AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .9779 99.9 YES
AFFECTED Product Versions Fixed WordPress 6.9.0 – —
TIMELINE Jul 17 Reserved by CNA Jul 21 Added to CISA KEV, due Jul 24 Jul 21 Published (CNA: WPScan)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
1477 CVEs published, led by Oracle Corporation (1097).
1477 CVEs published July 21, 2026: 310 critical, 658 high, 417 medium, 92 low; 4 in the KEV catalog at press time; 26 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 1077 on continuation pages.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 6894 | 19297 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
819 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 479 | 1959 | 178 | 1079 | 596 | 1 | 11 | 2 | 0.1 | 7.8 | .0016 | +379 ▲ |
| microsoft | 646 | 1403 | 96 | 975 | 318 | 14 | 286 | 23 | 1.6 | 7.8 | .0047 | +426 ▲ |
| 115 | 1380 | 156 | 629 | 556 | 39 | 77 | 6 | 0.4 | 7.8 | .0024 | -569 ▼ | |
| red hat | 93 | 315 | 16 | 124 | 154 | 21 | 2 | 0 | 0.0 | 6.5 | .0032 | +18 ▲ |
| apple | 0 | 104 | 2 | 28 | 72 | 2 | 88 | 7 | 6.7 | 6.5 | .0032 | -14 ▼ |
| canonical | 7 | 27 | 3 | 8 | 11 | 5 | 0 | 0 | 0.0 | 5.6 | .0014 | +6 ▲ |
| suse | 8 | 21 | 4 | 12 | 4 | 1 | 0 | 0 | 0.0 | 8.5 | .0039 | +4 ▲ |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 15 | 37 | 8 | 18 | 11 | 0 | 56 | 11 | 29.7 | 7.5 | .0057 | +6 ▲ |
| ubiquiti | 25 | 36 | 14 | 21 | 1 | 0 | 3 | 3 | 8.3 | 8.8 | .0049 | +20 ▲ |
| palo alto networks | 14 | 25 | 1 | 3 | 14 | 7 | 13 | 2 | 8.0 | 4.7 | .0028 | +5 ▲ |
| netgear | 6 | 23 | 0 | 0 | 22 | 1 | 0 | 0 | 0.0 | 4.6 | .0024 | -11 ▼ |
| fortinet | 13 | 22 | 6 | 6 | 10 | 0 | 28 | 5 | 22.7 | 7.3 | .0039 | +11 ▲ |
| f5 | 8 | 16 | 5 | 8 | 3 | 0 | 4 | 1 | 6.3 | 8.6 | .0057 | +2 ▲ |
| vmware | 8 | 12 | 1 | 8 | 2 | 1 | 7 | 1 | 8.3 | 8.2 | .0039 | +5 ▲ |
| ivanti | 2 | 11 | 4 | 5 | 2 | 0 | 25 | 5 | 45.5 | 8.8 | .3445 | -2 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 92 | 247 | 55 | 95 | 85 | 11 | 33 | 1 | 0.4 | 7.5 | .0059 | +6 ▲ |
| mozilla | 70 | 126 | 51 | 41 | 34 | 0 | 9 | 0 | 0.0 | 8.1 | .0031 | +21 ▲ |
| drupal | 46 | 51 | 6 | 5 | 35 | 5 | 4 | 1 | 2.0 | 5.9 | .0026 | +46 ▲ |
| gitlab | 7 | 38 | 0 | 5 | 27 | 6 | 4 | 2 | 5.3 | 4.7 | .0032 | -4 ▼ |
| github | 5 | 11 | 1 | 2 | 8 | 0 | 0 | 0 | 0.0 | 6.0 | .0042 | +5 ▲ |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.2 | .0016 | -4 ▼ |
| wordpress | 2 | 2 | 1 | 0 | 1 | 0 | 2 | 2 | 100.0 | 7.9 | .8879 | +2 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 1098 | 1368 | 339 | 646 | 322 | 61 | 27 | 3 | 0.2 | 8.1 | .0036 | +856 ▲ |
| adobe | 95 | 239 | 26 | 104 | 105 | 4 | 19 | 3 | 1.3 | 7.7 | .0026 | -34 ▼ |
| ibm | 36 | 160 | 52 | 54 | 54 | 0 | 6 | 0 | 0.0 | 7.5 | .0036 | +25 ▲ |
| solarwinds | 15 | 22 | 16 | 3 | 3 | 0 | 10 | 4 | 18.2 | 9.1 | .0058 | +12 ▲ |
| progress | 11 | 20 | 3 | 15 | 2 | 0 | 6 | 0 | 0.0 | 7.5 | .0037 | +6 ▲ |
| zohocorp | 2 | 5 | 1 | 2 | 2 | 0 | 0 | 0 | 0.0 | 7.1 | .0121 | +2 ▲ |
| veeam | 0 | 4 | 2 | 2 | 0 | 0 | 1 | 0 | 0.0 | 9.0 | .0052 | -1 ▼ |
| atlassian | 3 | 3 | 0 | 3 | 0 | 0 | 13 | 0 | 0.0 | 8.0 | .0026 | +3 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| rockwell automation | 17 | 24 | 4 | 18 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0029 | +10 ▲ |
| synology | 0 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -5 ▼ |
| d-link | 8 | 20 | 0 | 5 | 9 | 6 | 3 | 0 | 0.0 | 5.5 | .0105 | -1 ▼ |
| siemens | 7 | 16 | 1 | 8 | 7 | 0 | 0 | 0 | 0.0 | 7.6 | .0024 | 0 |
| abb | 1 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -4 ▼ |
| schneider electric | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0042 | -1 ▼ |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | -5 ▼ |
| dahua | 0 | 3 | 0 | 1 | 1 | 1 | 0 | 0 | 0.0 | 6.9 | .0036 | -3 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 49 | 120 | 0 | 0 | 62 | 58 | 0 | 0 | 0.0 | 5.5 | .0034 | +12 ▲ |
| openclaw | 44 | 111 | 0 | 58 | 39 | 14 | 0 | 0 | 0.0 | 7.0 | .0026 | -17 ▼ |
| dell | 37 | 93 | 5 | 42 | 43 | 3 | 2 | 1 | 1.1 | 7.0 | .0021 | +10 ▲ |
| capgo | 22 | 83 | 2 | 42 | 38 | 1 | 0 | 0 | 0.0 | 7.1 | .0037 | -2 ▼ |
| nvidia | 41 | 80 | 12 | 52 | 16 | 0 | 0 | 0 | 0.0 | 7.8 | .0037 | +35 ▲ |
| imagemagick | 32 | 73 | 1 | 5 | 55 | 12 | 0 | 0 | 0.0 | 5.3 | .0019 | +2 ▲ |
| spring | 0 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | -71 ▼ |
| itsourcecode | 17 | 70 | 0 | 0 | 19 | 51 | 0 | 0 | 0.0 | 2.1 | .0033 | -5 ▼ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-63030 | .9779 | 99.9 | 9.8 |
| CVE-2026-20230 | .8820 | 99.8 | 8.6 |
| CVE-2026-34910 | .8747 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-50522 | .8461 | 99.7 | 9.8 |
| CVE-2026-15409 | .8366 | 99.7 | 10.0 |
| CVE-2026-60137 | .7979 | 99.6 | 5.9 |
| CVE-2026-6875 | .7758 | 99.5 | 9.5 |
| CVE-2026-25089 | .7611 | 99.5 | 9.8 |
| CVE-2026-45659 | .7608 | 99.5 | 8.8 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-34910 | 10.0 | .8747 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-15409 | 10.0 | .8366 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-48282 | 10.0 | .4239 | KEV |
| CVE-2026-56290 | 10.0 | .3038 | KEV |
| CVE-2026-48939 | 10.0 | .1973 | KEV |
| CVE-2026-48908 | 10.0 | .1482 | KEV |
| CVE-2026-56291 | 10.0 | .1459 | KEV |
| CVE-2026-59726 | 10.0 | .0688 |
| Vendor | CVEs |
|---|---|
| oracle | 1098 |
| linux | 892 |
| microsoft | 647 |
| 521 | |
| red hat | 146 |
| apache | 127 |
| adobe | 108 |
| ibm | 100 |
| mozilla | 71 |
| sourcecodester | 61 |
| Vendor | KEV |
|---|---|
| microsoft | 23 |
| cisco | 11 |
| apple | 7 |
| 6 | |
| fortinet | 5 |
| ivanti | 5 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| oracle | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 66 |
| PyPI | 5 |
| npm | 5 |
| NuGet | 3 |
| Packagist | 1 |
| crates.io | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2021-27137 | DD-WRT | 0 |
| CVE-2026-0770 | Langflow | 0 |
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-25089 | Fortinet | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE-2026-34909 | Ubiquiti Inc | 0 |
| CVE-2026-34910 | Ubiquiti Inc | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1707 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1707 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1707 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1707 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1707 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1707 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1707 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1707 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1707 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1707 |
EXPLOIT PUBLISHED — netty: 5 CVEs (CVE-2026-55831, CVE-2026-55833, CVE-2026-56816, CVE-2026-56819, CVE-2026-56820). Public exploit references added.
EXPLOIT PUBLISHED — strukturag libheif: 5 CVEs (CVE-2026-47178, CVE-2026-47247, CVE-2026-47251, CVE-2026-47254, CVE-2026-47709). Public exploit references added.
EXPLOIT PUBLISHED — fogproject: 4 CVEs (CVE-2026-47685, CVE-2026-47687, CVE-2026-47688, CVE-2026-47689). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2023-4692 (grub). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2023-4693 (Red Hat Enterprise Linux 8). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-11816 (keras-team/keras). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-13142 (Unknown Social Login, Passkeys, Magic Link & Email OTP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16324 (Metasoft 美特软件 MetaCRM). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16372 (Mozilla Firefox). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-24779 (vllm-project vllm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-25048 (mlc-ai xgrammar). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-25960 (vllm-project vllm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-33236 (nltk). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47143 (capstone-engine capstone). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47671 (nhost cli). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-49978 (cure53 DOMPurify). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54293 (nltk). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58049 (FFmpeg). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-59197 (python-pillow Pillow). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-59204 (python-pillow Pillow). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-59732 (rclone). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63730 (hyperdxio hyperdx). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63731 (hyperdxio hyperdx). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63767 (kvcache-ai ktransformers). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63768 (calcom cal.diy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63769 (huginn). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63770 (glanceapp glance). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63771 (vrana adminer). Public exploit reference added.
RESCORED — Microsoft Windows 10 Version 1607: 4 CVEs (CVE-2026-50377, CVE-2026-50485, CVE-2026-50489, CVE-2026-50500). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2023-3640 (Red Hat Enterprise Linux 6). CVSS 7 → 7.8 (NVD).
RESCORED — CVE-2023-4692 (grub). CVSS 7.5 → 7.8 (NVD).
RESCORED — CVE-2023-4693 (Red Hat Enterprise Linux 8). CVSS 5.3 → 4.6 (NVD).
RESCORED — CVE-2026-16014 (code-projects Hospital Bed Management System). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-16075 (AstrBotDevs AstrBot). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16084 (Sipeed PicoClaw). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-16119 (nextlevelbuilder GoClaw). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16125 (zevorn rt-claw). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-16131 (itsourcecode Hospital Management System). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16155 (SourceCodester Class and Exam Timetabling System). CVSS 5.1 → 2 (NVD).
RESCORED — CVE-2026-16156 (SourceCodester Class and Exam Timetabling System). CVSS 5.1 → 2 (NVD).
RESCORED — CVE-2026-16198 (Sipeed PicoClaw). CVSS 6.3 → 2.9 (NVD).
RESCORED — CVE-2026-16204 (zevorn rt-claw). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16210 (newpanjing simpleui). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-16216 (geex-arts django-jet). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16223 (1Panel-dev CordysCRM). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16229 (itsourcecode Courier Management System). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16327 (D-Link DNS-320). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-22807 (vllm-project vllm). CVSS 8.8 → 9.8 (NVD).
RESCORED — CVE-2026-25960 (vllm-project vllm). CVSS 7.1 → 9.8 (NVD).
RESCORED — CVE-2026-56169 (Microsoft Windows Admin Center). CVSS 8.1 → 8.8 (NVD).
RESCORED — CVE-2026-7754 (IBM Langflow OSS). CVSS 7.7 → 6.5 (NVD).
ENRICHED — CVE-2026-46817 (Oracle E-Business Suite). Received CVSS 9.8 and CPE data from NVD.
How to read these box scores · glossary
1477 CVEs published. 25 box scores and 375 table rows below; the remaining 1077 continue on page 2 · page 3 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .9779 99.9 YES
AFFECTED Product Versions Fixed WordPress 6.9.0 – —
TIMELINE Jul 17 Reserved by CNA Jul 21 Added to CISA KEV, due Jul 24 Jul 21 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H N N 5.9 .7979 99.6 YES
AFFECTED Product Versions Fixed WordPress 6.8.0 – —
TIMELINE Jul 17 Reserved by CNA Jul 21 Added to CISA KEV, due Aug 4 Jul 21 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .6342 99.1 YES
AFFECTED Product Versions Fixed Langflow 1.4.2 – —
TIMELINE Jan 8 Reserved by CNA Jul 21 Added to CISA KEV, due Jul 24 Jul 21 Published (CNA: zdi)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H H H 8.1 .0399 89.7 YES
AFFECTED Product Versions Fixed DD-WRT unspecified —
TIMELINE Feb 10 Reserved by CNA Jul 21 Added to CISA KEV, due Jul 24 Jul 21 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0660 93.3 —
AFFECTED Product Versions Fixed MaxiCharger Single unspecified —
TIMELINE May 19 Reserved by CNA Jul 21 Published (CNA: CyberDanube)
AV AC PR UI S C I A CVSS EPSS %ile KEV A H N N U H H H 7.5 .0291 85.9 —
AFFECTED Product Versions Fixed Red Hat Enterprise Linux 8 unspecified 0:049-244.git20260529.el8_10 Red Hat Hardened Images unspecified 109-7.hum1 Red Hat Enterprise Linux 10 unspecified — Red Hat Enterprise Linux 6 unspecified — Red Hat Enterprise Linux 7 unspecified — Red Hat Enterprise Linux 9 unspecified — Red Hat OpenShift Container Platform 4 unspecified —
TIMELINE Jul 21 Reserved by CNA Jul 21 Published (CNA: redhat)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.5 .0229 81.9 —
AFFECTED Product Versions Fixed MaxiCharger Single unspecified —
TIMELINE May 19 Reserved by CNA Jul 21 Published (CNA: CyberDanube)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 9.4 .0226 81.6 —
AFFECTED Product Versions Fixed Security Center unspecified Patch SC202607.1
TIMELINE Jul 20 Reserved by CNA Jul 21 Published (CNA: tenable)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0223 81.4 —
AFFECTED Product Versions Fixed Security Center unspecified Patch SC202607.1
TIMELINE Jul 20 Reserved by CNA Jul 21 Published (CNA: tenable)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0213 80.6 —
AFFECTED Product Versions Fixed Serv-U 15.5.4 HF1 and below – —
TIMELINE Feb 26 Reserved by CNA Jul 21 Published (CNA: SolarWinds)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0165 74.7 —
AFFECTED Product Versions Fixed EdgeConnect SD-WAN Gateway (ECOS) 9.4.0.0 – —
TIMELINE May 7 Reserved by CNA Jul 21 Published (CNA: hpe)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0157 73.5 —
AFFECTED Product Versions Fixed DNS-320 1.0.2 – —
TIMELINE Jul 20 Reserved by CNA Jul 21 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0157 73.5 —
AFFECTED Product Versions Fixed DNS-320 1.0.2 – —
TIMELINE Jul 20 Reserved by CNA Jul 21 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0157 73.5 —
AFFECTED Product Versions Fixed DNS-320 1.0.2 – —
TIMELINE Jul 21 Reserved by CNA Jul 21 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0152 72.6 —
AFFECTED Product Versions Fixed AX7501-B1 firmware <= 5.17(ABPC.7.2)C0 – —
TIMELINE Apr 24 Reserved by CNA Jul 21 Published (CNA: Zyxel)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N P L L L 1.3 .0149 72.0 —
AFFECTED Product Versions Fixed MiniCode-Python 0.1.0 – 0.1.0-rc1
TIMELINE Jul 21 Reserved by CNA Jul 21 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0145 71.3 —
AFFECTED Product Versions Fixed DNS-320 1.0.2 – —
TIMELINE Jul 20 Reserved by CNA Jul 21 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0145 71.3 —
AFFECTED Product Versions Fixed DNS-320 1.0.2 – —
TIMELINE Jul 20 Reserved by CNA Jul 21 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U L H N 7.1 .0121 66.2 —
AFFECTED Product Versions Fixed ManageEngine ADSelfService Plus unspecified —
TIMELINE Feb 25 Reserved by CNA Jul 21 Published (CNA: Zohocorp)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0117 64.9 —
AFFECTED Product Versions Fixed PraisonAI < 4.6.40 – —
TIMELINE May 19 Reserved by CNA Jul 21 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0109 63.0 —
AFFECTED Product Versions Fixed MapSVG – Vector maps, Image maps, Google Maps unspecified —
TIMELINE Feb 2 Reserved by CNA Jul 21 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N L N L L L 1.9 .0108 62.6 —
AFFECTED Product Versions Fixed jsforce 3.10.0 – —
TIMELINE Jul 21 Reserved by CNA Jul 21 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0106 61.8 —
AFFECTED Product Versions Fixed DNS-120 20260205 – — DNR-202L 20260205 – — DNS-315L 20260205 – — DNS-320 20260205 – — DNS-320L 20260205 – — DNS-320LW 20260205 – — DNS-321 20260205 – — DNR-322L 20260205 – — DNS-323 20260205 – — DNS-325 20260205 – — + 10 more
TIMELINE Jul 21 Reserved by CNA Jul 21 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0091 57.2 —
AFFECTED Product Versions Fixed FUXA = 1.3.0 – —
TIMELINE May 4 Reserved by CNA Jul 21 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0089 56.6 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Mar 4 Reserved by CNA Jul 21 Published (CNA: mitre)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-47392 | 9.9 | 56.5 | MervinPraison | PraisonAI | CWE-184 | PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module l… |
| CVE-2026-47731 | 9.1 | 55.8 | NASA-AMMOS | AIT-Core | CWE-22 | NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file app… |
| CVE-2026-43945 | 8.9 | 55.1 | frangoteam | FUXA | CWE-94 | FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection |
| CVE-2026-65008 | 9.3 | 55.0 | getgrav | grav | CWE-94 | Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData |
| CVE-2026-65315 | 8.7 | 54.1 | Ollama | Ollama | CWE-789 | Ollama Remote Denial of Service via Attacker-Controlled Allocation in GGUF Me… |
| CVE-2026-64608 | 9.8 | 54.0 | Apache Software Foundation | Apache Fory | CWE-502 | Apache Fory: Heap type confusion and out-of-bounds read/write in C++ compatib… |
| CVE-2026-64878 | 9.4 | 53.7 | Tenable, Inc. | Security Center | CWE-78 | Command Injection |
| CVE-2026-64824 | 9.3 | 53.7 | home-assistant | Home Assistant Core | CWE-22 | Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore |
| CVE-2026-28304 | 9.1 | 53.4 | SolarWinds | Serv-U | CWE-284 | SolarWinds Serv-U Remote Code Execution Vulnerability |
| CVE-2026-28305 | 9.1 | 53.4 | SolarWinds | Serv-U | CWE-639 | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-28308 | 9.1 | 53.4 | SolarWinds | Serv-U | CWE-639 | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-47393 | 9.8 | 53.1 | MervinPraison | PraisonAI | CWE-306 | PraisonAI `deploy --type api` emits a Flask server with authentication disabl… |
| CVE-2026-64609 | 9.1 | 53.1 | Apache Software Foundation | Apache Fory | CWE-125 | Apache Fory, Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy… |
| CVE-2026-8984 | 10.0 | 52.7 | Autel | MaxiCharger Single | CWE-94 | Unauthenticated RCE |
| CVE-2026-44880 | 8.8 | 52.3 | Hewlett Packard Enterprise (HPE) | AOS-CX | CWE-120 | Low-Privilege Authenticated Buffer Overflow Vulnerabilities lead to Remote Co… |
| CVE-2026-15957 | 8.7 | 52.2 | AWS | aws-sdk-rust | CWE-770 | Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserialize… |
| CVE-2026-30631 | 9.8 | 51.3 | n/a | n/a | CWE-78 | An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309a… |
| CVE-2026-64606 | 9.8 | 51.2 | Apache Software Foundation | Apache Fory | CWE-502 | Apache Fory, Apache Fory: Class-registration bypass through an auto-admitted … |
| CVE-2026-50758 | 8.1 | 51.2 | n/a | n/a | CWE-79 | Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allo… |
| CVE-2026-28302 | 9.1 | 51.0 | SolarWinds | Serv-U | CWE-639 | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-60080 | 7.3 | 49.8 | Apache Software Foundation | Apache Fory | CWE-416 | Apache Fory: Rust MetaString heap use-after-free |
| CVE-2026-50759 | 7.5 | 49.4 | n/a | n/a | CWE-306 | An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privi… |
| CVE-2016-20096 | 9.3 | 49.3 | Kunshi Network Technology Co., Ltd. | Linknat VOS3000 | CWE-89 | Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp |
| CVE-2026-30632 | 7.5 | 48.8 | n/a | n/a | CWE-22 | Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted fol… |
| CVE-2026-3182 | 4.3 | 48.2 | Zohocorp | ManageEngine Endpoint Central | CWE-319 | Sensitive Data Exposure |
| CVE-2026-65317 | 9.2 | 48.0 | Weaviate | Verba | CWE-918 | Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Ori… |
| CVE-2026-47396 | 9.8 | 48.0 | MervinPraison | PraisonAI | CWE-284 | PraisonAI call server exposes unauthenticated agent listing, invocation, and … |
| CVE-2026-47410 | 9.8 | 47.8 | MervinPraison | praisonai-platform | CWE-321 | praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-… |
| CVE-2026-50757 | 7.8 | 47.3 | n/a | n/a | CWE-22 | Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allow… |
| CVE-2026-50755 | 9.8 | 47.0 | n/a | n/a | CWE-290 | An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to ob… |
| CVE-2026-28314 | 9.1 | 47.1 | SolarWinds | Serv-U | CWE-639 | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-63453 | 7.2 | 47.0 | Hewlett Packard Enterprise (HPE) | AOS-CX | CWE-120 | Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution i… |
| CVE-2026-16395 | 9.8 | 47.0 | Mozilla | Firefox | CWE-190 | Integer overflow in the Audio/Video component |
| CVE-2026-55851 | 8.7 | 46.6 | netty | netty | CWE-400 | Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder … |
| CVE-2026-56745 | 8.7 | 46.6 | netty | netty | CWE-400 | Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native M… |
| CVE-2026-44907 | 7.5 | 46.1 | Meta | react-server-dom-turbopack | — | A denial of service vulnerability could be triggered by sending specially cra… |
| CVE-2026-44878 | 7.2 | 46.0 | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateway (ECOS) | CWE-377 | Authenticated Path Traversal allows Unauthorized Access in Web Interface |
| CVE-2026-59144 | 9.8 | 46.0 | EGOR | Data::RingBuffer::Shared | CWE-121 | Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer o… |
| CVE-2026-65318 | 9.2 | 45.8 | Weaviate | Verba | CWE-918 | Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket… |
| CVE-2026-55082 | 8.7 | 45.1 | dhis2 | dhis2-core | CWE-89 | DHIS2 SQL injection in SQL View filter values |
| CVE-2026-65052 | 8.7 | 45.1 | Saturday Drive | Ninja Forms | CWE-472 | Ninja Forms Calculation and Payment Total Tampering via Fail-Open get_calc_va… |
| CVE-2026-64825 | 9.0 | 45.1 | home-assistant | Home Assistant Core | CWE-22 | Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload |
| CVE-2026-28312 | 9.1 | 44.9 | SolarWinds | Serv-U | CWE-285 | SolarWinds Serv-U Privilege Escalation Vulnerability |
| CVE-2026-28321 | 9.1 | 44.9 | SolarWinds | Serv-U | CWE-284 | SolarWinds Serv-U Broken Access Control Vulnerability |
| CVE-2026-47398 | 8.1 | 44.7 | MervinPraison | PraisonAI | CWE-94 | PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` i… |
| CVE-2026-43946 | 7.7 | 44.4 | frangoteam | FUXA | CWE-863 | FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue |
| CVE-2026-16389 | 9.8 | 44.3 | Mozilla | Firefox | CWE-190 | Incorrect boundary conditions, integer overflow in the Libraries component in… |
| CVE-2026-52469 | 9.8 | 44.0 | n/a | n/a | CWE-89 | SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to es… |
| CVE-2026-52470 | 9.8 | 44.0 | n/a | n/a | CWE-89 | SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to es… |
| CVE-2026-52472 | 9.8 | 44.0 | n/a | n/a | CWE-89 | SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to esca… |
| CVE-2026-59147 | 9.8 | 43.7 | EGOR | Data::DisjointSet::Shared | CWE-125 | Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds r… |
| CVE-2026-16367 | 10.0 | 43.6 | Mozilla | Firefox | CWE-119 | Sandbox escape due to invalid pointer in the Disability Access APIs component |
| CVE-2026-16388 | 9.8 | 43.6 | Mozilla | Firefox | CWE-693 | Sandbox escape in the DOM: Networking component |
| CVE-2026-16410 | 9.8 | 43.6 | Mozilla | Firefox | CWE-843 | JIT miscompilation in the JavaScript Engine: JIT component |
| CVE-2026-60264 | 9.8 | 43.5 | Oracle Corporation | Oracle Coherence | CWE-200 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-46600 | 7.5 | 43.5 | Go standard library | net | CWE-125 | Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage |
| CVE-2026-63454 | 7.2 | 43.4 | Hewlett Packard Enterprise (HPE) | AOS-CX | CWE-22 | Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in … |
| CVE-2026-60206 | 9.9 | 43.0 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-59139 | 9.1 | 42.9 | EGOR | Data::ReqRep::Shared | CWE-125 | Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds rea… |
| CVE-2026-59140 | 9.1 | 42.9 | EGOR | Data::SortedSet::Shared | CWE-125 | Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds … |
| CVE-2026-59141 | 9.1 | 42.9 | EGOR | Data::RadixTree::Shared | CWE-125 | Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds … |
| CVE-2026-59142 | 9.1 | 42.9 | EGOR | Data::HashMap::Shared | CWE-125 | Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds re… |
| CVE-2026-59145 | 9.1 | 42.9 | EGOR | Data::Intern::Shared | CWE-125 | Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds rea… |
| CVE-2026-65048 | 9.3 | 42.9 | Saturday Drive | Ninja Forms | CWE-79 | Ninja Forms Unauthenticated Stored Cross-Site Scripting via Repeatable Fields… |
| CVE-2026-16393 | 9.1 | 42.8 | Mozilla | Firefox | CWE-119 | Incorrect boundary conditions in the Graphics: WebGPU component |
| CVE-2026-59843 | 6.5 | 42.2 | Red Hat | Red Hat Enterprise Linux 10 | CWE-835 | Libssh: libssh: denial of service via zero advertised channel packet size |
| CVE-2026-59844 | 6.5 | 42.2 | Red Hat | Red Hat Enterprise Linux 10 | CWE-789 | Libssh: libssh: denial of service via oversized sftp read length |
| CVE-2026-47708 | 9.3 | 42.1 | SepineTam | stata-mcp | CWE-77 | MCP-for-Stata: Command injection via log_file_name parameter in Stata command… |
| CVE-2026-47409 | 8.1 | 42.1 | MervinPraison | praisonai-platform | CWE-269 | praisonai-platform: Any workspace member can remove any other member (includi… |
| CVE-2026-47412 | 8.1 | 42.1 | MervinPraison | praisonai-platform | CWE-269 | praisonai-platform: Any workspace member can delete the entire workspace via … |
| CVE-2026-15724 | 8.7 | 42.0 | Progress | ShareFile Storage Zones Controller | CWE-20 | Path traversal in Progress ShareFile Storage Zones Controller (SZC) |
| CVE-2026-47690 | 7.5 | 42.1 | meltano | hub | CWE-77 | MeltanoHub vulnerable to command injection in the `test_dispatcher` GitHub Ac… |
| CVE-2026-9499 | 6.3 | 42.0 | Qt | Qt | CWE-125 | Out-of-bounds read in QTextCodec::codecForName() in Qt |
| CVE-2026-56816 | 7.5 | 41.9 | netty | netty | CWE-400 | Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types |
| CVE-2026-16412 | 9.8 | 41.8 | Mozilla | Firefox | CWE-119 | Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 |
| CVE-2026-16353 | 9.8 | 41.6 | Mozilla | Firefox | CWE-416 | Invalid pointer in the DOM: Bindings (WebIDL) component |
| CVE-2026-16376 | 7.5 | 41.6 | Mozilla | Firefox | CWE-400 | Denial-of-service in the Graphics: WebGPU component |
| CVE-2026-16409 | 7.5 | 41.6 | Mozilla | Firefox | CWE-824 | Invalid pointer in the Security: PSM component |
| CVE-2026-52474 | 7.5 | 41.5 | n/a | n/a | CWE-200 | An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive inf… |
| CVE-2026-28315 | 6.2 | 41.5 | SolarWinds | Serv-U | CWE-79 | SolarWinds Serv-U Authenticated Stored Cross-site Scripting (XSS) Vulnerability |
| CVE-2026-8987 | 9.4 | 41.3 | Autel | MaxiCharger Single | CWE-122 | Authenticated Heap Overflow |
| CVE-2026-65316 | 7.1 | 41.1 | xuxueli | xxl-job | CWE-639 | xxl-job Cross-Job-Group Log Disclosure via Missing Authorization Check in /jo… |
| CVE-2026-47056 | 10.0 | 41.0 | Oracle Corporation | Oracle Data Integrator | CWE-306 | Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middlewa… |
| CVE-2026-60217 | 10.0 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60358 | 10.0 | 41.0 | Oracle Corporation | Oracle Access Manager | CWE-284 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-60360 | 10.0 | 41.0 | Oracle Corporation | Oracle Unified Directory | CWE-306 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60379 | 10.0 | 41.0 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60389 | 10.0 | 41.0 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60644 | 10.0 | 41.0 | Oracle Corporation | Oracle WebCenter Content | CWE-306 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-35290 | 9.8 | 41.0 | Oracle Corporation | Oracle Application Testing Suite | CWE-284 | Vulnerability in Oracle Application Testing Suite. The supported version that… |
| CVE-2026-46876 | 9.8 | 41.0 | Oracle Corporation | Oracle Application Testing Suite | CWE-284 | Vulnerability in Oracle Application Testing Suite. The supported version that… |
| CVE-2026-46924 | 9.8 | 41.0 | Oracle Corporation | Oracle Application Testing Suite | CWE-284 | Vulnerability in Oracle Application Testing Suite. The supported version that… |
| CVE-2026-46982 | 9.8 | 41.0 | Oracle Corporation | Oracle Retail Integration Bus | CWE-284 | Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail A… |
| CVE-2026-46983 | 9.8 | 41.0 | Oracle Corporation | Oracle Retail Integration Bus | CWE-284 | Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail A… |
| CVE-2026-47036 | 9.8 | 41.0 | Oracle Corporation | Siebel CRM Development | CWE-306 | Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (com… |
| CVE-2026-60173 | 9.8 | 41.0 | Oracle Corporation | Oracle BI Publisher | CWE-284 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-60197 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60198 | 9.8 | 41.0 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60199 | 9.8 | 41.0 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60200 | 9.8 | 41.0 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60202 | 9.8 | 41.0 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60204 | 9.8 | 41.0 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60205 | 9.8 | 41.0 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60209 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60210 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60212 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60215 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60216 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60219 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60221 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60224 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60225 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60226 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60227 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60228 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60229 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60230 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60232 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60234 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60236 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60240 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60241 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60242 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60244 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60246 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60247 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60250 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60251 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60253 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60254 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60256 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60257 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60258 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60259 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60262 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60269 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60272 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60274 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60275 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60276 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60278 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60279 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60280 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60285 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60286 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60287 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60288 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60289 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60290 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60291 | 9.8 | 41.0 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60292 | 9.8 | 41.0 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60294 | 9.8 | 41.0 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60296 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60297 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60298 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60299 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60300 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60302 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60306 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60308 | 9.8 | 41.0 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60328 | 9.8 | 41.0 | Oracle Corporation | Oracle Access Manager | CWE-287 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-60329 | 9.8 | 41.0 | Oracle Corporation | Oracle Identity Manager | CWE-306 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-60355 | 9.8 | 41.0 | Oracle Corporation | Oracle Access Manager | CWE-306 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-60362 | 9.8 | 41.0 | Oracle Corporation | Oracle Unified Directory | CWE-306 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60363 | 9.8 | 41.0 | Oracle Corporation | Oracle HTTP Server | CWE-284 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (… |
| CVE-2026-60364 | 9.8 | 41.0 | Oracle Corporation | Oracle HTTP Server | CWE-284 | Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle F… |
| CVE-2026-60374 | 9.8 | 41.0 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60375 | 9.8 | 41.0 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60376 | 9.8 | 41.0 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60378 | 9.8 | 41.0 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60380 | 9.8 | 41.0 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60384 | 9.8 | 41.0 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60385 | 9.8 | 41.0 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60386 | 9.8 | 41.0 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60387 | 9.8 | 41.0 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60388 | 9.8 | 41.0 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60435 | 9.8 | 41.0 | Oracle Corporation | Oracle WebCenter Content | CWE-306 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60441 | 9.8 | 41.0 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60442 | 9.8 | 41.0 | Oracle Corporation | Service Delivery Platform | CWE-306 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60446 | 9.8 | 41.0 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-306 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60460 | 9.8 | 41.0 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-306 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60463 | 9.8 | 41.0 | Oracle Corporation | WebCenter Content: Imaging | CWE-306 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd… |
| CVE-2026-60532 | 9.8 | 41.0 | Oracle Corporation | Oracle Identity Manager Connector | CWE-269 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-60535 | 9.8 | 41.0 | Oracle Corporation | Oracle Identity Manager Connector | CWE-306 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-60538 | 9.8 | 41.0 | Oracle Corporation | Oracle SOA Suite | CWE-306 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co… |
| CVE-2026-60541 | 9.8 | 41.0 | Oracle Corporation | Oracle SOA Suite | CWE-284 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co… |
| CVE-2026-60555 | 9.8 | 41.0 | Oracle Corporation | Oracle WebCenter Sites | CWE-200 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-60566 | 9.8 | 41.0 | Oracle Corporation | Oracle WebCenter Portal | CWE-269 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-60999 | 9.8 | 41.0 | Oracle Corporation | Oracle Data Integrator | CWE-284 | Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middlewa… |
| CVE-2026-61065 | 9.8 | 41.0 | Oracle Corporation | Oracle Access Manager | CWE-287 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-61100 | 9.8 | 41.0 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-306 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-61129 | 9.8 | 41.0 | Oracle Corporation | Oracle Commerce Platform | CWE-287 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com… |
| CVE-2026-61131 | 9.8 | 41.0 | Oracle Corporation | Oracle Commerce Platform | CWE-284 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com… |
| CVE-2026-61145 | 9.8 | 41.0 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-61154 | 9.8 | 41.0 | Oracle Corporation | Oracle Commerce Guided Search Platform Services | CWE-269 | Vulnerability in the Oracle Commerce Guided Search Platform Services product … |
| CVE-2026-61161 | 9.8 | 41.0 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-61167 | 9.8 | 41.0 | Oracle Corporation | Oracle Agile PLM | CWE-284 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-61178 | 9.8 | 41.0 | Oracle Corporation | Oracle Agile Product Lifecycle Management for Process | CWE-287 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process pr… |
| CVE-2026-61183 | 9.8 | 41.0 | Oracle Corporation | Oracle Agile Product Lifecycle Management for Process | CWE-287 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process pr… |
| CVE-2026-61196 | 9.8 | 41.0 | Oracle Corporation | Oracle Identity Manager | CWE-306 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-61233 | 9.8 | 41.0 | Oracle Corporation | PeopleSoft Enterprise FIN Common Objects Brazil | CWE-200 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product … |
| CVE-2026-61245 | 9.8 | 41.0 | Oracle Corporation | PeopleSoft Enterprise FIN Manufacturing Brazil | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product o… |
| CVE-2026-50756 | 7.5 | 40.9 | n/a | n/a | CWE-1390 | An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to ob… |
| CVE-2026-52476 | 7.5 | 40.9 | n/a | n/a | CWE-89 | SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to o… |
| CVE-2026-47399 | 8.8 | 40.9 | MervinPraison | praisonai-platform | CWE-284 | PraisonAI Platform workspace-scoped routes allow cross-workspace object acces… |
| CVE-2026-47405 | 8.8 | 40.9 | MervinPraison | praisonai-platform | CWE-284 | PraisonAI Platform missing role checks let any workspace member become owner … |
| CVE-2026-65319 | 8.7 | 40.9 | Feedbin | Feedbin | CWE-306 | Feedbin Unauthenticated Entry Content Disclosure via GET /api/v2/entries/:id/… |
| CVE-2026-11767 | 8.8 | 40.8 | Unknown | Free Theme Builder for Elementor | CWE-79 | CRT Addons for Elementor < 1.6.7 - Unauthenticated Stored XSS via Contact Form |
| CVE-2026-15927 | 6.8 | 40.7 | Red Hat | Red Hat Quay 3.1 | CWE-918 | Quay: mirror-registry: ssrf: repo-level mirror accepts external_reference wit… |
| CVE-2026-28306 | 9.1 | 40.2 | SolarWinds | Serv-U | CWE-284 | SolarWinds Serv-U Privilege Escalation Vulnerability |
| CVE-2026-28307 | 9.1 | 40.2 | SolarWinds | Serv-U | CWE-284 | SolarWinds Serv-U Privilege Escalation Vulnerability |
| CVE-2026-28309 | 9.1 | 40.2 | SolarWinds | Serv-U | CWE-862 | SolarWinds Serv-U Broken Access Control Vulnerability |
| CVE-2026-28310 | 9.1 | 40.2 | SolarWinds | Serv-U | CWE-862 | SolarWinds Serv-U Privilege Escalation Vulnerability |
| CVE-2026-28313 | 9.1 | 40.2 | SolarWinds | Serv-U | CWE-639 | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-28317 | 9.1 | 40.2 | SolarWinds | Serv-U | CWE-639 | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-61130 | 9.1 | 40.2 | Oracle Corporation | Oracle Commerce Platform | CWE-284 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com… |
| CVE-2026-61155 | 9.1 | 40.2 | Oracle Corporation | Oracle Commerce Guided Search Platform Services | CWE-284 | Vulnerability in the Oracle Commerce Guided Search Platform Services product … |
| CVE-2026-16411 | 9.8 | 40.1 | Mozilla | Firefox | CWE-119 | Memory safety bugs fixed in Firefox 153 |
| CVE-2026-65051 | 6.9 | 40.0 | Saturday Drive | Ninja Forms | CWE-602 | Ninja Forms Server-Side Validation Bypass via Client-Controlled Field Metadat… |
| CVE-2026-47394 | 8.7 | 39.9 | MervinPraison | PraisonAI | CWE-22 | PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.… |
| CVE-2026-61235 | 9.1 | 39.6 | Oracle Corporation | PeopleSoft Enterprise HCM Global Payroll Switzerland | CWE-284 | Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland pro… |
| CVE-2026-62546 | 9.1 | 39.6 | Oracle Corporation | Oracle Applications Framework | CWE-284 | Vulnerability in the Oracle Applications Framework product of Oracle E-Busine… |
| CVE-2026-46954 | 7.2 | 39.6 | Oracle Corporation | Oracle Human Resources | CWE-284 | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suit… |
| CVE-2026-46988 | 7.2 | 39.6 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-47005 | 7.2 | 39.6 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-47006 | 7.2 | 39.6 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-60153 | 7.2 | 39.6 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60335 | 7.2 | 39.6 | Oracle Corporation | Oracle WebCenter Content | CWE-306 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60340 | 7.2 | 39.6 | Oracle Corporation | Oracle Project Costing | CWE-269 | Vulnerability in the Oracle Project Costing product of Oracle E-Business Suit… |
| CVE-2026-60345 | 7.2 | 39.6 | Oracle Corporation | Oracle JDeveloper | CWE-284 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (c… |
| CVE-2026-60396 | 7.2 | 39.6 | Oracle Corporation | Oracle GoldenGate | CWE-306 | Vulnerability in Oracle GoldenGate (component: Distribution Server executable… |
| CVE-2026-60418 | 7.2 | 39.6 | Oracle Corporation | Oracle Unified Directory | CWE-269 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60466 | 7.2 | 39.6 | Oracle Corporation | WebCenter Content: Imaging | CWE-284 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd… |
| CVE-2026-60502 | 7.2 | 39.6 | Oracle Corporation | WebCenter Content: Imaging | CWE-284 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd… |
| CVE-2026-60519 | 7.2 | 39.6 | Oracle Corporation | Oracle Unified Directory | CWE-284 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60546 | 7.2 | 39.6 | Oracle Corporation | Oracle SOA Suite | CWE-269 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co… |
| CVE-2026-60576 | 7.2 | 39.6 | Oracle Corporation | Oracle Enterprise Command Center Framework | CWE-269 | Vulnerability in the Oracle Enterprise Command Center Framework product of Or… |
| CVE-2026-60734 | 7.2 | 39.6 | Oracle Corporation | Oracle Trading Community | CWE-284 | Vulnerability in the Oracle Trading Community product of Oracle E-Business Su… |
| CVE-2026-60755 | 7.2 | 39.6 | Oracle Corporation | Oracle Assets | CWE-284 | Vulnerability in the Oracle Assets product of Oracle E-Business Suite (compon… |
| CVE-2026-60786 | 7.2 | 39.6 | Oracle Corporation | Oracle Receivables | CWE-284 | Vulnerability in the Oracle Receivables product of Oracle E-Business Suite (c… |
| CVE-2026-60787 | 7.2 | 39.6 | Oracle Corporation | Oracle Receivables | CWE-284 | Vulnerability in the Oracle Receivables product of Oracle E-Business Suite (c… |
| CVE-2026-60813 | 7.2 | 39.6 | Oracle Corporation | Oracle iStore | CWE-284 | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (compon… |
| CVE-2026-60828 | 7.2 | 39.6 | Oracle Corporation | Oracle Interaction Blending | CWE-284 | Vulnerability in the Oracle Interaction Blending product of Oracle E-Business… |
| CVE-2026-60836 | 7.2 | 39.6 | Oracle Corporation | Oracle HCM Common Architecture | CWE-269 | Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Busin… |
| CVE-2026-60845 | 7.2 | 39.6 | Oracle Corporation | Oracle Mobile Application Server | CWE-284 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Bus… |
| CVE-2026-60900 | 7.2 | 39.6 | Oracle Corporation | Oracle HCM Configuration Workbench | CWE-269 | Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-B… |
| CVE-2026-60910 | 7.2 | 39.6 | Oracle Corporation | Oracle Property Manager | CWE-284 | Vulnerability in the Oracle Property Manager product of Oracle E-Business Sui… |
| CVE-2026-60918 | 7.2 | 39.6 | Oracle Corporation | Oracle Shipping Execution | CWE-269 | Vulnerability in the Oracle Shipping Execution product of Oracle E-Business S… |
| CVE-2026-60925 | 7.2 | 39.6 | Oracle Corporation | Oracle Public Sector Payroll | CWE-269 | Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Busines… |
| CVE-2026-60926 | 7.2 | 39.6 | Oracle Corporation | Oracle Public Sector Payroll | CWE-284 | Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Busines… |
| CVE-2026-61006 | 7.2 | 39.6 | Oracle Corporation | Oracle Process Manufacturing Logistics | CWE-269 | Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle… |
| CVE-2026-61025 | 7.2 | 39.6 | Oracle Corporation | Oracle iRecruitment | CWE-284 | Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (… |
| CVE-2026-61027 | 7.2 | 39.6 | Oracle Corporation | Oracle Cost Management | CWE-284 | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suit… |
| CVE-2026-61035 | 7.2 | 39.6 | Oracle Corporation | Oracle Financials for the Americas | CWE-284 | Vulnerability in the Oracle Financials for the Americas product of Oracle E-B… |
| CVE-2026-61039 | 7.2 | 39.6 | Oracle Corporation | Oracle Advanced Supply Chain Planning | CWE-284 | Vulnerability in the Oracle Advanced Supply Chain Planning product of Oracle … |
| CVE-2026-61068 | 7.2 | 39.6 | Oracle Corporation | PeopleSoft Enterprise FIN Billing Argentina | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Billing Argentina product of O… |
| CVE-2026-61107 | 7.2 | 39.6 | Oracle Corporation | Oracle Applications DBA | CWE-269 | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Sui… |
| CVE-2026-61115 | 7.2 | 39.6 | Oracle Corporation | Oracle Order Management | CWE-284 | Vulnerability in the Oracle Order Management product of Oracle E-Business Sui… |
| CVE-2026-61285 | 7.2 | 39.6 | Oracle Corporation | Oracle Process Manufacturing Systems | CWE-306 | Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E… |
| CVE-2026-61314 | 7.2 | 39.6 | Oracle Corporation | Oracle EDI Gateway | CWE-284 | Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (c… |
| CVE-2026-61336 | 7.2 | 39.6 | Oracle Corporation | Oracle Lease and Finance Management | CWE-269 | Vulnerability in the Oracle Lease and Finance Management product of Oracle E-… |
| CVE-2026-62466 | 7.2 | 39.6 | Oracle Corporation | Oracle Human Resources | CWE-284 | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suit… |
| CVE-2026-62548 | 7.2 | 39.6 | Oracle Corporation | Oracle HRMS (US) | CWE-269 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (com… |
| CVE-2026-61140 | 9.8 | 39.5 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-46681 | 7.2 | 39.3 | nevware21 | ts-utils | CWE-1321 | @nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for.… |
| CVE-2026-56852 | 7.5 | 38.9 | golang.org/x/text | golang.org/x/text/unicode/norm | CWE-835 | Infinite loop on invalid input in golang.org/x/text |
| CVE-2026-60551 | 9.8 | 38.8 | Oracle Corporation | Oracle WebCenter Sites | CWE-200 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-47040 | 9.1 | 38.8 | Oracle Corporation | Oracle Net Services | CWE-306 | Vulnerability in the Oracle Net Services component of Oracle Database Server.… |
| CVE-2026-64627 | 6.9 | 38.7 | parse-community | parse-server | CWE-209 | Parse Server 9.0.0 Schema Disclosure via GraphQL Variable Coercion |
| CVE-2026-63139 | 6.5 | 38.7 | Elastic | Kibana | CWE-400 | Uncontrolled Resource Consumption in Kibana Leading to Denial of Service |
| CVE-2026-63260 | 6.5 | 38.7 | Elastic | Kibana | CWE-400 | Uncontrolled Resource Consumption in Kibana Leading to Denial of Service |
| CVE-2026-63261 | 6.5 | 38.7 | Elastic | Kibana | CWE-400 | Uncontrolled Resource Consumption in Kibana Leading to Denial of Service |
| CVE-2026-47018 | 7.5 | 38.6 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-400 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-60252 | 7.5 | 38.6 | Oracle Corporation | Oracle Coherence | CWE-400 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60301 | 7.5 | 38.6 | Oracle Corporation | Oracle Coherence | CWE-400 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60382 | 7.5 | 38.6 | Oracle Corporation | Service Delivery Platform | CWE-400 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60425 | 7.5 | 38.6 | Oracle Corporation | Oracle Unified Directory | CWE-400 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60436 | 7.5 | 38.6 | Oracle Corporation | Oracle Unified Directory | CWE-400 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-16485 | 2.1 | 38.6 | SourceCodester | Class and Exam Timetabling System | CWE-79 | SourceCodester Class and Exam Timetabling System class.php cross site scripting |
| CVE-2026-16486 | 2.1 | 38.6 | SourceCodester | Class and Exam Timetabling System | CWE-79 | SourceCodester Class and Exam Timetabling System BSIS.php cross site scripting |
| CVE-2026-1617 | 9.8 | 38.4 | Turkmesh Communication Services Inc. | Turkhotspot 5651 Loglama | CWE-89 | SQLi in Turkmesh's Turkhotspot 5651 Loglama |
| CVE-2026-16360 | 9.8 | 38.4 | Mozilla | Firefox | CWE-119 | Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefo… |
| CVE-2026-47695 | 7.1 | 38.4 | cc-tweaked | CC-Tweaked | CWE-918 | CC-Tweaked has an SSRF Protection Bypass with NAT64 |
| CVE-2026-62516 | 8.8 | 38.3 | Oracle Corporation | Oracle Demantra Demand Management | CWE-89 | Vulnerability in the Oracle Demantra Demand Management product of Oracle Supp… |
| CVE-2026-60529 | 7.2 | 38.2 | Oracle Corporation | Oracle WebLogic Server | CWE-284 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-61094 | 7.2 | 38.2 | Oracle Corporation | MySQL Server | CWE-269 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-47057 | 7.5 | 38.1 | Oracle Corporation | Oracle Java SE | CWE-400 | Vulnerability in Oracle Java SE (component: Scripting). Supported versions th… |
| CVE-2026-60180 | 7.5 | 38.1 | Oracle Corporation | MySQL Connectors | CWE-400 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Con… |
| CVE-2026-60208 | 9.1 | 38.0 | Oracle Corporation | Oracle WebLogic Server | CWE-400 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-47397 | 7.1 | 37.8 | MervinPraison | PraisonAI | CWE-22 | PraisonAI has an Arbitrary File Write in Python API |
| CVE-2026-55084 | 8.8 | 37.6 | dhis2 | dhis2-core | CWE-89 | SQL Injection in SqlView Filter Parameter Leading to Arbitrary Database Read |
| CVE-2026-61203 | 9.4 | 37.5 | Oracle Corporation | PeopleSoft Enterprise FIN Expenses | CWE-269 | Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle Peo… |
| CVE-2026-60645 | 7.2 | 37.4 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-47008 | 4.9 | 37.2 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-60171 | 4.9 | 37.2 | Oracle Corporation | MySQL Cluster | CWE-400 | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Server… |
| CVE-2026-61128 | 4.9 | 37.2 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-61144 | 4.9 | 37.2 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-47247 | 7.5 | 37.0 | strukturag | libheif | CWE-200 | libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninit… |
| CVE-2026-60168 | 9.1 | 37.0 | Oracle Corporation | Oracle Hospitality Simphony | CWE-284 | Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and B… |
| CVE-2026-62415 | 9.1 | 36.9 | joomdonation.com | Membership Pro extension for Joomla | CWE-1188 | Joomla Extension - joomdonation.com - Insecure default configuration Membersh… |
| CVE-2026-16336 | 5.3 | 36.9 | trinodb | trino | CWE-601 | trinodb trino OAuth2/OIDC ExternalUriInfo.java redirect |
| CVE-2026-8082 | 7.5 | 36.9 | Unknown | bpost-shipping-platform | CWE-89 | Bpost Shipping Platform < 3.2.3 - Unauthenticated SQL Injection |
| CVE-2026-46403 | 6.3 | 36.9 | klever-io | klever-go | CWE-693 | Klever-Go KVM read-only execution can commit contract delete and upgrade side… |
| CVE-2026-61175 | 9.3 | 36.7 | Oracle Corporation | Oracle Product Lifecycle Analytics | CWE-200 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Sup… |
| CVE-2026-60544 | 8.2 | 36.7 | Oracle Corporation | Oracle SOA Suite | CWE-306 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co… |
| CVE-2026-56819 | 7.5 | 36.7 | netty | netty | CWE-400 | Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompress… |
| CVE-2026-47052 | 4.9 | 36.7 | Oracle Corporation | MySQL Server | CWE-400 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com… |
| CVE-2026-65049 | 8.4 | 36.6 | Saturday Drive | Ninja Forms | CWE-863 | Ninja Forms Cross-Site Network-Wide Data Deletion on WordPress Multisite via … |
| CVE-2026-61211 | 9.9 | 36.4 | Oracle Corporation | Oracle Database Server | CWE-284 | Vulnerability in the RDBMS component of Oracle Database Server. Supported ver… |
| CVE-2026-60293 | 8.6 | 36.2 | Oracle Corporation | Oracle WebLogic Server | CWE-200 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60431 | 8.6 | 36.2 | Oracle Corporation | Oracle HTTP Server | CWE-200 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (… |
| CVE-2026-60556 | 8.6 | 36.2 | Oracle Corporation | Oracle WebCenter Sites | CWE-200 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-60167 | 7.5 | 36.2 | Oracle Corporation | Oracle Hospitality Simphony | CWE-200 | Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and B… |
| CVE-2026-60554 | 7.5 | 36.2 | Oracle Corporation | Oracle WebCenter Sites | CWE-200 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-61116 | 7.5 | 36.2 | Oracle Corporation | Oracle Application Object Library | CWE-200 | Vulnerability in the Oracle Application Object Library product of Oracle E-Bu… |
| CVE-2026-61133 | 7.5 | 36.2 | Oracle Corporation | Oracle Commerce Platform | CWE-200 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com… |
| CVE-2026-61159 | 7.5 | 36.2 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-200 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-65050 | 7.1 | 36.2 | Saturday Drive | Ninja Forms | CWE-862 | Ninja Forms Missing Authorization in submissions-table Gutenberg Block Disclo… |
| CVE-2026-16363 | 9.8 | 36.1 | Mozilla | Firefox | CWE-682 | JIT miscompilation in the JavaScript: WebAssembly component |
| CVE-2026-16369 | 9.8 | 36.1 | Mozilla | Firefox | CWE-190 | Integer overflow in the JavaScript: WebAssembly component |
| CVE-2026-55081 | 7.3 | 36.1 | dhis2 | dhis2-core | CWE-79 | DHIS2 Reflected XSS in OpenAPI HTML scope parameter |
| CVE-2026-16408 | 9.8 | 36.1 | Mozilla | Firefox | CWE-190 | Integer overflow in the Audio/Video: Playback component |
| CVE-2026-60223 | 7.5 | 36.0 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-61176 | 6.7 | 36.0 | Oracle Corporation | Oracle Product Lifecycle Analytics | CWE-269 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Sup… |
| CVE-2026-62503 | 6.7 | 36.0 | Oracle Corporation | Oracle Time and Labor | CWE-284 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite… |
| CVE-2026-60333 | 9.9 | 35.8 | Oracle Corporation | Oracle Access Manager | CWE-287 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-60361 | 9.9 | 35.8 | Oracle Corporation | Oracle Unified Directory | CWE-306 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60381 | 9.9 | 35.8 | Oracle Corporation | Service Delivery Platform | CWE-284 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-60402 | 9.9 | 35.8 | Oracle Corporation | TimesTen In-Memory Database | CWE-284 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen I… |
| CVE-2026-60429 | 9.9 | 35.8 | Oracle Corporation | Oracle Unified Directory | CWE-284 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60445 | 9.9 | 35.8 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60447 | 9.9 | 35.8 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60456 | 9.9 | 35.8 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60457 | 9.9 | 35.8 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60458 | 9.9 | 35.8 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-306 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60459 | 9.9 | 35.8 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60461 | 9.9 | 35.8 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-306 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60524 | 9.9 | 35.8 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60531 | 9.9 | 35.8 | Oracle Corporation | Oracle Identity Manager Connector | CWE-306 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-60537 | 9.9 | 35.8 | Oracle Corporation | Oracle Managed File Transfer | CWE-306 | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Mi… |
| CVE-2026-60542 | 9.9 | 35.8 | Oracle Corporation | Oracle Business Process Management Suite | CWE-284 | Vulnerability in the Oracle Business Process Management Suite product of Orac… |
| CVE-2026-60547 | 9.9 | 35.8 | Oracle Corporation | Oracle Managed File Transfer | CWE-284 | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Mi… |
| CVE-2026-60552 | 9.9 | 35.8 | Oracle Corporation | Oracle WebCenter Sites | CWE-200 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-60561 | 9.9 | 35.8 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-60562 | 9.9 | 35.8 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-60568 | 9.9 | 35.8 | Oracle Corporation | Oracle WebCenter Portal | CWE-287 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-60627 | 9.9 | 35.8 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-306 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-60663 | 9.9 | 35.8 | Oracle Corporation | Oracle WebCenter Content | CWE-269 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60711 | 9.9 | 35.7 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-306 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-61041 | 9.9 | 35.8 | Oracle Corporation | Oracle Demantra Demand Management | CWE-284 | Vulnerability in the Oracle Demantra Demand Management product of Oracle Supp… |
| CVE-2026-61072 | 9.9 | 35.8 | Oracle Corporation | PeopleSoft Enterprise FIN Staffing Front Office Brazil | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office Brazil p… |
| CVE-2026-61076 | 9.9 | 35.8 | Oracle Corporation | PeopleSoft Enterprise HCM Talent Acquisition Manager | CWE-269 | Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager pro… |
| CVE-2026-61146 | 9.9 | 35.8 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-269 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-61209 | 9.9 | 35.8 | Oracle Corporation | PeopleSoft In-Memory Project Discovery | CWE-269 | Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle… |
| CVE-2026-61242 | 9.9 | 35.8 | Oracle Corporation | PeopleSoft Enterprise FIN Common Objects Argentina | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina produ… |
| CVE-2026-16380 | 9.1 | 35.8 | Mozilla | Firefox | CWE-693 | Mitigation bypass in the Networking component |
| CVE-2026-16394 | 9.1 | 35.8 | Mozilla | Firefox | CWE-693 | Mitigation bypass in the DOM: Security component |
| CVE-2026-46992 | 8.8 | 35.8 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-306 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-46995 | 8.8 | 35.8 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-269 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-47004 | 8.8 | 35.8 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-306 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-47031 | 8.8 | 35.8 | Oracle Corporation | Oracle Bills of Material | CWE-284 | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Su… |
| CVE-2026-47037 | 8.8 | 35.8 | Oracle Corporation | Oracle Access Manager | CWE-287 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-60157 | 8.8 | 35.8 | Oracle Corporation | Oracle GoldenGate | CWE-284 | Vulnerability in Oracle GoldenGate (component: Service Manager). Supported ve… |
| CVE-2026-60203 | 8.8 | 35.8 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60207 | 8.8 | 35.8 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60218 | 8.8 | 35.8 | Oracle Corporation | Oracle Coherence | CWE-306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60268 | 8.8 | 35.8 | Oracle Corporation | Oracle Coherence | CWE-284 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-60313 | 8.8 | 35.8 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60334 | 8.8 | 35.8 | Oracle Corporation | Oracle WebCenter Content | CWE-306 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60343 | 8.8 | 35.8 | Oracle Corporation | Oracle WebLogic Server | CWE-284 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60398 | 8.8 | 35.8 | Oracle Corporation | Oracle GoldenGate | CWE-306 | Vulnerability in Oracle GoldenGate (component: Oracle GoldenGate Microservice… |
| CVE-2026-60400 | 8.8 | 35.8 | Oracle Corporation | Oracle GoldenGate | CWE-284 | Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supp… |
| CVE-2026-60419 | 8.8 | 35.8 | Oracle Corporation | Oracle Unified Directory | CWE-269 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60423 | 8.8 | 35.8 | Oracle Corporation | Oracle Unified Directory | CWE-287 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60430 | 8.8 | 35.8 | Oracle Corporation | Oracle Unified Directory | CWE-284 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
Results continue: ranks 401–1477.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-21 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.