle CorporationOracle Enterprise Command Center FrameworkCWE-284Vulnerability in the Oracle Enterprise Command Center Framework product of Or…
CVE-2026-469459.138.4Oracle CorporationOracle iSupportCWE-284Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (comp…
CVE-2026-469469.138.4Oracle CorporationOracle iSupportCWE-284Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (comp…
CVE-2026-468518.138.2Oracle CorporationPeopleSoft Enterprise CS Campus CommunityCWE-94Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Ora…
CVE-2026-469449.137.8Oracle CorporationOracle iSupportCWE-284Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (comp…
CVE-2026-353267.237.8Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-467697.237.8Oracle CorporationOracle Application Development Framework (ADF)CWE-284Vulnerability in the Oracle Application Development Framework (ADF) product o…
CVE-2026-468677.237.8Oracle CorporationOracle Enterprise Manager Base PlatformCWE-269Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-468687.237.8Oracle CorporationOracle Enterprise Manager Base PlatformCWE-284Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-469227.237.8Oracle CorporationOracle HR IntelligenceCWE-269Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suit…
CVE-2026-469387.237.8Oracle CorporationOracle Cost ManagementCWE-284Vulnerability in the Oracle Cost Management product of Oracle E-Business Suit…
CVE-2026-469567.237.8Oracle CorporationOracle Property ManagerCWE-284Vulnerability in the Oracle Property Manager product of Oracle E-Business Sui…
CVE-2026-469607.237.8Oracle CorporationOracle Project Portfolio AnalysisCWE-284Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Bu…
CVE-2026-469697.237.8Oracle CorporationOracle Financials for EMEACWE-284Vulnerability in the Oracle Financials for EMEA product of Oracle E-Business …
CVE-2026-469707.237.8Oracle CorporationOracle HR IntelligenceCWE-269Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suit…
CVE-2024-249098.837.4DellOpenManageCWE-77Dell OpenManage Integration with Microsoft Windows Admin Center contains a Re…
CVE-2026-468589.137.3Oracle CorporationAPM - Application Performance ManagementCWE-284Vulnerability in the APM - Application Performance Management product of Orac…
CVE-2026-487779.337.3gtsteffaniakfilebrowserCWE-22FileBrowser Quantum: Path Traversal in public share PATCH allows file ops out…
CVE-2026-468559.936.9Oracle CorporationOracle Enterprise Manager Base PlatformCWE-284Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-352658.836.9Oracle CorporationIdentity ManagerCWE-306Vulnerability in the Identity Manager product of Oracle Fusion Middleware (co…
CVE-2026-352678.836.9Oracle CorporationIdentity ManagerCWE-306Vulnerability in the Identity Manager product of Oracle Fusion Middleware (co…
CVE-2026-06478.836.4Rockwell AutomationFLEX I/O EtherNet/IP AdaptersCWE-306Rockwell Automation FLEX I/O Dual-port EtherNet/IP Adapters – Multiple Vulner…
CVE-2025-589248.136.4ThemeREX GroupGeyaCWE-98WordPress Geya theme <= 1.15 - Local File Inclusion vulnerability
CVE-2025-691058.136.4ThemeREXModerneeCWE-98WordPress Modernee theme <= 1.6.0 - Local File Inclusion vulnerability
CVE-2025-691078.136.4ThemeREXRosaleenCWE-98WordPress Rosaleen theme <= 2.8 - Local File Inclusion vulnerability
CVE-2025-691098.136.4ThemeREXRaider SpiritCWE-98WordPress Raider Spirit theme <= 1.1.2 - Local File Inclusion vulnerability
CVE-2025-691128.136.4ThemeREXPlantyCWE-98WordPress Planty theme <= 1.14.0 - Local File Inclusion vulnerability
CVE-2025-691138.136.4ThemeREXNexioCWE-98WordPress Nexio theme <= 1.10.0 - Local File Inclusion vulnerability
CVE-2025-691148.136.4ThemeREXMaxiNetCWE-98WordPress MaxiNet theme <= 1.2.10 - Local File Inclusion vulnerability
CVE-2025-691168.136.4ThemeREXIonaCWE-98WordPress Iona theme <= 1.0.8 - Local File Inclusion vulnerability
CVE-2025-691198.136.4ThemeREXCorbesierCWE-98WordPress Corbesier theme <= 1.15.0 - Local File Inclusion vulnerability
CVE-2025-691218.136.4ThemeREXDeliciosaCWE-98WordPress Deliciosa theme <= 1.10.0 - Local File Inclusion vulnerability
CVE-2025-691248.136.4ThemeREXEspecioCWE-98WordPress Especio theme <= 1.0 - Local File Inclusion vulnerability
CVE-2025-691368.136.4THEMELOGIWaniumCWE-98WordPress Wanium theme <= 1.9.8 - Local File Inclusion vulnerability
CVE-2025-691428.136.4ThemeREXAbelleCWE-98WordPress Abelle theme <= 1.22 - Local File Inclusion vulnerability
CVE-2025-691438.136.4ThemeREXMissionCWE-98WordPress Mission theme <= 1.22 - Local File Inclusion vulnerability
CVE-2025-691478.136.4ThemeREXPutterCWE-98WordPress Putter theme <= 1.17 - Local File Inclusion vulnerability
CVE-2025-691498.136.4ThemeREXTop DogCWE-98WordPress Top Dog theme <= 1.0.5 - Local File Inclusion vulnerability
CVE-2025-691508.136.4ThemeREXMedeusCWE-98WordPress Medeus theme <= 1.14 - Local File Inclusion vulnerability
CVE-2025-691598.136.4ThemeREXPrintoCWE-98WordPress Printo theme <= 1.11 - Local File Inclusion vulnerability
CVE-2025-691608.136.4ThemeREXGitaCWE-98WordPress Gita theme <= 1.11 - Local File Inclusion vulnerability
CVE-2025-691628.136.4ThemeREXGreckoCWE-98WordPress Grecko theme <= 5.17 - Local File Inclusion vulnerability
CVE-2025-691638.136.4ThemeREXWineShopCWE-98WordPress WineShop theme <= 3.17 - Local File Inclusion vulnerability
CVE-2025-691658.136.4ThemeREXChoreoCWE-98WordPress Choreo theme <= 1.6 - Local File Inclusion vulnerability
CVE-2025-691678.136.4ThemeREXErosCWE-98WordPress Eros theme <= 1.3 - Local File Inclusion vulnerability
CVE-2025-691688.136.4ThemeREXSpikeCWE-98WordPress Spike theme <= 1.2 - Local File Inclusion vulnerability
CVE-2025-691788.136.4CactusThemesTruemagCWE-98WordPress Truemag theme <= 4.3.14.2 - Local File Inclusion vulnerability
CVE-2026-467779.136.4Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-467949.936.2Oracle CorporationIdentity Manager ConnectorCWE-269Vulnerability in the Identity Manager Connector product of Oracle Fusion Midd…
CVE-2026-468648.836.2Oracle CorporationOracle Enterprise Manager Base PlatformCWE-284Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-2547010.035.9ACPTACPT (Pro) - Custom Post Types Plugin for WordPressCWE-94WordPress ACPT (Pro) - Custom Post Types plugin for WordPress plugin <= 2.0.4…
CVE-2026-467849.135.7Oracle CorporationWebCenter Content: ImagingCWE-284Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd…
CVE-2025-600858.135.5ThemeREX GroupLearnifyCWE-98WordPress Learnify theme <= 1.15.0 - Local File Inclusion vulnerability
CVE-2026-348948.135.5WebGeniusLabIntegrio CoreCWE-98WordPress Integrio Core plugin < 1.2.8 - Local File Inclusion vulnerability
CVE-2026-395228.135.5Elated-ThemesSoleneCWE-98WordPress Solene theme <= 3.4 - Local File Inclusion vulnerability
CVE-2026-395498.135.5Elated-ThemesAperitifCWE-98WordPress Aperitif theme <= 1.5 - Local File Inclusion vulnerability
CVE-2026-395688.135.5Elated-ThemesMr. SEOCWE-98WordPress Mr. SEO theme <= 2.0 - Local File Inclusion vulnerability
CVE-2026-467899.634.8Oracle CorporationOracle WebCenter ContentCWE-306Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-352768.134.9Oracle CorporationPeopleSoft Enterprise PT PeopleToolsCWE-306Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle P…
CVE-2026-467917.534.7Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-352839.934.4Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-352849.934.4Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-352859.934.4Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-352949.934.4Oracle CorporationIdentity Manager ConnectorCWE-284Vulnerability in the Identity Manager Connector product of Oracle Fusion Midd…
CVE-2026-353139.934.4Oracle CorporationOracle Access ManagerCWE-284Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-353169.934.4Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-353219.934.4Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-353239.934.4Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-468329.934.5Oracle CorporationOracle Enterprise Manager Base PlatformCWE-284Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-468389.934.4Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-468479.934.4Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-468549.934.5Oracle CorporationOracle Enterprise Manager Base PlatformCWE-284Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-468959.934.5Oracle CorporationOracle Enterprise Command Center FrameworkCWE-269Vulnerability in the Oracle Enterprise Command Center Framework product of Or…
CVE-2026-469079.934.4Oracle CorporationJD Edwards EnterpriseOne Order PromisingCWE-284Vulnerability in the JD Edwards EnterpriseOne Order Promising product of Orac…
CVE-2026-469089.934.4Oracle CorporationJD Edwards EnterpriseOne Accounts PayableCWE-284Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product of Ora…
CVE-2026-469189.934.4Oracle CorporationOracle Process Manufacturing Product DevelopmentCWE-284Vulnerability in the Oracle Process Manufacturing Product Development product…
CVE-2026-469339.934.4Oracle CorporationOracle Applications ManagerCWE-269Vulnerability in the Oracle Applications Manager product of Oracle E-Business…
CVE-2026-352998.834.5Oracle CorporationWebLogic ServerCWE-306Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2026-353038.834.5Oracle CorporationWebLogic ServerCWE-306Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2026-353158.834.4Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-353178.834.4Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-353228.834.4Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-353258.834.4Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-468868.834.5Oracle CorporationSiebel Apps - MarketingCWE-284Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co…
CVE-2026-469298.834.4Oracle CorporationOracle Cost ManagementCWE-269Vulnerability in the Oracle Cost Management product of Oracle E-Business Suit…
CVE-2026-469318.834.4Oracle CorporationOracle Enterprise Asset ManagementCWE-284Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-B…
CVE-2026-469378.834.4Oracle CorporationOracle iSetupCWE-269Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (compon…
CVE-2026-469408.834.4Oracle CorporationOracle Cost ManagementCWE-269Vulnerability in the Oracle Cost Management product of Oracle E-Business Suit…
CVE-2026-469428.834.4Oracle CorporationOracle Process Manufacturing Process PlanningCWE-269Vulnerability in the Oracle Process Manufacturing Process Planning product of…
CVE-2026-469478.834.4Oracle CorporationOracle Advanced Outbound TelephonyCWE-284Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-B…
CVE-2026-469508.834.4Oracle CorporationOracle Advanced Outbound TelephonyCWE-284Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-B…
CVE-2026-469518.834.4Oracle CorporationOracle QualityCWE-269Vulnerability in the Oracle Quality product of Oracle E-Business Suite (compo…
CVE-2026-469618.834.4Oracle CorporationOracle Project Portfolio AnalysisCWE-269Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Bu…
CVE-2026-469658.834.4Oracle CorporationOracle Universal Work QueueCWE-284Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business…
CVE-2026-469738.834.4Oracle CorporationOracle Outsourced Mfg for Discrete IndustriesCWE-269Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of…
CVE-2026-123278.134.1MozillaFirefoxCWE-119Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firef…
CVE-2026-352898.134.1Oracle CorporationPeopleSoft Enterprise PT PeopleToolsCWE-306Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle P…
CVE-2025-691037.534.1UtillzBrikkCWE-862WordPress Brikk theme <= 3.0.0 - Arbitrary Content Deletion vulnerability
CVE-2026-468099.133.9Oracle CorporationOracle WebCenter SitesCWE-284Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-469309.133.9Oracle CorporationOracle In-Memory Cost Management for Discrete IndustriesCWE-284Vulnerability in the Oracle In-Memory Cost Management for Discrete Industries…
CVE-2026-469499.133.9Oracle CorporationOracle Advanced Outbound TelephonyCWE-284Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-B…
CVE-2026-468529.933.7Oracle CorporationOracle Enterprise Manager Base PlatformCWE-269Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-353118.833.7Oracle CorporationWebLogic ServerCWE-284Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2026-468858.833.7Oracle CorporationSiebel CRM IntegrationCWE-269Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com…
CVE-2026-469218.833.7Oracle CorporationSiebel CRM Cloud ApplicationsCWE-269Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-95075.133.8EnhancesoftosTicketCWE-38Session fixation vulnerability in Enhancesoft's osTicket
CVE-2026-352829.933.6Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-467659.933.6Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-467679.933.6Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-467799.933.6Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-467829.933.6Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-467929.933.6Oracle CorporationIdentity Manager ConnectorCWE-284Vulnerability in the Identity Manager Connector product of Oracle Fusion Midd…
CVE-2026-467939.933.6Oracle CorporationIdentity Manager ConnectorCWE-284Vulnerability in the Identity Manager Connector product of Oracle Fusion Midd…
CVE-2026-468029.933.6Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-468149.933.6Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-468449.933.6Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-469009.933.6Oracle CorporationOracle Enterprise Command Center FrameworkCWE-269Vulnerability in the Oracle Enterprise Command Center Framework product of Or…
CVE-2026-469639.933.6Oracle CorporationOracle Universal Work QueueCWE-284Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business…
CVE-2026-469649.933.6Oracle CorporationOracle Universal Work QueueCWE-269Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business…
CVE-2026-353188.833.6Oracle CorporationOracle WebCenter SitesCWE-284Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-353248.833.6Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-467808.833.6Oracle CorporationWebCenter Content: ImagingCWE-306Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd…
CVE-2026-469038.833.6Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-269Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-469528.833.6Oracle CorporationOracle QualityCWE-269Vulnerability in the Oracle Quality product of Oracle E-Business Suite (compo…
CVE-2026-469628.833.6Oracle CorporationOracle Project Portfolio AnalysisCWE-269Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Bu…
CVE-2026-469678.833.6Oracle CorporationOracle Public Sector Financials (International)CWE-284Vulnerability in the Oracle Public Sector Financials (International) product …
CVE-2026-472776.533.2runtipiruntipiCWE-22Runtipi: Unauthenticated arbitrary file read through app-store logo symlinks
CVE-2026-467888.433.1Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-122908.133.1MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-468929.133.0Oracle CorporationJD Edwards EnterpriseOne Human Resources ManagementCWE-284Vulnerability in the JD Edwards EnterpriseOne Human Resources Management prod…
CVE-2026-23816.533.0woocommerceWooCommerce Stripe Payment GatewayCWE-862WooCommerce Stripe Payment Gateway <= 10.7.0 - Missing Authorization to Unaut…
CVE-2026-122898.832.9MozillaFirefoxCWE-269Privilege escalation in the Graphics: WebRender component
CVE-2026-395578.132.8Elated-ThemesNeoBeatCWE-502WordPress NeoBeat theme <= 1.7 - PHP Object Injection vulnerability
CVE-2026-122959.632.6MozillaFirefoxCWE-693Sandbox escape in the DOM: Navigation component
CVE-2026-122969.632.6MozillaFirefoxCWE-693Sandbox escape in the Security: Process Sandboxing component
CVE-2026-122979.632.6MozillaFirefoxCWE-119Sandbox escape due to incorrect boundary conditions in the Networking component
CVE-2026-468668.232.6Oracle CorporationOracle Enterprise Manager Base PlatformCWE-400Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-467959.332.4Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-468059.332.4Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-352598.832.3Oracle CorporationWebLogic ServerCWE-601Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2026-352628.332.0Oracle CorporationOracle Data IntegratorCWE-284Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middlewa…
CVE-2026-122918.831.5MozillaFirefoxCWE-416Use-after-free in the Networking: HTTP component
CVE-2026-352748.230.9Oracle CorporationPeopleSoft Enterprise PT PeopleToolsCWE-306Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle P…
CVE-2026-395299.830.8ThemeREX GroupElementraCWE-502WordPress Elementra theme <= 1.0.9 - PHP Object Injection vulnerability
CVE-2026-541949.830.8ThemeFusionFusion BuilderCWE-502WordPress Fusion Builder plugin <= 3.15.4 - PHP Object Injection vulnerability
CVE-2026-468498.130.8Oracle CorporationPeopleSoft Enterprise CS Student FinancialsCWE-284Vulnerability in the PeopleSoft Enterprise CS Student Financials product of O…
CVE-2026-352798.130.7Oracle CorporationPeopleSoft Enterprise PT PeopleToolsCWE-306Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle P…
CVE-2026-469278.130.7Oracle CorporationOracle ReceivablesCWE-284Vulnerability in the Oracle Receivables product of Oracle E-Business Suite (c…
CVE-2026-123057.530.7MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-353209.030.6Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-394389.330.5Emraan CheemaListingProCWE-89WordPress ListingPro plugin <= 2.9.10 - SQL Injection vulnerability
CVE-2026-467768.630.4Oracle CorporationOracle Unified DirectoryCWE-284Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-491138.530.3THEMECOCornerstoneCWE-94WordPress Cornerstone plugin < 7.8.8 - Arbitrary Code Execution vulnerability
CVE-2026-106407.130.3zephyrprojectzephyrCWE-416Use-after-free reading `net_pkt` `iface` after send in IPv6 Neighbor Discover…
CVE-2026-468979.930.0Oracle CorporationOracle Enterprise Command Center FrameworkCWE-284Vulnerability in the Oracle Enterprise Command Center Framework product of Or…
CVE-2026-469019.930.0Oracle CorporationOracle Enterprise Command Center FrameworkCWE-269Vulnerability in the Oracle Enterprise Command Center Framework product of Or…
CVE-2026-122949.629.5MozillaFirefoxCWE-693Sandbox escape in the DOM: Workers component
CVE-2026-123268.129.5MozillaFirefoxCWE-119Memory safety bugs fixed in Firefox 152 and Thunderbird 152
CVE-2026-352639.929.4Oracle CorporationWebLogic ServerCWE-284Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2026-469199.829.5Oracle CorporationSiebel CRM Cloud ApplicationsCWE-284Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-468619.629.5Oracle CorporationMySQL NDB ClusterCWE-284Vulnerability in the MySQL NDB Cluster product of Oracle MySQL (component: Cl…
CVE-2026-469327.129.3Oracle CorporationOracle Enterprise Asset ManagementCWE-284Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-B…
CVE-2026-537769.329.0PerryTSperryCWE-613Perry < 0.5.1166 JWT Expiration Bypass via verify_decode
CVE-2026-4684610.028.7Oracle CorporationOracle WebCenter PortalCWE-306Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-449328.828.7SUSEwickedCWE-78indirect remote shell command injection via unsanitized DHCP options in wicked
CVE-2026-497729.328.7Liquid Web / StellarWPThe Events CalendarCWE-89WordPress The Events Calendar plugin 6.15.12-6.16.2 - SQL Injection vulnerabi…
CVE-2026-469109.128.7Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-20Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-352697.528.7Oracle CorporationIdentity ManagerCWE-284Vulnerability in the Identity Manager product of Oracle Fusion Middleware (co…
CVE-2026-353069.328.5Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-467968.028.6Oracle CorporationOracle WebCenter SitesCWE-601Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-106387.528.5zephyrprojectzephyrCWE-416Use-after-free in Zephyr ICMPv6 RX path when updating statistics after sendin…
CVE-2026-394336.528.4mojoomlaWPAMSCWE-862WordPress WPAMS plugin < 49.5.3 - Arbitrary Content Deletion vulnerability
CVE-2026-468988.128.3Oracle CorporationOracle Enterprise Command Center FrameworkCWE-284Vulnerability in the Oracle Enterprise Command Center Framework product of Or…
CVE-2026-352916.628.2Oracle CorporationWebLogic ServerCWE-269Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2025-691188.128.0ThemeREXCopyPressCWE-98WordPress CopyPress theme <= 1.4.5 - Local File Inclusion vulnerability
CVE-2025-691258.128.0ThemeREXFood DropCWE-98WordPress Food Drop theme <= 1.3 - Local File Inclusion vulnerability
CVE-2025-691418.128.0ThemeREXKelly YoungCWE-98WordPress Kelly Young theme <= 1.1.0 - Local File Inclusion vulnerability
CVE-2025-691468.128.0ThemeREXDomCWE-98WordPress Dom theme <= 1.24 - Local File Inclusion vulnerability
CVE-2025-691768.128.0ThemeREXITacticsCWE-98WordPress ITactics theme <= 1.0 - Local File Inclusion vulnerability
CVE-2026-84448.827.8https://wpreviewslider.com/WP Review Slider ProCWE-89WP Review Slider Pro <= 12.6.8 - Authenticated (Subscriber+) SQL Injection vi…
CVE-2026-538537.627.9OpenClawOpenClawCWE-693OpenClaw < 2026.5.12 - Argument Pattern Bypass in Exec Allowlist via Linux an…
CVE-2026-273959.827.6SchioccoSupport BoardCWE-266WordPress Support Board plugin < 3.8.9 - Privilege Escalation vulnerability
CVE-2026-468999.627.6Oracle CorporationOracle Enterprise Command Center FrameworkCWE-269Vulnerability in the Oracle Enterprise Command Center Framework product of Or…
CVE-2026-469398.127.6Oracle CorporationOracle Configure to OrderCWE-284Vulnerability in the Oracle Configure to Order product of Oracle E-Business S…
CVE-2026-06468.727.4Rockwell AutomationFLEX I/O EtherNet/IP AdaptersCWE-401Rockwell Automation FLEX I/O Dual-port EtherNet/IP Adapters – Multiple Vulner…
CVE-2026-469537.227.0Oracle CorporationOracle HRMS (UK)CWE-269Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (com…
CVE-2026-469767.227.0Oracle CorporationOracle Public Sector PayrollCWE-284Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Busines…
CVE-2026-353059.326.9Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-348938.126.9WebGeniusLabThegov CoreCWE-98WordPress Thegov Core plugin < 2.0.23 - Local File Inclusion vulnerability
CVE-2026-348958.126.9WebGeniusLabSoftlab CoreCWE-98WordPress Softlab Core plugin < 1.2.11 - Local File Inclusion vulnerability
CVE-2026-395478.126.9Select-ThemesGetawayCWE-98WordPress Getaway theme < 1.8 - Local File Inclusion vulnerability
CVE-2026-469069.626.8Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-284Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-468918.126.8Oracle CorporationJD Edwards EnterpriseOne Accounts PayableCWE-284Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product of Ora…
CVE-2026-467905.326.8Oracle CorporationOracle WebCenter ContentCWE-200Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-84438.826.6https://wpreviewslider.com/WP Review Slider ProCWE-89WP Review Slider Pro <= 12.6.8 - Authenticated (Subscriber+) SQL Injection vi…
CVE-2026-486169.326.2Rocket.ChatRocket.ChatCWE-284Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.…
CVE-2026-468088.726.3Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-51496.525.7romethemeRTMKitCWE-863RTMKit <= 2.0.7 - Authenticated (Contributor+) Missing Authorization to Arbit…
CVE-2026-468048.725.5Oracle CorporationOracle WebCenter ContentCWE-269Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-487979.325.4mcp-tool-shop-orgbackpropagateCWE-358Backpropagate: backprop ui --auth and backprop ui --share do not enforce auth…
CVE-2026-352718.725.3Oracle CorporationPeopleSoft Enterprise PT PeopleToolsCWE-284Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle P…
CVE-2026-468068.225.3Oracle CorporationOracle WebCenter ContentCWE-601Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-487459.325.2traccartraccar-clientCWE-940Traccar Client: silent configuration hijack via unverified deep link redirect…
CVE-2026-69645.325.3j_3rkVideo Conferencing with ZoomCWE-862Video Conferencing with Zoom <= 4.6.7 - Missing Authorization to Unauthentica…
CVE-2026-487826.825.1pydanticpydantic-aiCWE-918pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local N…
CVE-2026-407398.124.9Mikado-ThemesLuxeDriveCWE-502WordPress LuxeDrive theme <= 1.4 - PHP Object Injection vulnerability
CVE-2026-407518.124.9Mikado-ThemesAshtangaCWE-502WordPress Ashtanga theme <= 1.2 - PHP Object Injection vulnerability
CVE-2026-407588.124.9Elated-ThemesLéonieCWE-502WordPress Léonie theme <= 1.2.1 - PHP Object Injection vulnerability
CVE-2026-407598.124.9Mikado-ThemesEsméeCWE-502WordPress Esmée theme <= 1.4 - PHP Object Injection vulnerability
CVE-2026-469158.524.6Oracle CorporationOracle Complex Maintenance, Repair and OverhaulCWE-284Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product …
CVE-2026-72738.824.3ZyxelGS1900-48HPv2 firmwareCWE-121A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS190…
CVE-2026-123295.324.2MozillaFirefoxCWE-119Memory safety bug fixed in Thunderbird ESR 140.12
CVE-2026-490809.324.0TMSwpDataTablesCWE-89WordPress wpDataTables plugin <= 7.3.6 - SQL Injection vulnerability
CVE-2026-468708.523.9Oracle CorporationMySQL ShellCWE-284Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell fo…
CVE-2026-352957.523.9Oracle CorporationOracle WebCenter SitesCWE-306Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-469347.523.9Oracle CorporationOracle Complex Maintenance, Repair and OverhaulCWE-269Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product …
CVE-2026-469357.523.9Oracle CorporationOracle Complex Maintenance, Repair and OverhaulCWE-269Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product …
CVE-2026-469577.523.9Oracle CorporationOracle iSupplier PortalCWE-284Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Sui…
CVE-2026-469667.523.9Oracle CorporationOracle Universal Work QueueCWE-269Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business…
CVE-2026-108286.923.8MoxaNPort W2150A-W4/W2250A-W4 SeriesCWE-134A format string vulnerability has been found in the "alias" parameter of the …
CVE-2026-469168.823.5Oracle CorporationOracle Process Manufacturing Product DevelopmentCWE-269Vulnerability in the Oracle Process Manufacturing Product Development product…
CVE-2026-469288.823.5Oracle CorporationOracle Spares ManagementCWE-269Vulnerability in the Oracle Spares Management product of Oracle E-Business Su…
CVE-2026-394438.123.5PressLayoutsEmallShopCWE-502WordPress EmallShop theme <= 2.4.21 - PHP Object Injection vulnerability
CVE-2026-394468.123.5PressLayoutsKapeeCWE-502WordPress Kapee theme < 1.7.0 - PHP Object Injection vulnerability
CVE-2026-395398.123.5Edge-ThemesAlloggio - Hotel BookingCWE-502WordPress Alloggio - Hotel Booking theme <= 2.1.2 - PHP Object Injection vuln…
CVE-2026-395548.123.5Elated-ThemesFidalgoCWE-502WordPress Fidalgo theme <= 1.2.2 - PHP Object Injection vulnerability
CVE-2026-395678.123.5Select-ThemesSantéCWE-502WordPress Santé theme <= 1.5.1 - PHP Object Injection vulnerability
CVE-2026-106363.723.5zephyrprojectzephyrCWE-416Use-after-free in Zephyr IPv4 IGMP send path (`igmp_send`)
CVE-2026-4697810.023.4Oracle CorporationOracle SolarisCWE-284Vulnerability in the Oracle Solaris product of Oracle Systems (component: Rem…
CVE-2026-353147.323.5Oracle CorporationOracle Access ManagerCWE-284Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-122985.423.3MozillaFirefoxCWE-125Memory safety bug fixed in Firefox 152
CVE-2026-122995.423.3MozillaFirefoxCWE-843JIT miscompilation in the DOM: Core & HTML component
CVE-2026-352588.723.2Oracle CorporationWebLogic ServerCWE-601Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2026-394907.523.2artbeesJupiterX CoreCWE-862WordPress JupiterX Core plugin <= 4.14.1 - Broken Access Control vulnerability
CVE-2026-122939.822.9MozillaFirefoxCWE-416Use-after-free in the Graphics: WebGPU component
CVE-2026-113178.722.8Rockwell AutomationCompactLogix, ControlLogixCWE-404Rockwell Automation Logix 5370 and 5570 Controllers Vulnerable To Denial of S…
CVE-2026-468939.922.8Oracle CorporationJD Edwards EnterpriseOne General LedgerCWE-269Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracl…
CVE-2026-469728.822.8Oracle CorporationOracle Outsourced Mfg for Discrete IndustriesCWE-269Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of…
CVE-2026-353028.322.8Oracle CorporationWebLogic ServerCWE-601Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2026-106377.122.6zephyrprojectzephyrCWE-416Use-after-free of `net_pkt` in IPv6 MLD send path triggerable by a link-local…
CVE-2025-691376.522.6JthemesGenemyCWE-862WordPress Genemy theme <= 1.6.6 - Broken Access Control vulnerability
CVE-2026-121056.522.5DevolutionsDevolutions ServerCWE-862Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an a…
CVE-2026-93076.322.4Rockwell AutomationCompactLogix 5370CWE-497Rockwell Automation CompactLogix 5370 Controllers – Multiple Vulnerabilities
CVE-2026-107488.622.3SonatypeNexus RepositoryCWE-502Nexus Repository 3 - Remote Code Execution via License Deserialization
CVE-2026-490577.522.3EyeCix TechnologiesJobSearchCWE-862WordPress JobSearch plugin <= 3.2.7 - Broken Access Control vulnerability
CVE-2026-469796.522.0Oracle CorporationPeopleSoft Enterprise CS Campus CommunityCWE-284Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Ora…
CVE-2026-108316.921.8MoxaNPort 6000 SeriesCWE-862Improper Authorization of Break Signal Commands in Devices
CVE-2026-469208.121.7Oracle CorporationSiebel CRM Cloud ApplicationsCWE-284Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2025-130369.221.5Rockwell AutomationFactoryTalk Historian SECWE-362Rockwell Automation FactoryTalk Historian Site Edition - Authentication Bypass
CVE-2026-123177.521.4MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-01328.821.1GoogleAndroidCWE-122In Modem, there is a possible out of bounds write due to a heap buffer overfl…
CVE-2026-01498.821.1GoogleAndroidCWE-122In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap…
CVE-2026-123487.420.8The Browser Company of New York`Arc SearchCWE-1021Address Bar Spoofing in Arc Search for Android (window.open race condition)
CVE-2026-468729.020.8Oracle CorporationOracle Enterprise Manager Base PlatformCWE-284Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-497749.920.5Filipe NascRD StationCWE-94WordPress RD Station plugin <= 5.6.0 - Remote Code Execution (RCE) vulnerability
CVE-2026-395818.520.4activity-log.comWP Sessions Time Monitoring Full AutomaticCWE-89WordPress WP Sessions Time Monitoring Full Automatic plugin <= 1.1.4 - SQL In…
CVE-2026-01269.820.2GoogleAndroidCWE-787In WC-Radio, there is a possible out of bounds write due to a missing bounds …
CVE-2026-01398.820.2GoogleAndroidCWE-119In Modem, there is a possible out of bounds write due to a missing bounds che…
CVE-2026-01468.820.2GoogleAndroidCWE-120In mfc_core_get_dec_metadata_sei_nal of mfc_core_reg_api.c, there is a possib…
CVE-2026-01478.820.2GoogleAndroidCWE-120In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a …
CVE-2026-01488.820.2GoogleAndroidCWE-190In multiple functions of VideoRtpPayloadDecoderNode.cpp, there is a possible …
CVE-2026-538438.720.0OpenClawOpenClawCWE-613OpenClaw < 2026.5.26 - Node Token Revocation Bypass via Pairing-Scoped Device…
CVE-2026-407509.919.8themagnifico52Kids Online StoreCWE-434WordPress Kids Online Store theme <= 0.8.9 - Arbitrary File Upload vulnerability
CVE-2026-541976.519.8WpmetGetGenieCWE-201WordPress GetGenie plugin <= 4.4.1 - Sensitive Data Exposure vulnerability
CVE-2026-464488.519.6OpenStackNovaCWE-669In OpenStack Nova before 33.0.2, the server create API does not strip certain…
CVE-2026-352616.519.7Oracle CorporationOracle Access ManagerCWE-287Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-468106.519.7Oracle CorporationIdentity ManagerCWE-284Vulnerability in the Identity Manager product of Oracle Fusion Middleware (co…
CVE-2026-538667.619.4OpenClawOpenClawCWE-862OpenClaw < 2026.5.12 - Allowlist Bypass in Shell Inline-Command Parsing
CVE-2026-353277.619.3Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-395785.519.3Elated-ThemesValianceCWE-502WordPress Valiance theme <= 1.2 - PHP Object Injection vulnerability
CVE-2026-469119.618.9Oracle CorporationJD Edwards EnterpriseOne Project CostingCWE-284Vulnerability in the JD Edwards EnterpriseOne Project Costing product of Orac…
CVE-2026-469129.319.0Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-200Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-538498.618.9OpenClawOpenClawCWE-290OpenClaw < 2026.5.7 - Privilege Escalation via Mutable Discord Display Names …
CVE-2026-469258.318.6Oracle CorporationSiebel CRM Cloud ApplicationsCWE-284Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-123187.318.3MozillaFirefoxCWE-119Incorrect boundary conditions in the Libraries component in NSS
CVE-2026-468716.518.1Oracle CorporationMySQL ShellCWE-284Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell fo…
CVE-2026-123065.318.0MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-123075.318.0MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-123085.318.0MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-121174.318.0DevolutionsDevolutions ServerCWE-200Improper access control in the social login connection endpoint in Devolution…
CVE-2026-538557.617.9OpenClawOpenClawCWE-184OpenClaw < 2026.4.2 - Shell Positional Parameters Bypass in Inline-Eval Checks
CVE-2026-541906.517.8AwesomemotiveEnvira Photo GalleryCWE-862WordPress Envira Photo Gallery plugin <= 1.12.5 - Broken Access Control vulne…
CVE-2026-01276.517.1GoogleAndroidCWE-125In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is …
CVE-2026-01366.517.1GoogleAndroidCWE-120In Modem, there is a possible out of bounds read due to a missing bounds chec…
CVE-2026-01446.517.1GoogleAndroidCWE-120In writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety is…
CVE-2026-123107.516.9MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-123127.516.9MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-123147.516.9MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-123005.316.9MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-123015.316.9MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-123159.116.8MozillaFirefoxCWE-693Mitigation bypass in the DOM: Security component
CVE-2026-395808.116.6Select-ThemesMicdropCWE-502WordPress Micdrop theme <= 1.3.1 - PHP Object Injection vulnerability
CVE-2026-407368.116.6Edge-ThemesLauritsCWE-502WordPress Laurits theme <= 1.5.1 - PHP Object Injection vulnerability
CVE-2026-407548.116.6Elated-ThemesRoisinCWE-502WordPress Roisin theme <= 1.4 - PHP Object Injection vulnerability
CVE-2026-407558.116.6Mikado-ThemesTechLinkCWE-502WordPress TechLink theme <= 1.3 - PHP Object Injection vulnerability
CVE-2026-407608.116.6Edge-ThemesBeholdCWE-502WordPress Behold theme <= 1.5 - PHP Object Injection vulnerability
CVE-2026-407618.116.6Edge-ThemesValeskaCWE-502WordPress Valeska theme <= 1.2.2 - PHP Object Injection vulnerability
CVE-2026-538615.316.6OpenClawOpenClawCWE-184OpenClaw < 2026.5.6 - Allowlist Bypass via Combined POSIX Inline Flags on macOS
CVE-2026-123026.516.4MozillaFirefoxCWE-693Mitigation bypass in the DOM: Security component
CVE-2026-487888.216.3umputunremark42CWE-79Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing
CVE-2026-469587.516.3Oracle CorporationOracle Subledger AccountingCWE-269Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business…
CVE-2026-469597.516.3Oracle CorporationOracle Subledger AccountingCWE-269Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business…
CVE-2026-469717.516.3Oracle CorporationOracle HR IntelligenceCWE-269Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suit…
CVE-2026-17678.116.1Red HatRed Hat Enterprise Linux 10CWE-805Localsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer ove…
CVE-2026-538647.616.2OpenClawOpenClawCWE-184OpenClaw < 2026.5.26 - Insufficient Environment Variable Sanitization in Node…
CVE-2026-123169.116.1MozillaFirefoxCWE-693Mitigation bypass in the DOM: Security component
CVE-2026-468126.116.0Oracle CorporationOracle Access ManagerCWE-284Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-538546.016.1OpenClawOpenClawCWE-863OpenClaw < 2026.4.25 - Privilege Escalation via ownerAllowFrom Wildcard Inher…
CVE-2026-527159.315.7Eyal FitoussiGEO my WordPressCWE-89WordPress GEO my WordPress plugin <= 4.5.5 - SQL Injection vulnerability
CVE-2026-108257.115.4MoxaNPort 6000-G2 SeriesCWE-1287Improper JSON Input Validation in WebSocket API Leads to Denial of Service
CVE-2025-691047.114.9jkdevstudioQreatixCWE-79WordPress Qreatix theme <= 1.9.4 - Cross Site Scripting (XSS) vulnerability
CVE-2025-142728.314.6Rockwell AutomationFactoryTalk Analytics PavilionXCWE-862Rockwell Automation FactoryTalk Analytics PavilionX
CVE-2026-123096.514.7MozillaFirefoxCWE-119Memory safety bug fixed in Firefox 152
CVE-2026-395749.314.6RealMag777InPost GalleryCWE-89WordPress InPost Gallery plugin <= 2.1.4.6 - SQL Injection vulnerability
CVE-2026-118904.314.6DevolutionsDevolutions ServerCWE-882Improper access control in PAM account discovery results in Devolutions Serve…

Results continue: ranks 401–546.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-16 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion.