{
  "day": "2026-07-21",
  "boundary": "UTC calendar day",
  "published_count": 1477,
  "by_severity": {
    "CRITICAL": 310,
    "HIGH": 658,
    "MEDIUM": 417,
    "LOW": 92
  },
  "kev_count": 4,
  "exploit_reference_count": 26,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-63030",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.95605,
      "epss_percentile": 0.99865,
      "kev": true,
      "kev_due_at": "2026-07-24",
      "vendor": "WordPress",
      "product": "WordPress",
      "cwe": "CWE-436",
      "title": "WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63030"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-60137",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.731,
      "epss_percentile": 0.99411,
      "kev": true,
      "kev_due_at": "2026-08-04",
      "vendor": "WordPress",
      "product": "WordPress",
      "cwe": "CWE-89",
      "title": "WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60137"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-0770",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.56878,
      "epss_percentile": 0.98987,
      "kev": true,
      "kev_due_at": "2026-07-24",
      "vendor": "Langflow",
      "product": "Langflow",
      "cwe": "CWE-829",
      "title": "Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0770"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2021-27137",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.16488,
      "epss_percentile": 0.96729,
      "kev": true,
      "kev_due_at": "2026-07-24",
      "vendor": "DD-WRT",
      "product": "DD-WRT",
      "cwe": "CWE-121",
      "title": "DD-WRT DD-WRT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-27137"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-8985",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.06596,
      "epss_percentile": 0.93287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autel",
      "product": "MaxiCharger Single",
      "cwe": "CWE-78",
      "title": "Unauthenticated Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8985"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-64879",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0259,
      "epss_percentile": 0.84036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenable, Inc.",
      "product": "Security Center",
      "cwe": "CWE-78",
      "title": "Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64879"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-8986",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02286,
      "epss_percentile": 0.81804,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autel",
      "product": "MaxiCharger Single",
      "cwe": "CWE-78",
      "title": "Command Injection via Malicious OCPP Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8986"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-44879",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.01651,
      "epss_percentile": 0.7462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "EdgeConnect SD-WAN Gateway (ECOS)",
      "cwe": "CWE-77",
      "title": "Authenticated Command Injection allows arbitrary command execution in CLI Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44879"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-64881",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0144,
      "epss_percentile": 0.71063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenable, Inc.",
      "product": "Security Center",
      "cwe": "CWE-78",
      "title": "Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64881"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-28316",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0128,
      "epss_percentile": 0.67715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolarWinds",
      "product": "Serv-U",
      "cwe": "CWE-639",
      "title": "SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28316"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-16448",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01055,
      "epss_percentile": 0.61747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DNS-120",
      "cwe": "CWE-74",
      "title": "D-Link DNS-1550-04 remote_backup.cgi cgi_check_rsync_rw command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16448"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-16488",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.01003,
      "epss_percentile": 0.6021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QUSETIONS",
      "product": "MiniCode-Python",
      "cwe": "CWE-77",
      "title": "QUSETIONS MiniCode-Python Project File config.py subprocess.Popen os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16488"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-16445",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00989,
      "epss_percentile": 0.59725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 8",
      "cwe": "CWE-78",
      "title": "Dracut: dracut: root code execution via dhcp options command injection in networkmanager initrd module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16445"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-6952",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0095,
      "epss_percentile": 0.58478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zyxel",
      "product": "AX7501-B1 firmware",
      "cwe": "CWE-78",
      "title": "A post-authentication command injection vulnerability in the \"LogServer\" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6952"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-43945",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00862,
      "epss_percentile": 0.55719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frangoteam",
      "product": "FUXA",
      "cwe": "CWE-94",
      "title": "FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43945"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-65008",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00838,
      "epss_percentile": 0.54956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-94",
      "title": "Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65008"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-47731",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00804,
      "epss_percentile": 0.53912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NASA-AMMOS",
      "product": "AIT-Core",
      "cwe": "CWE-22",
      "title": "NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47731"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-47391",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0078,
      "epss_percentile": 0.53109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-95",
      "title": "PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47391"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-8984",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00766,
      "epss_percentile": 0.52644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autel",
      "product": "MaxiCharger Single",
      "cwe": "CWE-94",
      "title": "Unauthenticated RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8984"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-16330",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00728,
      "epss_percentile": 0.51355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DNS-320",
      "cwe": "CWE-284",
      "title": "D-Link DNS-320 uploadify.php unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16330"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-16331",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00728,
      "epss_percentile": 0.51354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DNS-320",
      "cwe": "CWE-284",
      "title": "D-Link DNS-320 save_ajax.php unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16331"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-16447",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00728,
      "epss_percentile": 0.51355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DNS-320",
      "cwe": "CWE-284",
      "title": "D-Link DNS-320 multi_uploadify.php unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16447"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-43947",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00666,
      "epss_percentile": 0.49027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frangoteam",
      "product": "FUXA",
      "cwe": "CWE-863",
      "title": "FUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43947"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-30632",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00659,
      "epss_percentile": 0.48771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30632"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-30633",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00659,
      "epss_percentile": 0.48771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30633"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-64606",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00634,
      "epss_percentile": 0.47651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Fory",
      "cwe": "CWE-502",
      "title": "Apache Fory, Apache Fory: Class-registration bypass through an auto-admitted SerializedLambda capturing interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64606"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-16489",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00624,
      "epss_percentile": 0.47224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "jsforce",
      "cwe": "CWE-77",
      "title": "jsforce SFDX Connection Registry sfdx.js _execCommand os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16489"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-55851",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00612,
      "epss_percentile": 0.46618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-400",
      "title": "Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55851"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-56745",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00612,
      "epss_percentile": 0.46619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-400",
      "title": "Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56745"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-47392",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00602,
      "epss_percentile": 0.46165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-184",
      "title": "PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47392"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-1771",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00586,
      "epss_percentile": 0.45435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oyatek",
      "product": "MapSVG – Vector maps, Image maps, Google Maps",
      "cwe": "CWE-20",
      "title": "MapSVG <= 8.14.0 - Authenticated (Administrator+) Arbitrary File Upload via '/mapsvg/v1/svgfile' Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1771"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-64824",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00576,
      "epss_percentile": 0.44981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "home-assistant",
      "product": "Home Assistant Core",
      "cwe": "CWE-22",
      "title": "Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64824"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-65315",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00572,
      "epss_percentile": 0.44783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ollama",
      "product": "Ollama",
      "cwe": "CWE-789",
      "title": "Ollama Remote Denial of Service via Attacker-Controlled Allocation in GGUF Metadata Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65315"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-28302",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00558,
      "epss_percentile": 0.44045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolarWinds",
      "product": "Serv-U",
      "cwe": "CWE-639",
      "title": "SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28302"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-63454",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00547,
      "epss_percentile": 0.43505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": "CWE-22",
      "title": "Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63454"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-28304",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00546,
      "epss_percentile": 0.43456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolarWinds",
      "product": "Serv-U",
      "cwe": "CWE-284",
      "title": "SolarWinds Serv-U Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28304"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-28305",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00546,
      "epss_percentile": 0.43457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolarWinds",
      "product": "Serv-U",
      "cwe": "CWE-639",
      "title": "SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28305"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-28308",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00546,
      "epss_percentile": 0.43457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolarWinds",
      "product": "Serv-U",
      "cwe": "CWE-639",
      "title": "SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28308"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-64878",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00542,
      "epss_percentile": 0.432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenable, Inc.",
      "product": "Security Center",
      "cwe": "CWE-78",
      "title": "Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64878"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-43946",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00542,
      "epss_percentile": 0.43253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frangoteam",
      "product": "FUXA",
      "cwe": "CWE-863",
      "title": "FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43946"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-16329",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0054,
      "epss_percentile": 0.43122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DNS-320",
      "cwe": "CWE-284",
      "title": "D-Link DNS-320 uploadify.php unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16329"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-16332",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0054,
      "epss_percentile": 0.43122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DNS-320",
      "cwe": "CWE-284",
      "title": "D-Link DNS-320 multi_uploadify.php unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16332"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-44880",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00527,
      "epss_percentile": 0.42412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": "CWE-120",
      "title": "Low-Privilege Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44880"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-59843",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00526,
      "epss_percentile": 0.4234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-835",
      "title": "Libssh: libssh: denial of service via zero advertised channel packet size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59843"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-59844",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00526,
      "epss_percentile": 0.42339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-789",
      "title": "Libssh: libssh: denial of service via oversized sftp read length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59844"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-60198",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00522,
      "epss_percentile": 0.42115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60198"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-60205",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00522,
      "epss_percentile": 0.42115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60205"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-60292",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00522,
      "epss_percentile": 0.42115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60292"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-56816",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00522,
      "epss_percentile": 0.42089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-400",
      "title": "Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56816"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-8987",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00513,
      "epss_percentile": 0.41542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autel",
      "product": "MaxiCharger Single",
      "cwe": "CWE-122",
      "title": "Authenticated Heap Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8987"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-60200",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00508,
      "epss_percentile": 0.41256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60200"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-60202",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00508,
      "epss_percentile": 0.41256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60202"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-60204",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00508,
      "epss_percentile": 0.41256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60204"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-60291",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00508,
      "epss_percentile": 0.41255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60291"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-60294",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00508,
      "epss_percentile": 0.41256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60294"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-50758",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00506,
      "epss_percentile": 0.4111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50758"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-30631",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00497,
      "epss_percentile": 0.4062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers to execute arbitrary code via crafted path to `computer_write_file`.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30631"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-60206",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SAML to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60206"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-60786",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00486,
      "epss_percentile": 0.3988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Receivables",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Receivables product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Receivables. Successful attacks of this vulnerability can result in takeover of Oracle Receivables. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60786"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-60900",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00486,
      "epss_percentile": 0.39924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HCM Configuration Workbench",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Rapid Implementation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HCM Configuration Workbench. Successful attacks of this vulnerability can result in takeover of Oracle HCM Configuration Workbench. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60900"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-60918",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00486,
      "epss_percentile": 0.3988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Shipping Execution",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Shipping Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.12-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Shipping Execution. Successful attacks of this vulnerability can result in takeover of Oracle Shipping Execution. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60918"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-60925",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00486,
      "epss_percentile": 0.39879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Public Sector Payroll",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.4-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60925"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-60926",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00486,
      "epss_percentile": 0.39879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Public Sector Payroll",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60926"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-61006",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00486,
      "epss_percentile": 0.39879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Logistics",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Logistics. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Logistics. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61006"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-61140",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61140"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-64825",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00482,
      "epss_percentile": 0.39679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "home-assistant",
      "product": "Home Assistant Core",
      "cwe": "CWE-22",
      "title": "Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64825"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-65317",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00481,
      "epss_percentile": 0.39597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Weaviate",
      "product": "Verba",
      "cwe": "CWE-918",
      "title": "Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65317"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-3183",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00481,
      "epss_percentile": 0.39593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine ADSelfService Plus",
      "cwe": "CWE-290",
      "title": "Multi Factor Auth Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3183"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-64608",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0048,
      "epss_percentile": 0.39567,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Fory",
      "cwe": "CWE-502",
      "title": "Apache Fory: Heap type confusion and out-of-bounds read/write in C++ compatible-mode field-skip paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64608"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-64609",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00476,
      "epss_percentile": 0.39291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Fory",
      "cwe": "CWE-125",
      "title": "Apache Fory, Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy java deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64609"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-60217",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00474,
      "epss_percentile": 0.39142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60217"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-60225",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00474,
      "epss_percentile": 0.39141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60225"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-60551",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00474,
      "epss_percentile": 0.3914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60551"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-47040",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00474,
      "epss_percentile": 0.39141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Net Services",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Net Services accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Net Services. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47040"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-60358",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Access Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60358"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-60360",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.3909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60360"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-60379",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60379"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-60389",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60389"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-35290",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Testing Suite",
      "cwe": "CWE-284",
      "title": "Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35290"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-46876",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Testing Suite",
      "cwe": "CWE-284",
      "title": "Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46876"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-46983",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Retail Integration Bus",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus. Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46983"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-60173",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle BI Publisher",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60173"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-60197",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60197"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-60209",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60209"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-60210",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.3909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60210"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-60212",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60212"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-60215",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60215"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-60216",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60216"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-60219",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60219"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-60224",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60224"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-60226",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60226"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-60227",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60227"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-60228",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60228"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-60229",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60229"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-60230",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60230"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-60234",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60234"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-60236",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60236"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-60240",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60240"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-60242",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60242"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-60247",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60247"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-60253",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60253"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-60254",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60254"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-60256",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60256"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-60257",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60257"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-60258",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60258"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-60259",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60259"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-60262",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60262"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-60272",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60272"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-60274",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60274"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-60275",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60275"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-60280",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60280"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-60285",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60285"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-60286",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60286"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-60287",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60287"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-60288",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60288"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-60289",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60289"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-60290",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60290"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-60296",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60296"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-60297",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60297"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-60298",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60298"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-60299",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60299"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-60300",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60300"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-60302",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60302"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-60355",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Access Manager",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60355"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-60362",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60362"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-60375",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60375"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-60376",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60376"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-60378",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60378"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-60384",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60384"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-60385",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60385"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-60386",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.3909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60386"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-60442",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60442"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-60532",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager Connector",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager Connector. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60532"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-60535",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager Connector",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager Connector. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60535"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-60538",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle SOA Suite",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Enterprise Scheduling System). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in takeover of Oracle SOA Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60538"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-60541",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle SOA Suite",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Enterprise Scheduling System). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in takeover of Oracle SOA Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60541"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-60555",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60555"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-61065",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Access Manager",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61065"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-61100",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61100"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-61129",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Platform",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: ATG Portals). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61129"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-61131",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61131"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-61145",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61145"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-61161",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61161"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-61167",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61167"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-61178",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Product Lifecycle Management for Process",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61178"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-61183",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Product Lifecycle Management for Process",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Reporting). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61183"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-61196",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61196"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-61233",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Common Objects Brazil",
      "cwe": "CWE-200",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Brazil. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61233"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-61155",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search Platform Services",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search Platform Services. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search Platform Services accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search Platform Services. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61155"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-60529",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60529"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-50757",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00464,
      "epss_percentile": 0.38507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50757"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-47057",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00463,
      "epss_percentile": 0.38445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE",
      "cwe": "CWE-400",
      "title": "Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47057"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-60180",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00463,
      "epss_percentile": 0.38445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Connectors",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60180"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-60208",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00462,
      "epss_percentile": 0.38347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60208"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-50759",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00462,
      "epss_percentile": 0.38392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-306",
      "title": "An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instance/{instance_id} endpoints with no authentication.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50759"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-60845",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00462,
      "epss_percentile": 0.38358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Mobile Application Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA General Bugs). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Mobile Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Mobile Application Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60845"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-59144",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00459,
      "epss_percentile": 0.38199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::RingBuffer::Shared",
      "cwe": "CWE-121",
      "title": "Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59144"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-61235",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00453,
      "epss_percentile": 0.37755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise HCM Global Payroll Switzerland",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland product of Oracle PeopleSoft (component: Global Payroll for Switzerland). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Global Payroll Switzerland. While the vulnerability is in PeopleSoft Enterprise HCM Global Payroll Switzerland, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise HCM Global Payroll Switzerland. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61235"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-46954",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Human Resources",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Data Removal Tool). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Human Resources. Successful attacks of this vulnerability can result in takeover of Oracle Human Resources. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46954"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-60153",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60153"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-60345",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle JDeveloper",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Shared Components). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60345"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-60466",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebCenter Content: Imaging",
      "cwe": "CWE-284",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60466"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-60502",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebCenter Content: Imaging",
      "cwe": "CWE-284",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via T3, IIOP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60502"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-60519",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60519"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-60546",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle SOA Suite",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in takeover of Oracle SOA Suite. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60546"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-60576",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Command Center Framework",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60576"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-60645",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60645"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-60828",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Interaction Blending",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Interaction Blending. Successful attacks of this vulnerability can result in takeover of Oracle Interaction Blending. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60828"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-61025",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iRecruitment",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iRecruitment. Successful attacks of this vulnerability can result in takeover of Oracle iRecruitment. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61025"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-61035",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Financials for the Americas",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Financials for the Americas product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Financials for the Americas. Successful attacks of this vulnerability can result in takeover of Oracle Financials for the Americas. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61035"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-61039",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37757,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Advanced Supply Chain Planning",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Advanced Supply Chain Planning product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Advanced Supply Chain Planning. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Supply Chain Planning. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61039"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-61068",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Billing Argentina",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Billing Argentina product of Oracle PeopleSoft (component: Billing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Billing Argentina. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Billing Argentina. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61068"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-61094",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-269",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61094"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-61107",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Applications DBA",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks of this vulnerability can result in takeover of Oracle Applications DBA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61107"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-61115",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Order Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can result in takeover of Oracle Order Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61115"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-61314",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle EDI Gateway",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: All Miscellaneous EDI Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle EDI Gateway. Successful attacks of this vulnerability can result in takeover of Oracle EDI Gateway. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61314"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-61336",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Lease and Finance Management",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Lease and Finance Management. Successful attacks of this vulnerability can result in takeover of Oracle Lease and Finance Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61336"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-62466",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Human Resources",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Data Removal Tool). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Human Resources. Successful attacks of this vulnerability can result in takeover of Oracle Human Resources. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62466"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-47018",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0045,
      "epss_percentile": 0.37595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47018"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-60252",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0045,
      "epss_percentile": 0.37594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60252"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-60301",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0045,
      "epss_percentile": 0.37594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60301"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-60382",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0045,
      "epss_percentile": 0.37594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Service Delivery Platform. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60382"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-47247",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00448,
      "epss_percentile": 0.37411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-200",
      "title": "libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel Plane Allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47247"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-56852",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.37274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/text",
      "product": "golang.org/x/text/unicode/norm",
      "cwe": "CWE-835",
      "title": "Infinite loop on invalid input in golang.org/x/text",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56852"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-28314",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00445,
      "epss_percentile": 0.37227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolarWinds",
      "product": "Serv-U",
      "cwe": "CWE-639",
      "title": "SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28314"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-61211",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00439,
      "epss_percentile": 0.36739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Database Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31 and 23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacker having Execute DBMS_CLOUD privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61211"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-16363",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00436,
      "epss_percentile": 0.36506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-682",
      "title": "JIT miscompilation in the JavaScript: WebAssembly component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16363"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-16369",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00436,
      "epss_percentile": 0.36506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-190",
      "title": "Integer overflow in the JavaScript: WebAssembly component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16369"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-16389",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00436,
      "epss_percentile": 0.36506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-190",
      "title": "Incorrect boundary conditions, integer overflow in the Libraries component in NSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16389"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-60678",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle General Ledger",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in takeover of Oracle General Ledger. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60678"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-60789",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Sales Offline",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Offline. Successful attacks of this vulnerability can result in takeover of Oracle Sales Offline. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60789"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-60863",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Advanced Pricing",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Pricing. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Pricing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60863"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-60872",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Order Management",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can result in takeover of Oracle Order Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60872"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-60890",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payroll",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60890"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-60897",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payroll",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60897"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-60901",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Project Intelligence",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Intelligence. Successful attacks of this vulnerability can result in takeover of Oracle Project Intelligence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60901"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-60920",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Customer Care",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Care. Successful attacks of this vulnerability can result in takeover of Oracle Customer Care. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60920"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-60924",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Public Sector Payroll",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60924"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-60932",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Labor Distribution",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution. Successful attacks of this vulnerability can result in takeover of Oracle Labor Distribution. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60932"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-60952",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Transportation Execution",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Execution. Successful attacks of this vulnerability can result in takeover of Oracle Transportation Execution. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60952"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-60989",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Advanced Collections",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Advanced Collections product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Collections. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Collections. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60989"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-61010",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Systems",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Systems. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Systems. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61010"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-60734",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00431,
      "epss_percentile": 0.36102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Trading Community",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Party Search UI). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Trading Community. Successful attacks of this vulnerability can result in takeover of Oracle Trading Community. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60734"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-47052",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00431,
      "epss_percentile": 0.36121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: InnoDB). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47052"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-60171",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00431,
      "epss_percentile": 0.36087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Cluster",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.47. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60171"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-61144",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00431,
      "epss_percentile": 0.36087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61144"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-8983",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00429,
      "epss_percentile": 0.35908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autel",
      "product": "MaxiCharger Single",
      "cwe": "CWE-798",
      "title": "Backdoor Authentication Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8983"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-47394",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00427,
      "epss_percentile": 0.35822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-22",
      "title": "PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47394"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-47667",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00426,
      "epss_percentile": 0.35729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GreycLab",
      "product": "CImg",
      "cwe": "CWE-401",
      "title": "CImg Library: Uncontrolled Memory Allocation and Memory Leak in `_load_analyze()` via Crafted NIfTI/Analyze Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47667"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-50755",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00425,
      "epss_percentile": 0.35672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-290",
      "title": "An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50755"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-61203",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00424,
      "epss_percentile": 0.35552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Expenses",
      "cwe": "CWE-269",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Expenses. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Expenses accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Expenses accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Expenses. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61203"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-61175",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00424,
      "epss_percentile": 0.35552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Product Lifecycle Analytics",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 9.3 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61175"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-65318",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00424,
      "epss_percentile": 0.35605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Weaviate",
      "product": "Verba",
      "cwe": "CWE-918",
      "title": "Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65318"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-60544",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00424,
      "epss_percentile": 0.35552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle SOA Suite",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle SOA Suite accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle SOA Suite. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60544"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-60080",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00424,
      "epss_percentile": 0.35584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Fory",
      "cwe": "CWE-416",
      "title": "Apache Fory: Rust MetaString heap use-after-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60080"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-59842",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00424,
      "epss_percentile": 0.35595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Libssh: libssh: information disclosure via short gssapi curve25519 public key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59842"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-60718",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00422,
      "epss_percentile": 0.35452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60718"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-60293",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00419,
      "epss_percentile": 0.35118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS - Web Services). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60293"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-60556",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00418,
      "epss_percentile": 0.35069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60556"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-60167",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00418,
      "epss_percentile": 0.35069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hospitality Simphony",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60167"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-60554",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00418,
      "epss_percentile": 0.35069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60554"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-61133",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00418,
      "epss_percentile": 0.35069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Platform",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61133"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-61159",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00418,
      "epss_percentile": 0.3507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61159"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-15957",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00417,
      "epss_percentile": 0.34995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "aws-sdk-rust",
      "cwe": "CWE-770",
      "title": "Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows unauthenticated remote denial of service via recursive shapes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15957"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-59147",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00416,
      "epss_percentile": 0.34868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::DisjointSet::Shared",
      "cwe": "CWE-125",
      "title": "Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59147"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-59145",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00416,
      "epss_percentile": 0.34868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::Intern::Shared",
      "cwe": "CWE-125",
      "title": "Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59145"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-60168",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00416,
      "epss_percentile": 0.34903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hospitality Simphony",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Simphony accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Simphony. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60168"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-60223",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60223"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-60207",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00414,
      "epss_percentile": 0.34696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60207"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-60343",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00414,
      "epss_percentile": 0.34695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60343"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-60689",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00414,
      "epss_percentile": 0.34706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60689"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-44878",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00412,
      "epss_percentile": 0.34569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "EdgeConnect SD-WAN Gateway (ECOS)",
      "cwe": "CWE-377",
      "title": "Authenticated Path Traversal allows Unauthorized Access in Web Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44878"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-16484",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00412,
      "epss_percentile": 0.34562,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System edit_subjecta.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16484"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-28321",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00409,
      "epss_percentile": 0.34266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolarWinds",
      "product": "Serv-U",
      "cwe": "CWE-284",
      "title": "SolarWinds Serv-U Broken Access Control Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28321"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-16350",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00405,
      "epss_percentile": 0.33919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Incorrect boundary conditions in the Audio/Video: cubeb component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16350"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-16353",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00405,
      "epss_percentile": 0.33919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Invalid pointer in the DOM: Bindings (WebIDL) component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16353"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-16355",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00405,
      "epss_percentile": 0.33919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-843",
      "title": "JIT miscompilation in the JavaScript Engine: JIT component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16355"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-16357",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00405,
      "epss_percentile": 0.33918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Incorrect boundary conditions in the Graphics component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16357"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-61176",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00405,
      "epss_percentile": 0.33936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Product Lifecycle Analytics",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61176"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-60174",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00405,
      "epss_percentile": 0.33868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60174"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-60243",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00405,
      "epss_percentile": 0.33868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60243"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-60404",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00405,
      "epss_percentile": 0.33869,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "TimesTen In-Memory Database",
      "cwe": "CWE-400",
      "title": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60404"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-61093",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00405,
      "epss_percentile": 0.33869,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61093"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-61109",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00405,
      "epss_percentile": 0.33868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61109"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-61194",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00405,
      "epss_percentile": 0.33867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Engineering Data Management",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61194"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-61195",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00405,
      "epss_percentile": 0.33867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Engineering Data Management",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61195"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-60542",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00403,
      "epss_percentile": 0.33681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Business Process Management Suite",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human Workflow). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Business Process Management Suite. While the vulnerability is in Oracle Business Process Management Suite, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Business Process Management Suite. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60542"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-60561",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00403,
      "epss_percentile": 0.33684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60561"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-60565",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00403,
      "epss_percentile": 0.33682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60565"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-47393",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00403,
      "epss_percentile": 0.33759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-306",
      "title": "PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47393"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-60157",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle GoldenGate",
      "cwe": "CWE-284",
      "title": "Vulnerability in Oracle GoldenGate (component: Service Manager). Supported versions that are affected are 19.1.0.0.0-19.29.0.0, 21.3-21.21 and 23.4-23.26.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60157"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-60175",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Database Server",
      "cwe": "CWE-269",
      "title": "Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60175"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-60203",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60203"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-60398",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle GoldenGate",
      "cwe": "CWE-306",
      "title": "Vulnerability in Oracle GoldenGate (component: Oracle GoldenGate Microservices). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60398"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-60676",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.3368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Applications Framework",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60676"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-60692",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.3368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Asset Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset Management. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Asset Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60692"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-60829",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Advanced Outbound Telephony",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Outbound Telephony. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60829"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-61311",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Product Hub",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61311"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-61322",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "TeleSales",
      "cwe": "CWE-269",
      "title": "Vulnerability in the TeleSales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise TeleSales. Successful attacks of this vulnerability can result in takeover of TeleSales. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61322"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-60333",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Access Manager",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60333"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-60361",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60361"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-60456",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60456"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-60457",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60457"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-60458",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60458"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-60459",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.3363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60459"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-60461",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.3363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60461"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-60524",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60524"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-60531",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager Connector",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60531"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-60537",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Managed File Transfer",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Managed File Transfer. While the vulnerability is in Oracle Managed File Transfer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Managed File Transfer. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60537"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-60547",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Managed File Transfer",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Managed File Transfer. While the vulnerability is in Oracle Managed File Transfer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Managed File Transfer. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60547"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-60552",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60552"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-60627",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": "CWE-306",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). The supported version that is affected is 9.2.26.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60627"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-60711",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60711"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-61041",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Demantra Demand Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Product Security). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demantra Demand Management. While the vulnerability is in Oracle Demantra Demand Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Demantra Demand Management. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61041"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-61072",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.3363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Staffing Front Office Brazil",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office Brazil product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Staffing Front Office Brazil. While the vulnerability is in PeopleSoft Enterprise FIN Staffing Front Office Brazil, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Staffing Front Office Brazil. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61072"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-61076",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise HCM Talent Acquisition Manager",
      "cwe": "CWE-269",
      "title": "Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager product of Oracle PeopleSoft (component: Job Opening). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Talent Acquisition Manager. While the vulnerability is in PeopleSoft Enterprise HCM Talent Acquisition Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise HCM Talent Acquisition Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61076"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-61146",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61146"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-61209",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft In-Memory Project Discovery",
      "cwe": "CWE-269",
      "title": "Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft In-Memory Project Discovery. While the vulnerability is in PeopleSoft In-Memory Project Discovery, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft In-Memory Project Discovery. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61209"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-46992",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46992"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-46995",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46995"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-47004",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Update Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47004"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-47031",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Bills of Material",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Bill Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. Successful attacks of this vulnerability can result in takeover of Oracle Bills of Material. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47031"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-60268",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60268"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-60334",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60334"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-60430",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60430"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-60465",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebCenter Content: Imaging",
      "cwe": "CWE-284",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60465"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-60493",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Human Resources Management",
      "cwe": "CWE-306",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Human Resources Management. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Human Resources Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60493"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-60499",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Solution Advisor",
      "cwe": "CWE-306",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Solution Advisor product of Oracle JD Edwards (component: Solution Advisor). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Solution Advisor. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Solution Advisor. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60499"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-60503",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebCenter Content: Imaging",
      "cwe": "CWE-284",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60503"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-60539",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle SOA Suite",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in takeover of Oracle SOA Suite. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60539"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-60545",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Managed File Transfer",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Managed File Transfer. Successful attacks of this vulnerability can result in takeover of Oracle Managed File Transfer. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60545"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-60549",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Managed File Transfer",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Managed File Transfer. Successful attacks of this vulnerability can result in takeover of Oracle Managed File Transfer. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60549"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-60583",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Transportation Management",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in takeover of Oracle Transportation Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60583"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-60594",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Campus Community",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Campus Community. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60594"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-60602",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Student Financials",
      "cwe": "CWE-306",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Student Financials product of Oracle PeopleSoft (component: Billing). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Financials. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Student Financials. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60602"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-60603",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Student Records",
      "cwe": "CWE-20",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Australian Features). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Student Records. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60603"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-60618",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Procurement and Subcontract Management",
      "cwe": "CWE-306",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Procurement and Subcontract Management product of Oracle JD Edwards (component: Procurement). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Procurement and Subcontract Management. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Procurement and Subcontract Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60618"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-60655",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60655"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-60656",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60656"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-60738",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Installed Base",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in takeover of Oracle Installed Base. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60738"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-60783",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iReceivables",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (component: AR Web Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iReceivables. Successful attacks of this vulnerability can result in takeover of Oracle iReceivables. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60783"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-61098",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61098"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-61099",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61099"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-61110",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Applications DBA",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks of this vulnerability can result in takeover of Oracle Applications DBA. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61110"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-61121",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.3362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (UK)",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (UK). CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61121"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-61127",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Communications Service Catalog and Design",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Solution Designer). Supported versions that are affected are 8.0.0.7.0-8.3.0.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design. Successful attacks of this vulnerability can result in takeover of Oracle Communications Service Catalog and Design. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61127"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-61149",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.3362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61149"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-61166",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61166"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-61168",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61168"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-61179",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Product Lifecycle Management for Process",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61179"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-61180",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Product Lifecycle Management for Process",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61180"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-61243",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Common Objects Argentina",
      "cwe": "CWE-269",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Argentina. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61243"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-61289",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Product Development",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Management Specs). The supported version that is affected is 12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Product Development. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Product Development. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61289"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-61320",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payables",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Payables product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payables. Successful attacks of this vulnerability can result in takeover of Oracle Payables. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61320"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-62447",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Trade Management",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trade Management. Successful attacks of this vulnerability can result in takeover of Oracle Trade Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62447"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-61160",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-20",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61160"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-60176",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payments",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Payments accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Payments. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60176"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-13439",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00401,
      "epss_percentile": 0.33519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hassantafreshi",
      "product": "Easy Form Builder by WhiteStudio – Drag & Drop Form Builder",
      "cwe": "CWE-269",
      "title": "Easy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13439"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-28312",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00401,
      "epss_percentile": 0.33463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolarWinds",
      "product": "Serv-U",
      "cwe": "CWE-285",
      "title": "SolarWinds Serv-U Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28312"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-47143",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00398,
      "epss_percentile": 0.33181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "capstone-engine",
      "product": "capstone",
      "cwe": "CWE-476",
      "title": "Capstone has a NULL Pointer Dereference with 3DNow! opcodes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47143"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-60145",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00398,
      "epss_percentile": 0.33206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60145"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-60194",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00398,
      "epss_percentile": 0.33206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON Duality). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60194"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-60195",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00398,
      "epss_percentile": 0.33206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON Duality). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60195"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-60365",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00397,
      "epss_percentile": 0.33051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HTTP Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle Weblogic Server Proxy Plug-in accessible data. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60365"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-60550",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.33051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60550"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-61026",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.33051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iRecruitment",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iRecruitment. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iRecruitment accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61026"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-62521",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.33051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (US)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - General). Supported versions that are affected are 12.2.7-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (US) accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62521"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-60267",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.33004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60267"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-60606",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.33003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CC Common Application Objects",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CC Common Application Objects. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CC Common Application Objects accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise CC Common Application Objects accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60606"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-60649",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.33008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60649"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-61059",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.33007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise SCM Order Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Order Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Order Management accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Order Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61059"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-61153",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.33005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61153"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-61156",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.33005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search Platform Services",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Commerce Guided Search Platform Services. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search Platform Services accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search Platform Services accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61156"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-61171",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.33006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61171"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-61184",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.33009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Product Lifecycle Management for Process",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Product Lifecycle Management for Process accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile Product Lifecycle Management for Process accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61184"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-61197",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.33008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61197"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-60356",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.33007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Access Manager",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60356"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-60359",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.33008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60359"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-60536",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.33007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager Connector",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60536"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-60559",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.33003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Access Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60559"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-60170",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.33005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hospitality Simphony",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60170"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-60263",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.33004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60263"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-60605",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.33003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Student Records",
      "cwe": "CWE-306",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Higher Ed Statistics Agency - UK HESA). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Student Records accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60605"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-60622",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.33009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle JDeveloper",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60622"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-61073",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.33009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Common Objects Brazil",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Purchasing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Brazil accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61073"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-61085",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.33009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise SCM Inventory",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise SCM Inventory product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise SCM Inventory. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Inventory accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61085"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-61086",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.33006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise SCM Order Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise SCM Order Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Order Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61086"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-61087",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.33006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Payables",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Payables product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Payables. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Payables accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61087"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-61088",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.3301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise SCM Manufacturing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise SCM Manufacturing product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Manufacturing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Manufacturing accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61088"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-61157",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.3301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61157"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-61158",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.33006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61158"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-61172",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.33004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61172"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-60880",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00395,
      "epss_percentile": 0.3288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Work in Process",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in takeover of Oracle Work in Process. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60880"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-16351",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00394,
      "epss_percentile": 0.32725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Sandbox escape due to use-after-free in the DOM: Navigation component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16351"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-16352",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00394,
      "epss_percentile": 0.32724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Sandbox escape due to use-after-free in the Disability Access APIs component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16352"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-16356",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00394,
      "epss_percentile": 0.32724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Sandbox escape due to use-after-free in the Disability Access APIs component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16356"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-61070",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00394,
      "epss_percentile": 0.32685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Common Objects Argentina",
      "cwe": "CWE-400",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Cash Management). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Common Objects Argentina. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61070"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-60923",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.3258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Capacity",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Capacity product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Capacity. While the vulnerability is in Oracle Capacity, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Capacity accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60923"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-60199",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0039,
      "epss_percentile": 0.32298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60199"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-16368",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00388,
      "epss_percentile": 0.3214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Incorrect boundary conditions in the JavaScript: WebAssembly component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16368"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-16318",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00388,
      "epss_percentile": 0.32128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Amazon",
      "product": "s2n-tls",
      "cwe": "CWE-401",
      "title": "QUIC Transport Parameters Memory Leak During HelloRetryRequest in s2n-tls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16318"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-60719",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00387,
      "epss_percentile": 0.32001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle BI Publisher",
      "cwe": "CWE-20",
      "title": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60719"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-16377",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00387,
      "epss_percentile": 0.3201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "title": "Mitigation bypass in the PDF Viewer component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16377"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-16383",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00387,
      "epss_percentile": 0.3201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "title": "Mitigation bypass in the DOM: Networking component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16383"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-61186",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00386,
      "epss_percentile": 0.31935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Engineering Data Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data as well as unauthorized read access to a subset of Oracle Agile Engineering Data Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61186"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-60846",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00386,
      "epss_percentile": 0.31885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Mobile Application Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Mobile Application Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Mobile Application Server accessible data as well as unauthorized update, insert or delete access to some of Oracle Mobile Application Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Mobile Application Server. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60846"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-8982",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00384,
      "epss_percentile": 0.31721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autel",
      "product": "MaxiCharger Single",
      "cwe": "CWE-798",
      "title": "Hard-coded / Backdoor Accounts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8982"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-60306",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00384,
      "epss_percentile": 0.31694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60306"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-60308",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00384,
      "epss_percentile": 0.31694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60308"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-52469",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.xml file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52469"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-52470",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52470"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-52472",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52472"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-60264",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60264"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2016-20096",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00382,
      "epss_percentile": 0.31518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kunshi Network Technology Co., Ltd.",
      "product": "Linknat VOS3000",
      "cwe": "CWE-89",
      "title": "Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20096"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-65316",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00382,
      "epss_percentile": 0.31476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xuxueli",
      "product": "xxl-job",
      "cwe": "CWE-639",
      "title": "xxl-job Cross-Job-Group Log Disclosure via Missing Authorization Check in /joblog/logDetailCat",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65316"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-47397",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00381,
      "epss_percentile": 0.31435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-22",
      "title": "PraisonAI has an Arbitrary File Write in Python API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47397"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-60941",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Service Fulfillment Manager",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Service Fulfillment Manager. While the vulnerability is in Oracle Service Fulfillment Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Service Fulfillment Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Service Fulfillment Manager accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60941"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-60165",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0038,
      "epss_percentile": 0.31283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Cost Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Enterprise Command Center). The supported version that is affected is V16. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Cost Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60165"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-60978",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0038,
      "epss_percentile": 0.31284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Scripting",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Scripting accessible data as well as unauthorized access to critical data or complete access to all Oracle Scripting accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60978"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-60862",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00379,
      "epss_percentile": 0.31248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Order Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Order Management. While the vulnerability is in Oracle Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Order Management accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60862"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-56746",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00379,
      "epss_percentile": 0.31214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-284",
      "title": "Netty has a Security Control Bypass via CORS Short-Circuit Failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56746"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-60433",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00379,
      "epss_percentile": 0.31248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Transportation Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Integration). The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Transportation Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Transportation Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60433"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-60843",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00379,
      "epss_percentile": 0.31248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Citizen Interaction Center",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Citizen Interaction Center product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Citizen Interaction Center. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Citizen Interaction Center accessible data as well as unauthorized access to critical data or complete access to all Oracle Citizen Interaction Center accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60843"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-47049",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00379,
      "epss_percentile": 0.31247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PeopleTools",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47049"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-16382",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00378,
      "epss_percentile": 0.31106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "title": "Mitigation bypass in the DOM: Service Workers component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16382"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-61309",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00377,
      "epss_percentile": 0.30988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle In-Memory Cost Management for Discrete Industries",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle In-Memory Cost Management for Discrete Industries product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle In-Memory Cost Management for Discrete Industries. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle In-Memory Cost Management for Discrete Industries accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61309"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-60192",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Connectors",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60192"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-60548",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle SOA Suite",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite. While the vulnerability is in Oracle SOA Suite, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle SOA Suite accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60548"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-61014",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Inventory Management",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Inventory Management. While the vulnerability is in Oracle Inventory Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Inventory Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61014"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-61125",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Configure to Order",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Configure to Order product of Oracle E-Business Suite (component: Supply to Order Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Configure to Order. While the vulnerability is in Oracle Configure to Order, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configure to Order accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61125"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-60609",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00376,
      "epss_percentile": 0.30879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Campus Community",
      "cwe": "CWE-200",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Communication). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60609"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-60673",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00376,
      "epss_percentile": 0.3088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle BI Publisher",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60673"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-60835",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00376,
      "epss_percentile": 0.30923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Price Protection",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Price Protection. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Price Protection accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60835"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-61251",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00376,
      "epss_percentile": 0.30923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "HRMS (Australia)",
      "cwe": "CWE-200",
      "title": "Vulnerability in the HRMS (Australia) product of Oracle E-Business Suite (component: Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise HRMS (Australia). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all HRMS (Australia) accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61251"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-16367",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00375,
      "epss_percentile": 0.30821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Sandbox escape due to invalid pointer in the Disability Access APIs component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16367"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-16388",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00375,
      "epss_percentile": 0.30822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "title": "Sandbox escape in the DOM: Networking component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16388"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-61009",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.3084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Logistics",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Logistics. While the vulnerability is in Oracle Process Manufacturing Logistics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Logistics. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61009"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-52474",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.30768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUtil.java file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52474"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-61165",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.30784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search Platform Services",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search Platform Services. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search Platform Services and unauthorized read access to a subset of Oracle Commerce Guided Search Platform Services accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61165"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-60892",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00375,
      "epss_percentile": 0.3084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (Norway)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payroll). Supported versions that are affected are 12.2.8-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Norway). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (Norway). CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60892"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-60613",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00374,
      "epss_percentile": 0.30644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Student Records",
      "cwe": "CWE-20",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Student Records. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60613"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-65319",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Feedbin",
      "product": "Feedbin",
      "cwe": "CWE-306",
      "title": "Feedbin Unauthenticated Entry Content Disclosure via GET /api/v2/entries/:id/text",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65319"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-56817",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-611",
      "title": "Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56817"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-47058",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE",
      "cwe": "CWE-502",
      "title": "Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data as well as unauthorized access to critical data or complete access to all Oracle Java SE accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47058"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-47009",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0037,
      "epss_percentile": 0.30284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47009"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-50756",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00369,
      "epss_percentile": 0.30113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-1390",
      "title": "An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50756"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-52476",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00369,
      "epss_percentile": 0.30088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the getPageData method in the DatacenterQuery.java file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52476"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-60316",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00368,
      "epss_percentile": 0.29979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60316"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-61201",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00366,
      "epss_percentile": 0.29818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CRM Common Objects",
      "cwe": "CWE-269",
      "title": "Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.2.23. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CRM Common Objects. While the vulnerability is in PeopleSoft Enterprise CRM Common Objects, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CRM Common Objects. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61201"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-61223",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00366,
      "epss_percentile": 0.29819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Communications Converged Application Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). Supported versions that are affected are 8.2 and 8.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle Communications Converged Application Server. While the vulnerability is in Oracle Communications Converged Application Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61223"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-60169",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.29819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hospitality Simphony",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Simphony. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60169"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-60201",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.29857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60201"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-60222",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.29817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60222"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-60417",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.29819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60417"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-60543",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.2982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle SOA Suite",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in takeover of Oracle SOA Suite. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60543"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-60558",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.29817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60558"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-60621",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.29818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": "CWE-306",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60621"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-60756",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.29857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle EDI Gateway",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: All Miscellaneous EDI Issues). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle EDI Gateway. Successful attacks of this vulnerability can result in takeover of Oracle EDI Gateway. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60756"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-60780",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.29857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Workflow",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in takeover of Oracle Workflow. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60780"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-60785",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.2982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iReceivables",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (component: AR Web Utilities). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iReceivables. Successful attacks of this vulnerability can result in takeover of Oracle iReceivables. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60785"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-61074",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.29819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Common Objects Brazil",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Brazil. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61074"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-61092",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.2982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61092"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-61106",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.29817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle GoldenGate",
      "cwe": "CWE-284",
      "title": "Vulnerability in Oracle GoldenGate (component: Config Service Executable). Supported versions that are affected are 23.4-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61106"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-61163",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.29818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61163"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-61170",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.29818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61170"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-56819",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-400",
      "title": "Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56819"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-60314",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Router",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Router. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Router. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60314"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-65052",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00364,
      "epss_percentile": 0.29679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Saturday Drive",
      "product": "Ninja Forms",
      "cwe": "CWE-472",
      "title": "Ninja Forms Calculation and Payment Total Tampering via Fail-Open get_calc_value in ListSelect and ListRadio Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65052"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-60910",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00364,
      "epss_percentile": 0.29627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Property Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Property Manager. Successful attacks of this vulnerability can result in takeover of Oracle Property Manager. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60910"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-16243",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00364,
      "epss_percentile": 0.29631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse OMR",
      "cwe": "CWE-125",
      "title": "Eclipse OMR : arraycmp SIMD implementation does not check if the number of bytes to compare is zero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16243"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-60255",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00363,
      "epss_percentile": 0.29544,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence as well as unauthorized update, insert or delete access to some of Oracle Coherence accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60255"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-46994",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00362,
      "epss_percentile": 0.29462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46994"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-16392",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00362,
      "epss_percentile": 0.29421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-670",
      "title": "JIT miscompilation in the JavaScript Engine: JIT component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16392"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-16420",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16420"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-60840",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Demand Signal Repository",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Demand Signal Repository. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Demand Signal Repository accessible data as well as unauthorized access to critical data or complete access to all Oracle Demand Signal Repository accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60840"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-60848",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.2947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Project Contracts",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Contracts. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Contracts accessible data as well as unauthorized access to critical data or complete access to all Oracle Project Contracts accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60848"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-60871",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.2944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Risk Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Risk Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Risk Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Risk Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Risk Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60871"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-60948",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Learning Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Learning Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Learning Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Learning Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60948"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-60951",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.2947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Time and Labor",
      "cwe": "CWE-863",
      "title": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data as well as unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60951"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-60953",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Telecommunications Billing Integrator",
      "cwe": "CWE-862",
      "title": "Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Telecommunications Billing Integrator. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Telecommunications Billing Integrator accessible data as well as unauthorized access to critical data or complete access to all Oracle Telecommunications Billing Integrator accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60953"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-60982",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.2944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle US Federal Human Resources",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle US Federal Human Resources product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle US Federal Human Resources. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle US Federal Human Resources accessible data as well as unauthorized access to critical data or complete access to all Oracle US Federal Human Resources accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60982"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-16376",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-400",
      "title": "Denial-of-service in the Graphics: WebGPU component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16376"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-61237",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00361,
      "epss_percentile": 0.29333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Common Objects Argentina",
      "cwe": "CWE-269",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina. While the vulnerability is in PeopleSoft Enterprise FIN Common Objects Argentina, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Argentina accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Common Objects Argentina accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Common Objects Argentina. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61237"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-60854",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Quality",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Quality. While the vulnerability is in Oracle Quality, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Quality accessible data as well as unauthorized update, insert or delete access to some of Oracle Quality accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Quality. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60854"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-60377",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0036,
      "epss_percentile": 0.29287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Service Delivery Platform accessible data as well as unauthorized access to critical data or complete access to all Service Delivery Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Service Delivery Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60377"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-47410",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0036,
      "epss_percentile": 0.29275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "praisonai-platform",
      "cwe": "CWE-321",
      "title": "praisonai-platform: JWT signing key defaults to hardcoded \"dev-secret-change-me\", allowing token forgery for any user when PLATFORM_ENV is unset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47410"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-60788",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.29286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Sales Offline",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Offline. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Sales Offline accessible data as well as unauthorized access to critical data or complete access to all Oracle Sales Offline accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Sales Offline. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60788"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-60647",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.29287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Content. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60647"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-60363",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00355,
      "epss_percentile": 0.28718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HTTP Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Apache Plugin). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60363"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-60364",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00355,
      "epss_percentile": 0.28718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HTTP Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Weblogic Server Proxy Plug-in. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Weblogic Server Proxy Plug-in accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60364"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-61249",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00355,
      "epss_percentile": 0.2878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Learning Management",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Import And Export). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Learning Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Learning Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61249"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-47056",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Data Integrator",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator. While the vulnerability is in Oracle Data Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47056"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-60644",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.2869,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60644"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-46924",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Testing Suite",
      "cwe": "CWE-284",
      "title": "Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46924"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-46982",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Retail Integration Bus",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 14.1.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus. Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46982"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-47036",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Development",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Siebel Approval Manager). Supported versions that are affected are 17.0-26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Development. Successful attacks of this vulnerability can result in takeover of Siebel CRM Development. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47036"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-60221",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60221"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-60232",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60232"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-60241",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60241"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-60244",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60244"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-60246",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60246"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-60250",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60250"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-60251",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60251"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-60269",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60269"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-60276",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60276"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-60278",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60278"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-60279",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60279"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-60328",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Access Manager",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60328"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-60329",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60329"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-60374",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60374"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-60380",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60380"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-60387",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60387"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-60388",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60388"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-60435",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60435"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-60441",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60441"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-60446",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60446"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-60460",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60460"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-60463",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebCenter Content: Imaging",
      "cwe": "CWE-306",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60463"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-60566",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60566"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-60999",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Data Integrator",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60999"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-61154",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search Platform Services",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search Platform Services. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search Platform Services. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61154"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-61245",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Manufacturing Brazil",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise FIN Manufacturing Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Manufacturing Brazil. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61245"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-61130",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Platform. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61130"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-60211",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.28672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Coherence executes to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60211"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-60261",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.28672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Coherence executes to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60261"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-60580",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.28673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Command Center Framework",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Enterprise Command Center Framework executes to compromise Oracle Enterprise Command Center Framework. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60580"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-60233",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00354,
      "epss_percentile": 0.28596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Coherence. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60233"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-60690",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.2842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60690"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-63453",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.2843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": "CWE-120",
      "title": "Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63453"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-60220",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00351,
      "epss_percentile": 0.28283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60220"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-60632",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00351,
      "epss_percentile": 0.28284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60632"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-60700",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.28284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Universal Work Queue",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: UWQ Server Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Universal Work Queue accessible data as well as unauthorized access to critical data or complete access to all Oracle Universal Work Queue accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60700"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-60557",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00351,
      "epss_percentile": 0.28283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60557"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-60624",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00351,
      "epss_percentile": 0.28285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Connectors",
      "cwe": "CWE-404",
      "title": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60624"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-60790",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.28185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Sales Offline",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Sales Offline. While the vulnerability is in Oracle Sales Offline, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Sales Offline. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60790"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-61224",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.28186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Communications Converged Application Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). The supported version that is affected is 8.3. Difficult to exploit vulnerability allows high privileged attacker with network access via TLS to compromise Oracle Communications Converged Application Server. While the vulnerability is in Oracle Communications Converged Application Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61224"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-46600",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.28221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Go standard library",
      "product": "net",
      "cwe": "CWE-125",
      "title": "Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46600"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-60178",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0035,
      "epss_percentile": 0.28186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60178"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-60585",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0035,
      "epss_percentile": 0.28185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60585"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-60825",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0035,
      "epss_percentile": 0.28185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iSupport",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this vulnerability can result in takeover of Oracle iSupport. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60825"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-60826",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0035,
      "epss_percentile": 0.28184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iSupport",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this vulnerability can result in takeover of Oracle iSupport. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60826"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-61328",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0035,
      "epss_percentile": 0.28186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Cost Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61328"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-59139",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00349,
      "epss_percentile": 0.28119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::ReqRep::Shared",
      "cwe": "CWE-125",
      "title": "Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59139"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-61225",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Communications Converged Application Server",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that are affected are 8.2 and 8.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle Communications Converged Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61225"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-60773",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00347,
      "epss_percentile": 0.27856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Object Library",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Application Object Library. While the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Application Object Library accessible data as well as unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60773"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-60586",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Connectors",
      "cwe": "CWE-306",
      "title": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60586"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-47396",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00346,
      "epss_percentile": 0.27747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-284",
      "title": "PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47396"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-28306",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00344,
      "epss_percentile": 0.27526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolarWinds",
      "product": "Serv-U",
      "cwe": "CWE-284",
      "title": "SolarWinds Serv-U Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28306"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-28307",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00344,
      "epss_percentile": 0.27526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolarWinds",
      "product": "Serv-U",
      "cwe": "CWE-284",
      "title": "SolarWinds Serv-U Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28307"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-28309",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00344,
      "epss_percentile": 0.27554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolarWinds",
      "product": "Serv-U",
      "cwe": "CWE-862",
      "title": "SolarWinds Serv-U Broken Access Control Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28309"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-28310",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00344,
      "epss_percentile": 0.27554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolarWinds",
      "product": "Serv-U",
      "cwe": "CWE-862",
      "title": "SolarWinds Serv-U Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28310"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-28313",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00344,
      "epss_percentile": 0.27554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolarWinds",
      "product": "Serv-U",
      "cwe": "CWE-639",
      "title": "SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28313"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-28317",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00344,
      "epss_percentile": 0.27525,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolarWinds",
      "product": "Serv-U",
      "cwe": "CWE-639",
      "title": "SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28317"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-47012",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00344,
      "epss_percentile": 0.27502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47012"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-65050",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.27475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Saturday Drive",
      "product": "Ninja Forms",
      "cwe": "CWE-862",
      "title": "Ninja Forms Missing Authorization in submissions-table Gutenberg Block Discloses Form Submissions to Unauthenticated Visitors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65050"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-60177",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60177"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-60182",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60182"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-60184",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60184"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-60185",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60185"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-60186",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60186"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2026-60187",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60187"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2026-47695",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cc-tweaked",
      "product": "CC-Tweaked",
      "cwe": "CWE-918",
      "title": "CC-Tweaked has an SSRF Protection Bypass with NAT64",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47695"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-46403",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00342,
      "epss_percentile": 0.27357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klever-io",
      "product": "klever-go",
      "cwe": "CWE-693",
      "title": "Klever-Go KVM read-only execution can commit contract delete and upgrade side effects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46403"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-16354",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-200",
      "title": "Information disclosure in the Graphics: ImageLib component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16354"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-15724",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress",
      "product": "ShareFile Storage Zones Controller",
      "cwe": "CWE-20",
      "title": "Path traversal in Progress ShareFile Storage Zones Controller (SZC)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15724"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-46988",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.2697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Connector Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46988"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-47005",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Update Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47005"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-47006",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Update Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47006"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-60335",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60335"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-60340",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Project Costing",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Project Costing product of Oracle E-Business Suite (component: Enterprise Command Center). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Project Costing. Successful attacks of this vulnerability can result in takeover of Oracle Project Costing. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60340"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-60396",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle GoldenGate",
      "cwe": "CWE-306",
      "title": "Vulnerability in Oracle GoldenGate (component: Distribution Server executable). Supported versions that are affected are 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60396"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-60418",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60418"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-60755",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Assets",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Assets. Successful attacks of this vulnerability can result in takeover of Oracle Assets. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60755"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-60787",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.2697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Receivables",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Receivables product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Receivables. Successful attacks of this vulnerability can result in takeover of Oracle Receivables. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60787"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-60813",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iStore",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability can result in takeover of Oracle iStore. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60813"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-60836",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.27016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HCM Common Architecture",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HCM Common Architecture. Successful attacks of this vulnerability can result in takeover of Oracle HCM Common Architecture. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60836"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-61027",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Cost Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Inventory Costing). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61027"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-61285",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.27016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Systems",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Systems. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Systems. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61285"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-62548",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (US)",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (US). CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62548"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-61207",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00338,
      "epss_percentile": 0.26824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise SCM eProcurement",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise SCM eProcurement product of Oracle PeopleSoft (component: Manage Requisition Status). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM eProcurement. While the vulnerability is in PeopleSoft Enterprise SCM eProcurement, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM eProcurement accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise SCM eProcurement accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61207"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-60284",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Coherence accessible data as well as unauthorized update, insert or delete access to some of Oracle Coherence accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60284"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-60615",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Campus Community",
      "cwe": "CWE-287",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60615"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2026-60668",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise HCM Human Resources",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: French Public Sector Specific). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human Resources. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise HCM Human Resources accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise HCM Human Resources accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60668"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-61089",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise SCM Inventory",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise SCM Inventory product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Inventory. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Inventory accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise SCM Inventory accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61089"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-60686",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle U.S. Federal Financials",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle U.S. Federal Financials. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle U.S. Federal Financials accessible data as well as unauthorized access to critical data or complete access to all Oracle U.S. Federal Financials accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60686"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-60741",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.2682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Cost Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Cost Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60741"
    },
    {
      "rank": 547,
      "cve_id": "CVE-2026-60749",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Assets",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Assets. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Assets accessible data as well as unauthorized access to critical data or complete access to all Oracle Assets accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60749"
    },
    {
      "rank": 548,
      "cve_id": "CVE-2026-60771",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Complex Maintenance, Repair and Overhaul",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Complex Maintenance, Repair and Overhaul accessible data as well as unauthorized access to critical data or complete access to all Oracle Complex Maintenance, Repair and Overhaul accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60771"
    },
    {
      "rank": 549,
      "cve_id": "CVE-2026-60867",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Advanced Pricing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Pricing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Pricing accessible data as well as unauthorized access to critical data or complete access to all Oracle Advanced Pricing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60867"
    },
    {
      "rank": 550,
      "cve_id": "CVE-2026-60875",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Trade Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trade Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Trade Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Trade Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60875"
    },
    {
      "rank": 551,
      "cve_id": "CVE-2026-60942",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Service Fulfillment Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Fulfillment Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Service Fulfillment Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Service Fulfillment Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60942"
    },
    {
      "rank": 552,
      "cve_id": "CVE-2026-60963",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Treasury",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Treasury product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Treasury. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Treasury accessible data as well as unauthorized access to critical data or complete access to all Oracle Treasury accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60963"
    },
    {
      "rank": 553,
      "cve_id": "CVE-2026-60997",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Universal Work Queue",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Non-Media Integration issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Universal Work Queue accessible data as well as unauthorized access to critical data or complete access to all Oracle Universal Work Queue accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60997"
    },
    {
      "rank": 554,
      "cve_id": "CVE-2026-61000",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Systems",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Systems. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Systems accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Systems accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61000"
    },
    {
      "rank": 555,
      "cve_id": "CVE-2026-61004",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Landed Cost Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Landed Cost Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Landed Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Landed Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Landed Cost Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61004"
    },
    {
      "rank": 556,
      "cve_id": "CVE-2026-61005",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Logistics",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Logistics. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Logistics accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Logistics accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61005"
    },
    {
      "rank": 557,
      "cve_id": "CVE-2026-61019",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Customers Online",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Customers Online product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customers Online. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Customers Online accessible data as well as unauthorized access to critical data or complete access to all Oracle Customers Online accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61019"
    },
    {
      "rank": 558,
      "cve_id": "CVE-2026-61031",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Financials Common Country",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Financials Common Country product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Country. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financials Common Country accessible data as well as unauthorized access to critical data or complete access to all Oracle Financials Common Country accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61031"
    },
    {
      "rank": 559,
      "cve_id": "CVE-2026-61287",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.2682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Systems",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Systems. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Systems accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Systems accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61287"
    },
    {
      "rank": 560,
      "cve_id": "CVE-2026-61310",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Product Hub",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Hub accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61310"
    },
    {
      "rank": 561,
      "cve_id": "CVE-2026-61327",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Bills of Material",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.13-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Bills of Material accessible data as well as unauthorized access to critical data or complete access to all Oracle Bills of Material accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61327"
    },
    {
      "rank": 562,
      "cve_id": "CVE-2026-61329",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.2682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Price Protection",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Price Protection. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Price Protection accessible data as well as unauthorized access to critical data or complete access to all Oracle Price Protection accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61329"
    },
    {
      "rank": 563,
      "cve_id": "CVE-2026-61338",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Contracts Integration",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Contracts Integration accessible data as well as unauthorized access to critical data or complete access to all Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61338"
    },
    {
      "rank": 564,
      "cve_id": "CVE-2026-62445",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Order Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.4-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Order Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Order Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62445"
    },
    {
      "rank": 565,
      "cve_id": "CVE-2026-60750",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payroll",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. While the vulnerability is in Oracle Payroll, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Payroll accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60750"
    },
    {
      "rank": 566,
      "cve_id": "CVE-2026-61112",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00338,
      "epss_percentile": 0.26821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Order Management",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Order Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61112"
    },
    {
      "rank": 567,
      "cve_id": "CVE-2026-61323",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00338,
      "epss_percentile": 0.26815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Advanced Benefits",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Internal Operations). The supported version that is affected is 12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Benefits accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61323"
    },
    {
      "rank": 568,
      "cve_id": "CVE-2026-62480",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00338,
      "epss_percentile": 0.2682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Public Sector Financials",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Public Sector Financials accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62480"
    },
    {
      "rank": 569,
      "cve_id": "CVE-2026-60239",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00337,
      "epss_percentile": 0.26782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60239"
    },
    {
      "rank": 570,
      "cve_id": "CVE-2026-60540",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00337,
      "epss_percentile": 0.26775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle SOA Suite",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite. While the vulnerability is in Oracle SOA Suite, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle SOA Suite accessible data as well as unauthorized access to critical data or complete access to all Oracle SOA Suite accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60540"
    },
    {
      "rank": 571,
      "cve_id": "CVE-2026-60564",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00337,
      "epss_percentile": 0.26775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60564"
    },
    {
      "rank": 572,
      "cve_id": "CVE-2026-59140",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00337,
      "epss_percentile": 0.26795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::SortedSet::Shared",
      "cwe": "CWE-125",
      "title": "Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59140"
    },
    {
      "rank": 573,
      "cve_id": "CVE-2026-59141",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00337,
      "epss_percentile": 0.26795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::RadixTree::Shared",
      "cwe": "CWE-125",
      "title": "Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59141"
    },
    {
      "rank": 574,
      "cve_id": "CVE-2026-59142",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00337,
      "epss_percentile": 0.26795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::HashMap::Shared",
      "cwe": "CWE-125",
      "title": "Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59142"
    },
    {
      "rank": 575,
      "cve_id": "CVE-2026-47019",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Product Hub",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Hub accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47019"
    },
    {
      "rank": 576,
      "cve_id": "CVE-2026-47028",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Document Management and Collaboration",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Attachments). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Document Management and Collaboration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Document Management and Collaboration accessible data as well as unauthorized access to critical data or complete access to all Oracle Document Management and Collaboration accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47028"
    },
    {
      "rank": 577,
      "cve_id": "CVE-2026-60520",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Unified Directory accessible data as well as unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60520"
    },
    {
      "rank": 578,
      "cve_id": "CVE-2026-60560",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60560"
    },
    {
      "rank": 579,
      "cve_id": "CVE-2026-60599",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Student Records",
      "cwe": "CWE-287",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise PeopleSoft Enterprise CS Student Records. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Student Records accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Student Records accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60599"
    },
    {
      "rank": 580,
      "cve_id": "CVE-2026-60706",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Inventory",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Process Manufacturing Inventory product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Inventory. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Inventory accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Inventory accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60706"
    },
    {
      "rank": 581,
      "cve_id": "CVE-2026-60714",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.2678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Price Protection",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Price Protection. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Price Protection accessible data as well as unauthorized access to critical data or complete access to all Oracle Price Protection accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60714"
    },
    {
      "rank": 582,
      "cve_id": "CVE-2026-60736",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle E-Business Intelligence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Definition). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Intelligence. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Intelligence accessible data as well as unauthorized access to critical data or complete access to all Oracle E-Business Intelligence accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60736"
    },
    {
      "rank": 583,
      "cve_id": "CVE-2026-60778",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26773,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payments",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Payments accessible data as well as unauthorized access to critical data or complete access to all Oracle Payments accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60778"
    },
    {
      "rank": 584,
      "cve_id": "CVE-2026-60784",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Trading Community",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Party Search UI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trading Community. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Trading Community accessible data as well as unauthorized access to critical data or complete access to all Oracle Trading Community accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60784"
    },
    {
      "rank": 585,
      "cve_id": "CVE-2026-60793",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26773,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle TeleSales",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle TeleSales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle TeleSales. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle TeleSales accessible data as well as unauthorized access to critical data or complete access to all Oracle TeleSales accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60793"
    },
    {
      "rank": 586,
      "cve_id": "CVE-2026-60817",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.2678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iStore",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iStore accessible data as well as unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60817"
    },
    {
      "rank": 587,
      "cve_id": "CVE-2026-60844",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Customer Support",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Customer Support product of Oracle E-Business Suite (component: Update Service Request). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Support. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Customer Support accessible data as well as unauthorized access to critical data or complete access to all Oracle Customer Support accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60844"
    },
    {
      "rank": 588,
      "cve_id": "CVE-2026-60877",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Trade Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trade Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Trade Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Trade Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60877"
    },
    {
      "rank": 589,
      "cve_id": "CVE-2026-60904",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Installed Base",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Installed Base accessible data as well as unauthorized access to critical data or complete access to all Oracle Installed Base accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60904"
    },
    {
      "rank": 590,
      "cve_id": "CVE-2026-60917",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Inventory Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Core Receiving). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Inventory Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Inventory Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Inventory Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60917"
    },
    {
      "rank": 591,
      "cve_id": "CVE-2026-60959",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle SDP Number Portability",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SDP Number Portability. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle SDP Number Portability accessible data as well as unauthorized access to critical data or complete access to all Oracle SDP Number Portability accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60959"
    },
    {
      "rank": 592,
      "cve_id": "CVE-2026-60965",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (France)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (France). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HRMS (France) accessible data as well as unauthorized access to critical data or complete access to all Oracle HRMS (France) accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60965"
    },
    {
      "rank": 593,
      "cve_id": "CVE-2026-60966",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.2678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Public Sector Human Resources",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (component: Regression Testing). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Human Resources. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Public Sector Human Resources accessible data as well as unauthorized access to critical data or complete access to all Oracle Public Sector Human Resources accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60966"
    },
    {
      "rank": 594,
      "cve_id": "CVE-2026-60972",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle E-Business Tax",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Tax. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Tax accessible data as well as unauthorized access to critical data or complete access to all Oracle E-Business Tax accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60972"
    },
    {
      "rank": 595,
      "cve_id": "CVE-2026-60974",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle E-Business Tax",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Tax. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Tax accessible data as well as unauthorized access to critical data or complete access to all Oracle E-Business Tax accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60974"
    },
    {
      "rank": 596,
      "cve_id": "CVE-2026-60986",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Project Portfolio Analysis",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Portfolio Analysis accessible data as well as unauthorized access to critical data or complete access to all Oracle Project Portfolio Analysis accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60986"
    },
    {
      "rank": 597,
      "cve_id": "CVE-2026-61024",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iRecruitment",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iRecruitment. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iRecruitment accessible data as well as unauthorized access to critical data or complete access to all Oracle iRecruitment accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61024"
    },
    {
      "rank": 598,
      "cve_id": "CVE-2026-61030",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Product Development",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Product Development. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Product Development accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Product Development accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61030"
    },
    {
      "rank": 599,
      "cve_id": "CVE-2026-61037",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Loans",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Loans product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Loans. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Loans accessible data as well as unauthorized access to critical data or complete access to all Oracle Loans accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61037"
    },
    {
      "rank": 600,
      "cve_id": "CVE-2026-61102",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Banking Trade Finance",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance accessible data as well as unauthorized access to critical data or complete access to all Oracle Banking Trade Finance accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61102"
    },
    {
      "rank": 601,
      "cve_id": "CVE-2026-61105",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Banking Trade Finance",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance accessible data as well as unauthorized access to critical data or complete access to all Oracle Banking Trade Finance accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61105"
    },
    {
      "rank": 602,
      "cve_id": "CVE-2026-61122",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26773,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (UK)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HRMS (UK) accessible data as well as unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61122"
    },
    {
      "rank": 603,
      "cve_id": "CVE-2026-61333",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.2678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Product Workbench",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Workbench accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Workbench accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61333"
    },
    {
      "rank": 604,
      "cve_id": "CVE-2026-61335",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Product Workbench",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Workbench accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Workbench accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61335"
    },
    {
      "rank": 605,
      "cve_id": "CVE-2026-62468",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Human Resources",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Enterprise Command Center). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Human Resources. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Human Resources accessible data as well as unauthorized access to critical data or complete access to all Oracle Human Resources accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62468"
    },
    {
      "rank": 606,
      "cve_id": "CVE-2026-60683",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Regulatory Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Regulatory Management. While the vulnerability is in Oracle Process Manufacturing Regulatory Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Process Manufacturing Regulatory Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60683"
    },
    {
      "rank": 607,
      "cve_id": "CVE-2026-60425",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60425"
    },
    {
      "rank": 608,
      "cve_id": "CVE-2026-60436",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60436"
    },
    {
      "rank": 609,
      "cve_id": "CVE-2026-16395",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00336,
      "epss_percentile": 0.26636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-190",
      "title": "Integer overflow in the Audio/Video component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16395"
    },
    {
      "rank": 610,
      "cve_id": "CVE-2026-16402",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00336,
      "epss_percentile": 0.26636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-190",
      "title": "Integer overflow in the Graphics: ImageLib component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16402"
    },
    {
      "rank": 611,
      "cve_id": "CVE-2026-16408",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00336,
      "epss_percentile": 0.26636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-190",
      "title": "Integer overflow in the Audio/Video: Playback component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16408"
    },
    {
      "rank": 612,
      "cve_id": "CVE-2026-16418",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-121",
      "title": "Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16418"
    },
    {
      "rank": 613,
      "cve_id": "CVE-2026-55082",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dhis2",
      "product": "dhis2-core",
      "cwe": "CWE-89",
      "title": "DHIS2 SQL injection in SQL View filter values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55082"
    },
    {
      "rank": 614,
      "cve_id": "CVE-2026-60855",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Quality",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quality. Successful attacks of this vulnerability can result in takeover of Oracle Quality. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60855"
    },
    {
      "rank": 615,
      "cve_id": "CVE-2026-60859",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Quoting",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Quoting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quoting. Successful attacks of this vulnerability can result in takeover of Oracle Quoting. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60859"
    },
    {
      "rank": 616,
      "cve_id": "CVE-2026-60894",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payroll",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Payroll. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60894"
    },
    {
      "rank": 617,
      "cve_id": "CVE-2026-60927",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Public Sector Financials",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Financials. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60927"
    },
    {
      "rank": 618,
      "cve_id": "CVE-2026-60931",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Public Sector Financials",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Financials. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60931"
    },
    {
      "rank": 619,
      "cve_id": "CVE-2026-60943",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Service Fulfillment Manager",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Fulfillment Manager. Successful attacks of this vulnerability can result in takeover of Oracle Service Fulfillment Manager. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60943"
    },
    {
      "rank": 620,
      "cve_id": "CVE-2026-60988",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Project Portfolio Analysis",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in takeover of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60988"
    },
    {
      "rank": 621,
      "cve_id": "CVE-2026-60266",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00334,
      "epss_percentile": 0.26462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60266"
    },
    {
      "rank": 622,
      "cve_id": "CVE-2026-60610",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00334,
      "epss_percentile": 0.26462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Campus Community",
      "cwe": "CWE-200",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60610"
    },
    {
      "rank": 623,
      "cve_id": "CVE-2026-16412",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00333,
      "epss_percentile": 0.26318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16412"
    },
    {
      "rank": 624,
      "cve_id": "CVE-2026-16421",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.26159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16421"
    },
    {
      "rank": 625,
      "cve_id": "CVE-2026-60667",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.26181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise HCM Human Resources",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Core). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise PeopleSoft Enterprise HCM Human Resources. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise HCM Human Resources accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise HCM Human Resources. CVSS 3.1 Base Score 7.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60667"
    },
    {
      "rank": 626,
      "cve_id": "CVE-2026-60309",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.25991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Coherence executes to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60309"
    },
    {
      "rank": 627,
      "cve_id": "CVE-2026-60196",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.2596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the Oracle WebLogic Server executes to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60196"
    },
    {
      "rank": 628,
      "cve_id": "CVE-2026-10678",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.26034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-476",
      "title": "NULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an unauthenticated I2C controller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10678"
    },
    {
      "rank": 629,
      "cve_id": "CVE-2026-47398",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.26011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-94",
      "title": "PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47398"
    },
    {
      "rank": 630,
      "cve_id": "CVE-2026-60593",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.25993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Staffing Front Office",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office product of Oracle PeopleSoft (component: Staffing Front Office). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Staffing Front Office. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Staffing Front Office accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60593"
    },
    {
      "rank": 631,
      "cve_id": "CVE-2026-60235",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence as well as unauthorized update, insert or delete access to some of Oracle Coherence accessible data and unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60235"
    },
    {
      "rank": 632,
      "cve_id": "CVE-2026-44907",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Meta",
      "product": "react-server-dom-turbopack",
      "cwe": null,
      "title": "A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.7, 19.1.0 through 19.1.8, and 19.2.0 through 19.2.7).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44907"
    },
    {
      "rank": 633,
      "cve_id": "CVE-2026-60492",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne HCM Foundation",
      "cwe": "CWE-269",
      "title": "Vulnerability in the JD Edwards EnterpriseOne HCM Foundation product of Oracle JD Edwards (component: OW HR PR Foundation). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne HCM Foundation. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne HCM Foundation and unauthorized read access to a subset of JD Edwards EnterpriseOne HCM Foundation accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60492"
    },
    {
      "rank": 634,
      "cve_id": "CVE-2026-60311",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 9.0.0-9.7.1; MySQL Cluster: 9.0.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60311"
    },
    {
      "rank": 635,
      "cve_id": "CVE-2026-62498",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Flow Manufacturing",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.7-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in takeover of Oracle Flow Manufacturing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62498"
    },
    {
      "rank": 636,
      "cve_id": "CVE-2026-16360",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00326,
      "epss_percentile": 0.25589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16360"
    },
    {
      "rank": 637,
      "cve_id": "CVE-2026-61297",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.25591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Customers Online",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Customers Online product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customers Online. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Customers Online accessible data as well as unauthorized access to critical data or complete access to all Oracle Customers Online accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61297"
    },
    {
      "rank": 638,
      "cve_id": "CVE-2026-61301",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.25591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Financials",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Financials. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Financials accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Financials accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61301"
    },
    {
      "rank": 639,
      "cve_id": "CVE-2026-60179",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.25559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Connectors",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60179"
    },
    {
      "rank": 640,
      "cve_id": "CVE-2026-60431",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HTTP Server",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_proxy). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. While the vulnerability is in Oracle HTTP Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60431"
    },
    {
      "rank": 641,
      "cve_id": "CVE-2026-60652",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60652"
    },
    {
      "rank": 642,
      "cve_id": "CVE-2026-60807",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Bills of Material",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Bills of Material. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60807"
    },
    {
      "rank": 643,
      "cve_id": "CVE-2026-61116",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Object Library",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61116"
    },
    {
      "rank": 644,
      "cve_id": "CVE-2026-47689",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00324,
      "epss_percentile": 0.25345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOGProject",
      "product": "fogproject",
      "cwe": "CWE-79",
      "title": "FOGProject has stored XSS via unescaped inventory data in buildRow() rendered on Group Inventory tab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47689"
    },
    {
      "rank": 645,
      "cve_id": "CVE-2026-60898",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Warehouse Management",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Warehouse Management. Successful attacks of this vulnerability can result in takeover of Oracle Warehouse Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60898"
    },
    {
      "rank": 646,
      "cve_id": "CVE-2026-60578",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Command Center Framework",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. While the vulnerability is in Oracle Enterprise Command Center Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Command Center Framework accessible data as well as unauthorized update, insert or delete access to some of Oracle Enterprise Command Center Framework accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60578"
    },
    {
      "rank": 647,
      "cve_id": "CVE-2026-61325",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Advanced Benefits",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Internal Operations). The supported version that is affected is 12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits. While the vulnerability is in Oracle Advanced Benefits, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Benefits accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Benefits accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61325"
    },
    {
      "rank": 648,
      "cve_id": "CVE-2026-62515",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Advanced Planning Command Center",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Advanced Planning Command Center product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Advanced Planning Command Center. While the vulnerability is in Oracle Advanced Planning Command Center, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Planning Command Center accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Planning Command Center accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62515"
    },
    {
      "rank": 649,
      "cve_id": "CVE-2026-60270",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.25222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Coherence accessible data as well as unauthorized update, insert or delete access to some of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60270"
    },
    {
      "rank": 650,
      "cve_id": "CVE-2026-60156",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.25235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle APEX",
      "cwe": "CWE-200",
      "title": "Vulnerability in Oracle APEX (component: General). Supported versions that are affected are 24.1, 24.2 and 26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle APEX. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle APEX accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60156"
    },
    {
      "rank": 651,
      "cve_id": "CVE-2026-60237",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.25179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60237"
    },
    {
      "rank": 652,
      "cve_id": "CVE-2026-60260",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.2518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60260"
    },
    {
      "rank": 653,
      "cve_id": "CVE-2026-60283",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.2518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60283"
    },
    {
      "rank": 654,
      "cve_id": "CVE-2026-60394",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.25179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle GoldenGate",
      "cwe": "CWE-200",
      "title": "Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle GoldenGate accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60394"
    },
    {
      "rank": 655,
      "cve_id": "CVE-2026-60611",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.25179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Campus Community",
      "cwe": "CWE-200",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60611"
    },
    {
      "rank": 656,
      "cve_id": "CVE-2026-47008",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.25162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: InnoDB). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47008"
    },
    {
      "rank": 657,
      "cve_id": "CVE-2026-47023",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.25208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47023"
    },
    {
      "rank": 658,
      "cve_id": "CVE-2026-61128",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.25162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61128"
    },
    {
      "rank": 659,
      "cve_id": "CVE-2026-21575",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.25068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Atlassian",
      "product": "Sourcetree for Mac",
      "cwe": "CWE-94",
      "title": "This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Sourcetree for Mac and Sourcetree for Windows customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.13 See the release notes (https://www.sourcetreeapp.com/download-archives). You can download the latest version of Sourcetree for Mac and Sourcetree for Windows from the download center (https://www.sourcetreeapp.com/download-archives). This vulnerability was reported via our Bug Bounty program.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21575"
    },
    {
      "rank": 660,
      "cve_id": "CVE-2026-16374",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-200",
      "title": "Information disclosure in the Framework component in DevTools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16374"
    },
    {
      "rank": 661,
      "cve_id": "CVE-2026-16391",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.25099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-200",
      "title": "Information disclosure in the Storage: IndexedDB component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16391"
    },
    {
      "rank": 662,
      "cve_id": "CVE-2026-59850",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.25119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-416",
      "title": "Libssh: libssh: use-after-free via data callbacks on closed channels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59850"
    },
    {
      "rank": 663,
      "cve_id": "CVE-2026-61192",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00322,
      "epss_percentile": 0.25143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Engineering Data Management",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61192"
    },
    {
      "rank": 664,
      "cve_id": "CVE-2026-60326",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00321,
      "epss_percentile": 0.24983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Access Manager",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Access Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60326"
    },
    {
      "rank": 665,
      "cve_id": "CVE-2026-60327",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00321,
      "epss_percentile": 0.24983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Access Manager",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60327"
    },
    {
      "rank": 666,
      "cve_id": "CVE-2026-60584",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00321,
      "epss_percentile": 0.24948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Transportation Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: CSV Management). The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Transportation Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Transportation Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Transportation Management. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60584"
    },
    {
      "rank": 667,
      "cve_id": "CVE-2026-60320",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00321,
      "epss_percentile": 0.24983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Data Integrator",
      "cwe": "CWE-863",
      "title": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Data Integrator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60320"
    },
    {
      "rank": 668,
      "cve_id": "CVE-2026-60704",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00321,
      "epss_percentile": 0.24953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60704"
    },
    {
      "rank": 669,
      "cve_id": "CVE-2026-47237",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kubeflow",
      "product": "community-distribution",
      "cwe": "CWE-266",
      "title": "Kubeflow Community Distribution: Overly Permissive Istio Permissions Allows Kubeflow Authorization Token Stealing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47237"
    },
    {
      "rank": 670,
      "cve_id": "CVE-2026-61012",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Time and Labor",
      "cwe": "CWE-863",
      "title": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Time and Labor. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61012"
    },
    {
      "rank": 671,
      "cve_id": "CVE-2026-61119",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (UK)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HRMS (UK) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HRMS (UK). CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61119"
    },
    {
      "rank": 672,
      "cve_id": "CVE-2026-60448",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60448"
    },
    {
      "rank": 673,
      "cve_id": "CVE-2026-60597",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Cash Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Cash Management product of Oracle PeopleSoft (component: Cash Management). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Cash Management. While the vulnerability is in PeopleSoft Enterprise FIN Cash Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Cash Management accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Cash Management accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60597"
    },
    {
      "rank": 674,
      "cve_id": "CVE-2026-60281",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Coherence executes to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60281"
    },
    {
      "rank": 675,
      "cve_id": "CVE-2026-46943",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Retail EFTLink",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Core/Plugin). Supported versions that are affected are 21.0.0-25.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Retail EFTLink. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Retail EFTLink accessible data as well as unauthorized access to critical data or complete access to all Oracle Retail EFTLink accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46943"
    },
    {
      "rank": 676,
      "cve_id": "CVE-2026-60725",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Router",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Router. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Router accessible data as well as unauthorized access to critical data or complete access to all MySQL Router accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60725"
    },
    {
      "rank": 677,
      "cve_id": "CVE-2026-61113",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Object Library",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Application Object Library accessible data as well as unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61113"
    },
    {
      "rank": 678,
      "cve_id": "CVE-2026-61135",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61135"
    },
    {
      "rank": 679,
      "cve_id": "CVE-2026-61164",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61164"
    },
    {
      "rank": 680,
      "cve_id": "CVE-2026-61173",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61173"
    },
    {
      "rank": 681,
      "cve_id": "CVE-2026-61210",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise SCM Manufacturing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise SCM Manufacturing product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise SCM Manufacturing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Manufacturing accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Manufacturing accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61210"
    },
    {
      "rank": 682,
      "cve_id": "CVE-2026-61234",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Common Objects Brazil",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Common Objects Brazil accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Brazil accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61234"
    },
    {
      "rank": 683,
      "cve_id": "CVE-2026-47003",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00317,
      "epss_percentile": 0.24527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47003"
    },
    {
      "rank": 684,
      "cve_id": "CVE-2026-60348",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00317,
      "epss_percentile": 0.24529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle JDeveloper",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60348"
    },
    {
      "rank": 685,
      "cve_id": "CVE-2026-60189",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00317,
      "epss_percentile": 0.24604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60189"
    },
    {
      "rank": 686,
      "cve_id": "CVE-2026-16390",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00316,
      "epss_percentile": 0.24375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "title": "Mitigation bypass in the Enterprise Policies component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16390"
    },
    {
      "rank": 687,
      "cve_id": "CVE-2026-16493",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-88",
      "title": "Ansible-core: argument injection in ansible-galaxy collection install via git clone (incomplete fix for cve-2026-11332)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16493"
    },
    {
      "rank": 688,
      "cve_id": "CVE-2026-16411",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00315,
      "epss_percentile": 0.24366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Memory safety bugs fixed in Firefox 153",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16411"
    },
    {
      "rank": 689,
      "cve_id": "CVE-2026-59847",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.24236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-253",
      "title": "Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59847"
    },
    {
      "rank": 690,
      "cve_id": "CVE-2026-15789",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.24236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moby",
      "product": "BuildKit",
      "cwe": "CWE-22",
      "title": "Malicious client can bypass destination directory validation on local sources upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15789"
    },
    {
      "rank": 691,
      "cve_id": "CVE-2026-62503",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.24223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Time and Labor",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data as well as unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Time and Labor. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62503"
    },
    {
      "rank": 692,
      "cve_id": "CVE-2026-60805",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.2421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Cost Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Cost Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Cost Management. CVSS 3.1 Base Score 6.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60805"
    },
    {
      "rank": 693,
      "cve_id": "CVE-2026-60888",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.24234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Work in Process",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Work in Process accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60888"
    },
    {
      "rank": 694,
      "cve_id": "CVE-2026-65048",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.2408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Saturday Drive",
      "product": "Ninja Forms",
      "cwe": "CWE-79",
      "title": "Ninja Forms Unauthenticated Stored Cross-Site Scripting via Repeatable Fieldset Submission Index",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65048"
    },
    {
      "rank": 695,
      "cve_id": "CVE-2026-60213",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.24099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence as well as unauthorized update, insert or delete access to some of Oracle Coherence accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60213"
    },
    {
      "rank": 696,
      "cve_id": "CVE-2026-59848",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.24158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-770",
      "title": "Libssh: libssh: denial of service via sftp responses with unknown request ids",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59848"
    },
    {
      "rank": 697,
      "cve_id": "CVE-2026-60770",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.2394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Object Library",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in takeover of Oracle Application Object Library. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60770"
    },
    {
      "rank": 698,
      "cve_id": "CVE-2026-61141",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.2394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Advanced Benefits",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Affordable Care Act). Supported versions that are affected are 12.2.7-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Benefits. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61141"
    },
    {
      "rank": 699,
      "cve_id": "CVE-2026-60651",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60651"
    },
    {
      "rank": 700,
      "cve_id": "CVE-2026-47033",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Contracts Integration",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. While the vulnerability is in Oracle Contracts Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Contracts Integration. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47033"
    },
    {
      "rank": 701,
      "cve_id": "CVE-2026-60295",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60295"
    },
    {
      "rank": 702,
      "cve_id": "CVE-2026-60330",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60330"
    },
    {
      "rank": 703,
      "cve_id": "CVE-2026-61312",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Product Hub",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. While the vulnerability is in Oracle Product Hub, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61312"
    },
    {
      "rank": 704,
      "cve_id": "CVE-2026-16384",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-908",
      "title": "Information disclosure due to uninitialized memory in the Graphics: WebGPU component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16384"
    },
    {
      "rank": 705,
      "cve_id": "CVE-2026-16385",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-908",
      "title": "Information disclosure due to uninitialized memory in the Graphics: WebGPU component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16385"
    },
    {
      "rank": 706,
      "cve_id": "CVE-2026-16386",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-908",
      "title": "Information disclosure due to uninitialized memory in the Graphics: WebGPU component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16386"
    },
    {
      "rank": 707,
      "cve_id": "CVE-2026-46941",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Cost Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Maintenance). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46941"
    },
    {
      "rank": 708,
      "cve_id": "CVE-2026-60495",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Requirements Planning",
      "cwe": "CWE-306",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Requirements Planning product of Oracle JD Edwards (component: Requirements Planning). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Requirements Planning. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Requirements Planning. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60495"
    },
    {
      "rank": 709,
      "cve_id": "CVE-2026-60496",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Advanced Pricing - Procurement",
      "cwe": "CWE-306",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Advanced Pricing - Procurement product of Oracle JD Edwards (component: Advanced Pricing). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Advanced Pricing - Procurement. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Advanced Pricing - Procurement. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60496"
    },
    {
      "rank": 710,
      "cve_id": "CVE-2026-60497",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne CRM Foundation",
      "cwe": "CWE-306",
      "title": "Vulnerability in the JD Edwards EnterpriseOne CRM Foundation product of Oracle JD Edwards (component: CRM Foundation). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne CRM Foundation. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne CRM Foundation. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60497"
    },
    {
      "rank": 711,
      "cve_id": "CVE-2026-60498",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Human Resources Management",
      "cwe": "CWE-306",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Human Resources Management. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Human Resources Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60498"
    },
    {
      "rank": 712,
      "cve_id": "CVE-2026-60598",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Student Records",
      "cwe": "CWE-287",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Student Records. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60598"
    },
    {
      "rank": 713,
      "cve_id": "CVE-2026-60604",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Campus Community",
      "cwe": "CWE-306",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Campus Community. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60604"
    },
    {
      "rank": 714,
      "cve_id": "CVE-2026-60619",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne HCM Foundation",
      "cwe": "CWE-269",
      "title": "Vulnerability in the JD Edwards EnterpriseOne HCM Foundation product of Oracle JD Edwards (component: Time Accounting and HRM Base). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne HCM Foundation. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne HCM Foundation. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60619"
    },
    {
      "rank": 715,
      "cve_id": "CVE-2026-60806",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Cost Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Costing Transaction Errors). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60806"
    },
    {
      "rank": 716,
      "cve_id": "CVE-2026-61114",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Object Library",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: DB Privileges). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in takeover of Oracle Application Object Library. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61114"
    },
    {
      "rank": 717,
      "cve_id": "CVE-2026-61188",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Product Lifecycle Management for Process",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The supported version that is affected is 6.2.4. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61188"
    },
    {
      "rank": 718,
      "cve_id": "CVE-2026-61337",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Lease and Finance Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.11-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Lease and Finance Management. Successful attacks of this vulnerability can result in takeover of Oracle Lease and Finance Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61337"
    },
    {
      "rank": 719,
      "cve_id": "CVE-2026-60349",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00311,
      "epss_percentile": 0.23838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle JDeveloper",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Java Business Objects). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle JDeveloper. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60349"
    },
    {
      "rank": 720,
      "cve_id": "CVE-2026-16361",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00309,
      "epss_percentile": 0.23638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Memory safety bugs fixed in Thunderbird ESR 140.13",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16361"
    },
    {
      "rank": 721,
      "cve_id": "CVE-2026-16370",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00309,
      "epss_percentile": 0.23595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "title": "Mitigation bypass in the DOM: Networking component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16370"
    },
    {
      "rank": 722,
      "cve_id": "CVE-2026-16380",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00309,
      "epss_percentile": 0.23595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "title": "Mitigation bypass in the Networking component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16380"
    },
    {
      "rank": 723,
      "cve_id": "CVE-2026-60438",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00307,
      "epss_percentile": 0.23407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HTTP Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_ssl). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60438"
    },
    {
      "rank": 724,
      "cve_id": "CVE-2026-60567",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00307,
      "epss_percentile": 0.23405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60567"
    },
    {
      "rank": 725,
      "cve_id": "CVE-2026-61238",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00307,
      "epss_percentile": 0.23408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Common Objects Argentina",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Common Objects Argentina accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Argentina accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61238"
    },
    {
      "rank": 726,
      "cve_id": "CVE-2026-61244",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00307,
      "epss_percentile": 0.23407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Manufacturing Argentina",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Argentina product of Oracle PeopleSoft (component: Manufacturing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Manufacturing Argentina. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Manufacturing Argentina accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Manufacturing Argentina accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61244"
    },
    {
      "rank": 727,
      "cve_id": "CVE-2026-63764",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InternLM",
      "product": "lmdeploy",
      "cwe": "CWE-918",
      "title": "LMDeploy Server-Side Request Forgery via HTTP Redirect Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63764"
    },
    {
      "rank": 728,
      "cve_id": "CVE-2026-35287",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Testing Suite",
      "cwe": "CWE-284",
      "title": "Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Testing Suite accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35287"
    },
    {
      "rank": 729,
      "cve_id": "CVE-2026-61232",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Common Objects Brazil",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Brazil accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61232"
    },
    {
      "rank": 730,
      "cve_id": "CVE-2026-61236",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Common Objects Brazil",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Brazil accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61236"
    },
    {
      "rank": 731,
      "cve_id": "CVE-2026-16364",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00306,
      "epss_percentile": 0.23319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Incorrect boundary conditions in the Audio/Video: Playback component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16364"
    },
    {
      "rank": 732,
      "cve_id": "CVE-2026-61205",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00306,
      "epss_percentile": 0.23288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise SCM Purchasing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Purchasing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Purchasing accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise SCM Purchasing accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61205"
    },
    {
      "rank": 733,
      "cve_id": "CVE-2026-16378",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00306,
      "epss_percentile": 0.2332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-20",
      "title": "Other issue in the DOM: Copy & Paste and Drag & Drop component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16378"
    },
    {
      "rank": 734,
      "cve_id": "CVE-2026-46984",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00306,
      "epss_percentile": 0.23288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46984"
    },
    {
      "rank": 735,
      "cve_id": "CVE-2026-46986",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00306,
      "epss_percentile": 0.23288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46986"
    },
    {
      "rank": 736,
      "cve_id": "CVE-2026-60342",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00306,
      "epss_percentile": 0.23288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Access Manager",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Access Manager accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60342"
    },
    {
      "rank": 737,
      "cve_id": "CVE-2026-47059",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00306,
      "epss_percentile": 0.23266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47059"
    },
    {
      "rank": 738,
      "cve_id": "CVE-2026-16410",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00305,
      "epss_percentile": 0.23221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-843",
      "title": "JIT miscompilation in the JavaScript Engine: JIT component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16410"
    },
    {
      "rank": 739,
      "cve_id": "CVE-2026-47013",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00305,
      "epss_percentile": 0.23216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE",
      "cwe": "CWE-770",
      "title": "Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47013"
    },
    {
      "rank": 740,
      "cve_id": "CVE-2026-47021",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00305,
      "epss_percentile": 0.23215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47021"
    },
    {
      "rank": 741,
      "cve_id": "CVE-2026-60695",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00304,
      "epss_percentile": 0.23067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Asset Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Asset Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Enterprise Asset Management accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60695"
    },
    {
      "rank": 742,
      "cve_id": "CVE-2026-60801",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00304,
      "epss_percentile": 0.23067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle E-Business Intelligence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle E-Business Intelligence. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Intelligence accessible data as well as unauthorized access to critical data or complete access to all Oracle E-Business Intelligence accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60801"
    },
    {
      "rank": 743,
      "cve_id": "CVE-2026-60534",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.23021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager Connector",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60534"
    },
    {
      "rank": 744,
      "cve_id": "CVE-2026-60399",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00303,
      "epss_percentile": 0.22996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle GoldenGate",
      "cwe": "CWE-400",
      "title": "Vulnerability in Oracle GoldenGate (component: Receiver Service Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60399"
    },
    {
      "rank": 745,
      "cve_id": "CVE-2026-60403",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00303,
      "epss_percentile": 0.22997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "TimesTen In-Memory Database",
      "cwe": "CWE-400",
      "title": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60403"
    },
    {
      "rank": 746,
      "cve_id": "CVE-2026-61108",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00303,
      "epss_percentile": 0.22996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: GIS). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61108"
    },
    {
      "rank": 747,
      "cve_id": "CVE-2026-60562",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00302,
      "epss_percentile": 0.22836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60562"
    },
    {
      "rank": 748,
      "cve_id": "CVE-2026-47708",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00302,
      "epss_percentile": 0.22924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SepineTam",
      "product": "stata-mcp",
      "cwe": "CWE-77",
      "title": "MCP-for-Stata: Command injection via log_file_name parameter in Stata command wrapper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47708"
    },
    {
      "rank": 749,
      "cve_id": "CVE-2026-60400",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle GoldenGate",
      "cwe": "CWE-284",
      "title": "Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60400"
    },
    {
      "rank": 750,
      "cve_id": "CVE-2026-60675",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Applications Framework",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60675"
    },
    {
      "rank": 751,
      "cve_id": "CVE-2026-60381",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00301,
      "epss_percentile": 0.22791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60381"
    },
    {
      "rank": 752,
      "cve_id": "CVE-2026-60402",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00301,
      "epss_percentile": 0.2279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "TimesTen In-Memory Database",
      "cwe": "CWE-284",
      "title": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database. While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of TimesTen In-Memory Database. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60402"
    },
    {
      "rank": 753,
      "cve_id": "CVE-2026-60429",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00301,
      "epss_percentile": 0.22793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60429"
    },
    {
      "rank": 754,
      "cve_id": "CVE-2026-60445",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00301,
      "epss_percentile": 0.22795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60445"
    },
    {
      "rank": 755,
      "cve_id": "CVE-2026-60447",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00301,
      "epss_percentile": 0.22792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60447"
    },
    {
      "rank": 756,
      "cve_id": "CVE-2026-60568",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00301,
      "epss_percentile": 0.22793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60568"
    },
    {
      "rank": 757,
      "cve_id": "CVE-2026-60663",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00301,
      "epss_percentile": 0.22795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60663"
    },
    {
      "rank": 758,
      "cve_id": "CVE-2026-61242",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00301,
      "epss_percentile": 0.2279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Common Objects Argentina",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina. While the vulnerability is in PeopleSoft Enterprise FIN Common Objects Argentina, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Argentina. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61242"
    },
    {
      "rank": 759,
      "cve_id": "CVE-2026-47037",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Access Manager",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). The supported version that is affected is 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47037"
    },
    {
      "rank": 760,
      "cve_id": "CVE-2026-60218",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60218"
    },
    {
      "rank": 761,
      "cve_id": "CVE-2026-60419",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60419"
    },
    {
      "rank": 762,
      "cve_id": "CVE-2026-60423",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.2279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60423"
    },
    {
      "rank": 763,
      "cve_id": "CVE-2026-60464",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebCenter Content: Imaging",
      "cwe": "CWE-287",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60464"
    },
    {
      "rank": 764,
      "cve_id": "CVE-2026-60472",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebCenter Content: Imaging",
      "cwe": "CWE-284",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60472"
    },
    {
      "rank": 765,
      "cve_id": "CVE-2026-60489",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne CRM Foundation",
      "cwe": "CWE-306",
      "title": "Vulnerability in the JD Edwards EnterpriseOne CRM Foundation product of Oracle JD Edwards (component: CRM Foundation). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne CRM Foundation. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne CRM Foundation. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60489"
    },
    {
      "rank": 766,
      "cve_id": "CVE-2026-60490",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne CRM Foundation",
      "cwe": "CWE-284",
      "title": "Vulnerability in the JD Edwards EnterpriseOne CRM Foundation product of Oracle JD Edwards (component: CRM Foundation). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne CRM Foundation. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne CRM Foundation. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60490"
    },
    {
      "rank": 767,
      "cve_id": "CVE-2026-60563",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60563"
    },
    {
      "rank": 768,
      "cve_id": "CVE-2026-60654",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60654"
    },
    {
      "rank": 769,
      "cve_id": "CVE-2026-60681",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Regulatory Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Regulatory Management. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Regulatory Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60681"
    },
    {
      "rank": 770,
      "cve_id": "CVE-2026-61148",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61148"
    },
    {
      "rank": 771,
      "cve_id": "CVE-2026-62464",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payroll",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62464"
    },
    {
      "rank": 772,
      "cve_id": "CVE-2026-61067",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Access Manager",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Access Manager executes to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61067"
    },
    {
      "rank": 773,
      "cve_id": "CVE-2026-60528",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60528"
    },
    {
      "rank": 774,
      "cve_id": "CVE-2026-60467",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebCenter Content: Imaging",
      "cwe": "CWE-601",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60467"
    },
    {
      "rank": 775,
      "cve_id": "CVE-2026-9499",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00301,
      "epss_percentile": 0.22769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qt",
      "product": "Qt",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in QTextCodec::codecForName() in Qt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9499"
    },
    {
      "rank": 776,
      "cve_id": "CVE-2026-61050",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.003,
      "epss_percentile": 0.22694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Production Scheduling",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Production Scheduling. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61050"
    },
    {
      "rank": 777,
      "cve_id": "CVE-2026-16393",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00299,
      "epss_percentile": 0.22548,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Incorrect boundary conditions in the Graphics: WebGPU component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16393"
    },
    {
      "rank": 778,
      "cve_id": "CVE-2026-60945",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00299,
      "epss_percentile": 0.22533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Learning Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Learning Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Learning Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Learning Management accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60945"
    },
    {
      "rank": 779,
      "cve_id": "CVE-2026-60437",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Unified Directory accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 8.7 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60437"
    },
    {
      "rank": 780,
      "cve_id": "CVE-2026-60443",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60443"
    },
    {
      "rank": 781,
      "cve_id": "CVE-2026-60469",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebCenter Content: Imaging",
      "cwe": "CWE-284",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all WebCenter Content: Imaging accessible data as well as unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60469"
    },
    {
      "rank": 782,
      "cve_id": "CVE-2026-60523",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60523"
    },
    {
      "rank": 783,
      "cve_id": "CVE-2026-61078",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CC Common Application Objects",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CC Common Application Objects. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise CC Common Application Objects, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CC Common Application Objects accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise CC Common Application Objects accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61078"
    },
    {
      "rank": 784,
      "cve_id": "CVE-2026-61185",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.22333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Product Lifecycle Management for Process",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile Product Lifecycle Management for Process executes to compromise Oracle Agile Product Lifecycle Management for Process. While the vulnerability is in Oracle Agile Product Lifecycle Management for Process, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile Product Lifecycle Management for Process accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61185"
    },
    {
      "rank": 785,
      "cve_id": "CVE-2026-60346",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00297,
      "epss_percentile": 0.22357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": "CWE-284",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Interoperability Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60346"
    },
    {
      "rank": 786,
      "cve_id": "CVE-2026-47419",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.22199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "praisonai-platform",
      "cwe": "CWE-639",
      "title": "praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47419"
    },
    {
      "rank": 787,
      "cve_id": "CVE-2026-42397",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00296,
      "epss_percentile": 0.2225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42397"
    },
    {
      "rank": 788,
      "cve_id": "CVE-2026-56145",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00296,
      "epss_percentile": 0.2225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-400",
      "title": "Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56145"
    },
    {
      "rank": 789,
      "cve_id": "CVE-2026-60143",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Workflow",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Workflow accessible data as well as unauthorized read access to a subset of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60143"
    },
    {
      "rank": 790,
      "cve_id": "CVE-2026-47046",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.21997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Database Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of RDBMS as well as unauthorized update, insert or delete access to some of RDBMS accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47046"
    },
    {
      "rank": 791,
      "cve_id": "CVE-2026-62518",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.2201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Production Scheduling",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Production Scheduling. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Production Scheduling accessible data as well as unauthorized read access to a subset of Oracle Production Scheduling accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Production Scheduling. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62518"
    },
    {
      "rank": 792,
      "cve_id": "CVE-2026-47690",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.21977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "meltano",
      "product": "hub",
      "cwe": "CWE-77",
      "title": "MeltanoHub vulnerable to command injection in the `test_dispatcher` GitHub Actions workflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47690"
    },
    {
      "rank": 793,
      "cve_id": "CVE-2026-61136",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.22059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Platform accessible data as well as unauthorized read access to a subset of Oracle Commerce Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Platform. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61136"
    },
    {
      "rank": 794,
      "cve_id": "CVE-2026-16362",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the WebRTC: Audio/Video component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16362"
    },
    {
      "rank": 795,
      "cve_id": "CVE-2026-60827",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.2181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iSupport",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iSupport, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iSupport accessible data. CVSS 3.1 Base Score 7.4 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60827"
    },
    {
      "rank": 796,
      "cve_id": "CVE-2026-60424",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.2166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60424"
    },
    {
      "rank": 797,
      "cve_id": "CVE-2026-60273",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60273"
    },
    {
      "rank": 798,
      "cve_id": "CVE-2026-60277",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60277"
    },
    {
      "rank": 799,
      "cve_id": "CVE-2026-60416",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Access Manager",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60416"
    },
    {
      "rank": 800,
      "cve_id": "CVE-2026-60450",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60450"
    },
    {
      "rank": 801,
      "cve_id": "CVE-2026-60462",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.2166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60462"
    },
    {
      "rank": 802,
      "cve_id": "CVE-2026-60670",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Applications Technology Stack",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Client System Analyzer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Technology Stack. Successful attacks of this vulnerability can result in takeover of Oracle Applications Technology Stack. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60670"
    },
    {
      "rank": 803,
      "cve_id": "CVE-2026-60979",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Scripting",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in takeover of Oracle Scripting. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60979"
    },
    {
      "rank": 804,
      "cve_id": "CVE-2026-61137",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.2166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Platform",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61137"
    },
    {
      "rank": 805,
      "cve_id": "CVE-2026-60440",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Service Delivery Platform accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60440"
    },
    {
      "rank": 806,
      "cve_id": "CVE-2026-60705",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60705"
    },
    {
      "rank": 807,
      "cve_id": "CVE-2026-16441",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "OpenJ9",
      "cwe": "CWE-758",
      "title": "Eclipse OpenJ9 : Method resolution default method precedence failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16441"
    },
    {
      "rank": 808,
      "cve_id": "CVE-2026-60812",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Supply Chain Trading Connector",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Supply Chain Trading Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Supply Chain Trading Connector accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60812"
    },
    {
      "rank": 809,
      "cve_id": "CVE-2026-60899",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HCM Configuration Workbench",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Rapid Implementation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HCM Configuration Workbench. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HCM Configuration Workbench accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60899"
    },
    {
      "rank": 810,
      "cve_id": "CVE-2026-62470",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Self-Service Human Resources",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Manager Self-Service). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Self-Service Human Resources. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Self-Service Human Resources accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62470"
    },
    {
      "rank": 811,
      "cve_id": "CVE-2026-47399",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.21577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "praisonai-platform",
      "cwe": "CWE-284",
      "title": "PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47399"
    },
    {
      "rank": 812,
      "cve_id": "CVE-2026-47405",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.21547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "praisonai-platform",
      "cwe": "CWE-284",
      "title": "PraisonAI Platform missing role checks let any workspace member become owner and take over workspace membership",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47405"
    },
    {
      "rank": 813,
      "cve_id": "CVE-2026-59851",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.21563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-863",
      "title": "Libssh: libssh: authentication bypass via missing gssapi principal check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59851"
    },
    {
      "rank": 814,
      "cve_id": "CVE-2026-60395",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.21571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle GoldenGate",
      "cwe": "CWE-200",
      "title": "Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle GoldenGate accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60395"
    },
    {
      "rank": 815,
      "cve_id": "CVE-2026-61292",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.21612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle U.S. Federal Financials",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle U.S. Federal Financials. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle U.S. Federal Financials accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61292"
    },
    {
      "rank": 816,
      "cve_id": "CVE-2026-61315",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.21571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle EDI Gateway",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: EDI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle EDI Gateway. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle EDI Gateway accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61315"
    },
    {
      "rank": 817,
      "cve_id": "CVE-2026-61316",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.21612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle EDI Gateway",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: EDI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle EDI Gateway. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle EDI Gateway accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61316"
    },
    {
      "rank": 818,
      "cve_id": "CVE-2026-47418",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21464,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "praisonai-platform",
      "cwe": "CWE-639",
      "title": "praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47418"
    },
    {
      "rank": 819,
      "cve_id": "CVE-2026-46917",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46917"
    },
    {
      "rank": 820,
      "cve_id": "CVE-2026-47027",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE",
      "cwe": "CWE-284",
      "title": "Vulnerability in Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47027"
    },
    {
      "rank": 821,
      "cve_id": "CVE-2026-16409",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.21381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-824",
      "title": "Invalid pointer in the Security: PSM component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16409"
    },
    {
      "rank": 822,
      "cve_id": "CVE-2026-61267",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.2139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HCM Configuration Workbench",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HCM Configuration Workbench. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HCM Configuration Workbench accessible data as well as unauthorized read access to a subset of Oracle HCM Configuration Workbench accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HCM Configuration Workbench. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61267"
    },
    {
      "rank": 823,
      "cve_id": "CVE-2026-61271",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.2139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Document Management and Collaboration",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Attachments). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Document Management and Collaboration. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Document Management and Collaboration accessible data as well as unauthorized read access to a subset of Oracle Document Management and Collaboration accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Document Management and Collaboration. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61271"
    },
    {
      "rank": 824,
      "cve_id": "CVE-2026-60774",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.21322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Applications Framework",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean [Incl. Advanced]). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data as well as unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60774"
    },
    {
      "rank": 825,
      "cve_id": "CVE-2026-60799",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.21323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Compensation Workbench",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Compensation Workbench. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Compensation Workbench accessible data as well as unauthorized update, insert or delete access to some of Oracle Compensation Workbench accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60799"
    },
    {
      "rank": 826,
      "cve_id": "CVE-2026-60870",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.21322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Advanced Pricing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Pricing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Pricing accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Pricing accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60870"
    },
    {
      "rank": 827,
      "cve_id": "CVE-2026-60908",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.21323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Installed Base",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Installed Base accessible data as well as unauthorized update, insert or delete access to some of Oracle Installed Base accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60908"
    },
    {
      "rank": 828,
      "cve_id": "CVE-2026-60420",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data as well as unauthorized update, insert or delete access to some of Oracle Unified Directory accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60420"
    },
    {
      "rank": 829,
      "cve_id": "CVE-2026-60444",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60444"
    },
    {
      "rank": 830,
      "cve_id": "CVE-2026-60452",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebCenter Content: Imaging",
      "cwe": "CWE-284",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. While the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data as well as unauthorized update, insert or delete access to some of WebCenter Content: Imaging accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60452"
    },
    {
      "rank": 831,
      "cve_id": "CVE-2026-60641",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Content. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60641"
    },
    {
      "rank": 832,
      "cve_id": "CVE-2026-60451",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebCenter Content: Imaging",
      "cwe": "CWE-284",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data as well as unauthorized update, insert or delete access to some of WebCenter Content: Imaging accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60451"
    },
    {
      "rank": 833,
      "cve_id": "CVE-2026-60577",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Command Center Framework",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Command Center Framework accessible data as well as unauthorized update, insert or delete access to some of Oracle Enterprise Command Center Framework accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60577"
    },
    {
      "rank": 834,
      "cve_id": "CVE-2026-60800",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Compensation Workbench",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Compensation Workbench. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Compensation Workbench accessible data as well as unauthorized update, insert or delete access to some of Oracle Compensation Workbench accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60800"
    },
    {
      "rank": 835,
      "cve_id": "CVE-2026-61095",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Communications Unified Inventory Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security). Supported versions that are affected are 7.5.0, 7.5.1, 7.6.0, 7.7.0, 7.8.0 and 8.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Unified Inventory Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Communications Unified Inventory Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61095"
    },
    {
      "rank": 836,
      "cve_id": "CVE-2026-61151",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61151"
    },
    {
      "rank": 837,
      "cve_id": "CVE-2026-61299",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Logistics",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Logistics. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Process Manufacturing Logistics accessible data as well as unauthorized update, insert or delete access to some of Oracle Process Manufacturing Logistics accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61299"
    },
    {
      "rank": 838,
      "cve_id": "CVE-2026-60147",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.21274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60147"
    },
    {
      "rank": 839,
      "cve_id": "CVE-2026-60304",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.21302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60304"
    },
    {
      "rank": 840,
      "cve_id": "CVE-2026-60303",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.2126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Coherence. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60303"
    },
    {
      "rank": 841,
      "cve_id": "CVE-2026-62546",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00285,
      "epss_percentile": 0.21123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Applications Framework",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Framework. While the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62546"
    },
    {
      "rank": 842,
      "cve_id": "CVE-2026-46998",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00285,
      "epss_percentile": 0.21102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-601",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46998"
    },
    {
      "rank": 843,
      "cve_id": "CVE-2026-15927",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.21063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Quay 3.1",
      "cwe": "CWE-918",
      "title": "Quay: mirror-registry: ssrf: repo-level mirror accepts external_reference without url validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15927"
    },
    {
      "rank": 844,
      "cve_id": "CVE-2026-47409",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.21022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "praisonai-platform",
      "cwe": "CWE-269",
      "title": "praisonai-platform: Any workspace member can remove any other member (including the owner) via DELETE /workspaces/{id}/members/{user_id}",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47409"
    },
    {
      "rank": 845,
      "cve_id": "CVE-2026-47412",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.21022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "praisonai-platform",
      "cwe": "CWE-269",
      "title": "praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47412"
    },
    {
      "rank": 846,
      "cve_id": "CVE-2026-46681",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.20974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nevware21",
      "product": "ts-utils",
      "cwe": "CWE-1321",
      "title": "@nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for...in without hasOwnProperty",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46681"
    },
    {
      "rank": 847,
      "cve_id": "CVE-2026-60190",
      "cvss_base": 2.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00284,
      "epss_percentile": 0.21016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 2.2 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60190"
    },
    {
      "rank": 848,
      "cve_id": "CVE-2026-16424",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16424"
    },
    {
      "rank": 849,
      "cve_id": "CVE-2026-65051",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00283,
      "epss_percentile": 0.20827,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Saturday Drive",
      "product": "Ninja Forms",
      "cwe": "CWE-602",
      "title": "Ninja Forms Server-Side Validation Bypass via Client-Controlled Field Metadata Merge in AJAX Submission Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65051"
    },
    {
      "rank": 850,
      "cve_id": "CVE-2026-28315",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00283,
      "epss_percentile": 0.20893,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolarWinds",
      "product": "Serv-U",
      "cwe": "CWE-79",
      "title": "SolarWinds Serv-U Authenticated Stored Cross-site Scripting (XSS) Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28315"
    },
    {
      "rank": 851,
      "cve_id": "CVE-2025-68640",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00283,
      "epss_percentile": 0.20897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-287",
      "title": "The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices and remove offline devices from an Apple ID account without triggering two-factor authentication or ownership verification. This may result in unauthorized removal of devices associated with the account.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68640"
    },
    {
      "rank": 852,
      "cve_id": "CVE-2026-61044",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Production Scheduling",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Production Scheduling. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Production Scheduling accessible data as well as unauthorized read access to a subset of Oracle Production Scheduling accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Production Scheduling. CVSS 3.1 Base Score 4.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61044"
    },
    {
      "rank": 853,
      "cve_id": "CVE-2026-60936",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00282,
      "epss_percentile": 0.20778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Labor Distribution",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Labor Distribution. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60936"
    },
    {
      "rank": 854,
      "cve_id": "CVE-2026-61048",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00282,
      "epss_percentile": 0.20744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Inventory Optimization",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Oracle Inventory Optimization product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Inventory Optimization. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Inventory Optimization. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61048"
    },
    {
      "rank": 855,
      "cve_id": "CVE-2026-60852",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Lease and Finance Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Lease and Finance Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Lease and Finance Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Lease and Finance Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60852"
    },
    {
      "rank": 856,
      "cve_id": "CVE-2026-60857",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Contracts Integration",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Contracts Integration accessible data as well as unauthorized access to critical data or complete access to all Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60857"
    },
    {
      "rank": 857,
      "cve_id": "CVE-2026-60325",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Access Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Access Manager executes to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60325"
    },
    {
      "rank": 858,
      "cve_id": "CVE-2026-61324",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Advanced Benefits",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Internal Operations). The supported version that is affected is 12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits. While the vulnerability is in Oracle Advanced Benefits, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Benefits accessible data. CVSS 3.1 Base Score 7.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61324"
    },
    {
      "rank": 859,
      "cve_id": "CVE-2026-47039",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Database Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java VM accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47039"
    },
    {
      "rank": 860,
      "cve_id": "CVE-2026-47415",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "praisonai-platform",
      "cwe": "CWE-639",
      "title": "praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47415"
    },
    {
      "rank": 861,
      "cve_id": "CVE-2026-60581",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Command Center Framework",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Enterprise Command Center Framework executes to compromise Oracle Enterprise Command Center Framework. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60581"
    },
    {
      "rank": 862,
      "cve_id": "CVE-2026-13693",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Bit Form",
      "cwe": "CWE-22",
      "title": "Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13693"
    },
    {
      "rank": 863,
      "cve_id": "CVE-2026-46968",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE",
      "cwe": "CWE-284",
      "title": "Vulnerability in Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46968"
    },
    {
      "rank": 864,
      "cve_id": "CVE-2026-60422",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00279,
      "epss_percentile": 0.20477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). The supported version that is affected is 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Unified Directory accessible data as well as unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60422"
    },
    {
      "rank": 865,
      "cve_id": "CVE-2026-16407",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00279,
      "epss_percentile": 0.20426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-284",
      "title": "Mitigation bypass in the DOM: Service Workers component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16407"
    },
    {
      "rank": 866,
      "cve_id": "CVE-2026-60677",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Common Application Components",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Common Application Components product of Oracle E-Business Suite (component: Oracle Common Modules). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Application Components. While the vulnerability is in Oracle Common Application Components, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Common Application Components accessible data as well as unauthorized access to critical data or complete access to all Oracle Common Application Components accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Common Application Components. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60677"
    },
    {
      "rank": 867,
      "cve_id": "CVE-2026-62473",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Installed Base",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Installed Base accessible data as well as unauthorized access to critical data or complete access to all Oracle Installed Base accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Installed Base. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62473"
    },
    {
      "rank": 868,
      "cve_id": "CVE-2026-46923",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Public Sector Financials (International)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials (International). While the vulnerability is in Oracle Public Sector Financials (International), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Financials (International). CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46923"
    },
    {
      "rank": 869,
      "cve_id": "CVE-2026-64627",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00279,
      "epss_percentile": 0.20423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "parse-community",
      "product": "parse-server",
      "cwe": "CWE-209",
      "title": "Parse Server 9.0.0 Schema Disclosure via GraphQL Variable Coercion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64627"
    },
    {
      "rank": 870,
      "cve_id": "CVE-2026-61279",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00279,
      "epss_percentile": 0.20476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Proposals",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (component: Proposals). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Proposals. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Proposals accessible data as well as unauthorized read access to a subset of Oracle Proposals accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Proposals. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61279"
    },
    {
      "rank": 871,
      "cve_id": "CVE-2026-65058",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00279,
      "epss_percentile": 0.20487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trezor",
      "product": "Safe 3",
      "cwe": "CWE-358",
      "title": "Trezor Safe improper security check in on-device display",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65058"
    },
    {
      "rank": 872,
      "cve_id": "CVE-2026-16371",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "title": "Privilege escalation in the DOM: Navigation component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16371"
    },
    {
      "rank": 873,
      "cve_id": "CVE-2026-16379",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "title": "Privilege escalation in the DOM: Content Processes component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16379"
    },
    {
      "rank": 874,
      "cve_id": "CVE-2026-60701",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Universal Work Queue",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60701"
    },
    {
      "rank": 875,
      "cve_id": "CVE-2026-60571",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle SDP Number Portability",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Installation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SDP Number Portability. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle SDP Number Portability accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle SDP Number Portability. CVSS 3.1 Base Score 5.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60571"
    },
    {
      "rank": 876,
      "cve_id": "CVE-2026-3182",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine Endpoint Central",
      "cwe": "CWE-319",
      "title": "Sensitive Data Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3182"
    },
    {
      "rank": 877,
      "cve_id": "CVE-2026-11767",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Free Theme Builder for Elementor",
      "cwe": "CWE-79",
      "title": "CRT Addons for Elementor < 1.6.7 - Unauthenticated Stored XSS via Contact Form",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11767"
    },
    {
      "rank": 878,
      "cve_id": "CVE-2026-8989",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autel",
      "product": "MaxiCharger Single",
      "cwe": "CWE-1191",
      "title": "Open Recovery Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8989"
    },
    {
      "rank": 879,
      "cve_id": "CVE-2026-65049",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.19921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Saturday Drive",
      "product": "Ninja Forms",
      "cwe": "CWE-863",
      "title": "Ninja Forms Cross-Site Network-Wide Data Deletion on WordPress Multisite via nf_delete_all_data AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65049"
    },
    {
      "rank": 880,
      "cve_id": "CVE-2026-60410",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.19847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "TimesTen In-Memory Database",
      "cwe": "CWE-400",
      "title": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of TimesTen In-Memory Database. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60410"
    },
    {
      "rank": 881,
      "cve_id": "CVE-2026-16450",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00274,
      "epss_percentile": 0.19875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zsadmin2025",
      "product": "ZS-Admin",
      "cwe": "CWE-285",
      "title": "zsadmin2025 ZS-Admin MyBatis-Plus Tenant Plugin page getTenantId authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16450"
    },
    {
      "rank": 882,
      "cve_id": "CVE-2026-62549",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00273,
      "epss_percentile": 0.19798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (UK)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). While the vulnerability is in Oracle HRMS (UK), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HRMS (UK) accessible data as well as unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62549"
    },
    {
      "rank": 883,
      "cve_id": "CVE-2026-60323",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60323"
    },
    {
      "rank": 884,
      "cve_id": "CVE-2026-62514",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Regulatory Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Regulatory Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Regulatory Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Regulatory Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62514"
    },
    {
      "rank": 885,
      "cve_id": "CVE-2026-47045",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00273,
      "epss_percentile": 0.19751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Database Server",
      "cwe": "CWE-601",
      "title": "Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows high privileged attacker having None privilege with network access via Oracle Net to compromise JDBC. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of JDBC. CVSS 3.1 Base Score 6.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47045"
    },
    {
      "rank": 886,
      "cve_id": "CVE-2026-16485",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.19739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-79",
      "title": "SourceCodester Class and Exam Timetabling System class.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16485"
    },
    {
      "rank": 887,
      "cve_id": "CVE-2026-16486",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.19738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-79",
      "title": "SourceCodester Class and Exam Timetabling System BSIS.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16486"
    },
    {
      "rank": 888,
      "cve_id": "CVE-2026-16372",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "title": "Privilege escalation in the DOM: Content Processes component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16372"
    },
    {
      "rank": 889,
      "cve_id": "CVE-2026-16373",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-200",
      "title": "Information disclosure in the Privacy component in Firefox for Android",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16373"
    },
    {
      "rank": 890,
      "cve_id": "CVE-2026-47026",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PeopleTools",
      "cwe": "CWE-601",
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47026"
    },
    {
      "rank": 891,
      "cve_id": "CVE-2026-47687",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.19416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOGProject",
      "product": "fogproject",
      "cwe": "CWE-79",
      "title": "FOGProject has stored XSS via unescaped option label in selectForm() accessible from unauthenticated inventory endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47687"
    },
    {
      "rank": 892,
      "cve_id": "CVE-2026-62415",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0027,
      "epss_percentile": 0.19349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomdonation.com",
      "product": "Membership Pro extension for Joomla",
      "cwe": "CWE-1188",
      "title": "Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62415"
    },
    {
      "rank": 893,
      "cve_id": "CVE-2026-46993",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46993"
    },
    {
      "rank": 894,
      "cve_id": "CVE-2026-60525",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60525"
    },
    {
      "rank": 895,
      "cve_id": "CVE-2026-60665",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise HCM Global Payroll Switzerland",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland product of Oracle PeopleSoft (component: Global Payroll for Switzerland). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Global Payroll Switzerland. While the vulnerability is in PeopleSoft Enterprise HCM Global Payroll Switzerland, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise HCM Global Payroll Switzerland accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise HCM Global Payroll Switzerland accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60665"
    },
    {
      "rank": 896,
      "cve_id": "CVE-2026-60629",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle JDeveloper",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Data Visualization Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. While the vulnerability is in Oracle JDeveloper, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data as well as unauthorized update, insert or delete access to some of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60629"
    },
    {
      "rank": 897,
      "cve_id": "CVE-2026-60612",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.1923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Financial Aid",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Commonline Loans). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Financial Aid. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Financial Aid accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Financial Aid accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60612"
    },
    {
      "rank": 898,
      "cve_id": "CVE-2026-60744",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Cost Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Cost Management accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60744"
    },
    {
      "rank": 899,
      "cve_id": "CVE-2026-60795",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iSetup",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSetup. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iSetup accessible data as well as unauthorized access to critical data or complete access to all Oracle iSetup accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60795"
    },
    {
      "rank": 900,
      "cve_id": "CVE-2026-61134",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.1923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61134"
    },
    {
      "rank": 901,
      "cve_id": "CVE-2026-60616",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Campus Community",
      "cwe": "CWE-306",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60616"
    },
    {
      "rank": 902,
      "cve_id": "CVE-2026-63139",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-400",
      "title": "Uncontrolled Resource Consumption in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63139"
    },
    {
      "rank": 903,
      "cve_id": "CVE-2026-63260",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-400",
      "title": "Uncontrolled Resource Consumption in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63260"
    },
    {
      "rank": 904,
      "cve_id": "CVE-2026-63261",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-400",
      "title": "Uncontrolled Resource Consumption in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63261"
    },
    {
      "rank": 905,
      "cve_id": "CVE-2026-61117",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (UK)",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.8-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). While the vulnerability is in Oracle HRMS (UK), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61117"
    },
    {
      "rank": 906,
      "cve_id": "CVE-2026-16365",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "title": "Privilege escalation in the DOM: Workers component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16365"
    },
    {
      "rank": 907,
      "cve_id": "CVE-2026-16366",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "title": "Privilege escalation in the DOM: Navigation component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16366"
    },
    {
      "rank": 908,
      "cve_id": "CVE-2026-60940",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Service Contracts",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Service Contracts. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Service Contracts accessible data as well as unauthorized access to critical data or complete access to all Oracle Service Contracts accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60940"
    },
    {
      "rank": 909,
      "cve_id": "CVE-2026-61239",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00268,
      "epss_percentile": 0.19024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Common Objects Argentina",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina. While the vulnerability is in PeopleSoft Enterprise FIN Common Objects Argentina, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Common Objects Argentina accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise FIN Common Objects Argentina accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Common Objects Argentina. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61239"
    },
    {
      "rank": 910,
      "cve_id": "CVE-2026-55081",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dhis2",
      "product": "dhis2-core",
      "cwe": "CWE-79",
      "title": "DHIS2 Reflected XSS in OpenAPI HTML scope parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55081"
    },
    {
      "rank": 911,
      "cve_id": "CVE-2026-65007",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-862",
      "title": "Grav before 1.0.8 Missing Authorization on API Key Generation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65007"
    },
    {
      "rank": 912,
      "cve_id": "CVE-2026-60582",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Command Center Framework",
      "cwe": "CWE-89",
      "title": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Command Center Framework accessible data as well as unauthorized read access to a subset of Oracle Enterprise Command Center Framework accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60582"
    },
    {
      "rank": 913,
      "cve_id": "CVE-2026-47064",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.1859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47064"
    },
    {
      "rank": 914,
      "cve_id": "CVE-2026-47671",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nhost",
      "product": "cli",
      "cwe": "CWE-306",
      "title": "Nhost CLI local configserver allows cross-origin unauthenticated read/write access to local development configuration and secrets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47671"
    },
    {
      "rank": 915,
      "cve_id": "CVE-2026-60471",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.1853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebCenter Content: Imaging",
      "cwe": "CWE-284",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the WebCenter Content: Imaging executes to compromise WebCenter Content: Imaging. While the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60471"
    },
    {
      "rank": 916,
      "cve_id": "CVE-2026-62516",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.18472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Demantra Demand Management",
      "cwe": "CWE-89",
      "title": "Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Product Security). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Demantra Demand Management. Successful attacks of this vulnerability can result in takeover of Oracle Demantra Demand Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62516"
    },
    {
      "rank": 917,
      "cve_id": "CVE-2026-16359",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00263,
      "epss_percentile": 0.18327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Incorrect boundary conditions in the Audio/Video: GMP component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16359"
    },
    {
      "rank": 918,
      "cve_id": "CVE-2026-60352",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00263,
      "epss_percentile": 0.18354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle JDeveloper",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60352"
    },
    {
      "rank": 919,
      "cve_id": "CVE-2026-60354",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00263,
      "epss_percentile": 0.18355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle JDeveloper",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Data Visualization Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60354"
    },
    {
      "rank": 920,
      "cve_id": "CVE-2026-60919",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00263,
      "epss_percentile": 0.18355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iSupplier Portal",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupplier Portal. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle iSupplier Portal accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60919"
    },
    {
      "rank": 921,
      "cve_id": "CVE-2026-61015",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00263,
      "epss_percentile": 0.18354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Time and Labor",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Time and Labor accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61015"
    },
    {
      "rank": 922,
      "cve_id": "CVE-2026-61104",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00263,
      "epss_percentile": 0.18354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Student Records",
      "cwe": "CWE-200",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise CS Student Records accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61104"
    },
    {
      "rank": 923,
      "cve_id": "CVE-2026-60428",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data as well as unauthorized update, insert or delete access to some of Oracle Unified Directory accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60428"
    },
    {
      "rank": 924,
      "cve_id": "CVE-2026-60674",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Business Intelligence Enterprise Edition",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60674"
    },
    {
      "rank": 925,
      "cve_id": "CVE-2026-60810",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Supply Chain Trading Connector",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Supply Chain Trading Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Supply Chain Trading Connector accessible data as well as unauthorized update, insert or delete access to some of Oracle Supply Chain Trading Connector accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60810"
    },
    {
      "rank": 926,
      "cve_id": "CVE-2026-47014",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Product Workbench",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Security). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Workbench accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Workbench accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47014"
    },
    {
      "rank": 927,
      "cve_id": "CVE-2026-60708",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Financials",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Financials. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Financials accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Financials accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60708"
    },
    {
      "rank": 928,
      "cve_id": "CVE-2026-60732",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iReceivables",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (component: AR Web Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iReceivables. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iReceivables accessible data as well as unauthorized access to critical data or complete access to all Oracle iReceivables accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60732"
    },
    {
      "rank": 929,
      "cve_id": "CVE-2026-60735",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Sales Offline",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Offline. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Sales Offline accessible data as well as unauthorized access to critical data or complete access to all Oracle Sales Offline accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60735"
    },
    {
      "rank": 930,
      "cve_id": "CVE-2026-60740",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Cash Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Cash Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cash Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Cash Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Cash Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60740"
    },
    {
      "rank": 931,
      "cve_id": "CVE-2026-60764",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Financials Common Modules",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financials Common Modules accessible data as well as unauthorized access to critical data or complete access to all Oracle Financials Common Modules accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60764"
    },
    {
      "rank": 932,
      "cve_id": "CVE-2026-61020",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Customers Online",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Customers Online product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customers Online. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Customers Online accessible data as well as unauthorized access to critical data or complete access to all Oracle Customers Online accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61020"
    },
    {
      "rank": 933,
      "cve_id": "CVE-2026-61218",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle E-Business Suite Secure Enterprise Search",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search Integration Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Suite Secure Enterprise Search. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Suite Secure Enterprise Search accessible data as well as unauthorized access to critical data or complete access to all Oracle E-Business Suite Secure Enterprise Search accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61218"
    },
    {
      "rank": 934,
      "cve_id": "CVE-2026-62472",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Installed Base",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.4-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Installed Base accessible data as well as unauthorized access to critical data or complete access to all Oracle Installed Base accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62472"
    },
    {
      "rank": 935,
      "cve_id": "CVE-2026-60824",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iSupport",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSupport. While the vulnerability is in Oracle iSupport, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iSupport accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60824"
    },
    {
      "rank": 936,
      "cve_id": "CVE-2026-8082",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "bpost-shipping-platform",
      "cwe": "CWE-89",
      "title": "Bpost Shipping Platform < 3.2.3 - Unauthenticated SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8082"
    },
    {
      "rank": 937,
      "cve_id": "CVE-2026-61250",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.18097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payroll",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Payroll accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61250"
    },
    {
      "rank": 938,
      "cve_id": "CVE-2026-60427",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.17977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Unified Directory accessible data as well as unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60427"
    },
    {
      "rank": 939,
      "cve_id": "CVE-2026-60553",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.17978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Sites accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60553"
    },
    {
      "rank": 940,
      "cve_id": "CVE-2026-60653",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.18064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60653"
    },
    {
      "rank": 941,
      "cve_id": "CVE-2026-60691",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.18065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Content Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Content Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Content Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Content Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60691"
    },
    {
      "rank": 942,
      "cve_id": "CVE-2026-60710",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.18065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle EDI Gateway",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle EDI Gateway. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle EDI Gateway accessible data as well as unauthorized access to critical data or complete access to all Oracle EDI Gateway accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60710"
    },
    {
      "rank": 943,
      "cve_id": "CVE-2026-60768",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.18063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Applications Framework",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Graph / Charting). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Applications Framework accessible data as well as unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60768"
    },
    {
      "rank": 944,
      "cve_id": "CVE-2026-61150",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.18064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61150"
    },
    {
      "rank": 945,
      "cve_id": "CVE-2026-62451",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.18063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Work in Process",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Work in Process accessible data as well as unauthorized access to critical data or complete access to all Oracle Work in Process accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62451"
    },
    {
      "rank": 946,
      "cve_id": "CVE-2026-46987",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.18066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Application Service Level Mgmt). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46987"
    },
    {
      "rank": 947,
      "cve_id": "CVE-2026-61142",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.18066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payroll",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. While the vulnerability is in Oracle Payroll, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Payroll accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61142"
    },
    {
      "rank": 948,
      "cve_id": "CVE-2026-60823",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.17977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iSupport",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iSupport accessible data as well as unauthorized access to critical data or complete access to all Oracle iSupport accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60823"
    },
    {
      "rank": 949,
      "cve_id": "CVE-2026-60984",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.17976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Project Portfolio Analysis",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Portfolio Analysis accessible data as well as unauthorized read access to a subset of Oracle Project Portfolio Analysis accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60984"
    },
    {
      "rank": 950,
      "cve_id": "CVE-2026-61334",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.17976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Price Protection",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Price Protection. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Price Protection accessible data as well as unauthorized read access to a subset of Oracle Price Protection accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61334"
    },
    {
      "rank": 951,
      "cve_id": "CVE-2026-60687",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle U.S. Federal Financials",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle U.S. Federal Financials. While the vulnerability is in Oracle U.S. Federal Financials, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle U.S. Federal Financials accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60687"
    },
    {
      "rank": 952,
      "cve_id": "CVE-2026-60521",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Advanced Pricing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Price List). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Pricing. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Advanced Pricing accessible data as well as unauthorized read access to a subset of Oracle Advanced Pricing accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60521"
    },
    {
      "rank": 953,
      "cve_id": "CVE-2026-61262",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.17979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Teleservice",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Diagnostics Scripts). Supported versions that are affected are 12.2.3-12.215. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Teleservice. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Teleservice accessible data as well as unauthorized read access to a subset of Oracle Teleservice accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61262"
    },
    {
      "rank": 954,
      "cve_id": "CVE-2026-62556",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (US)",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (US) accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62556"
    },
    {
      "rank": 955,
      "cve_id": "CVE-2026-1617",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Turkmesh Communication Services Inc.",
      "product": "Turkhotspot 5651 Loglama",
      "cwe": "CWE-89",
      "title": "SQLi in Turkmesh's Turkhotspot 5651 Loglama",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1617"
    },
    {
      "rank": 956,
      "cve_id": "CVE-2026-60838",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Price Protection",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Price Protection. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Price Protection accessible data as well as unauthorized read access to a subset of Oracle Price Protection accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60838"
    },
    {
      "rank": 957,
      "cve_id": "CVE-2026-21579",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Atlassian",
      "product": "Confluence Data Center",
      "cwe": "CWE-200",
      "title": "This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Information Disclosure vulnerability, with a CVSS Score of 8.2, allows an unauthenticated attacker to view sensitive information via an Information Disclosure vulnerability. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.22 Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.14 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Atlassian (Internal) program.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21579"
    },
    {
      "rank": 958,
      "cve_id": "CVE-2026-60614",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Campus Community",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Person Data). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Campus Community accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise CS Campus Community. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60614"
    },
    {
      "rank": 959,
      "cve_id": "CVE-2026-61013",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.1773,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Time and Labor",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Time and Labor. While the vulnerability is in Oracle Time and Labor, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data as well as unauthorized update, insert or delete access to some of Oracle Time and Labor accessible data. CVSS 3.1 Base Score 6.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61013"
    },
    {
      "rank": 960,
      "cve_id": "CVE-2026-61294",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Common Applications Calendar",
      "cwe": "CWE-89",
      "title": "Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Calendar Synchronizations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications Calendar. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Common Applications Calendar accessible data as well as unauthorized read access to a subset of Oracle Common Applications Calendar accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Common Applications Calendar. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61294"
    },
    {
      "rank": 961,
      "cve_id": "CVE-2026-61247",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Workflow",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 4.8 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61247"
    },
    {
      "rank": 962,
      "cve_id": "CVE-2026-16336",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "trinodb",
      "product": "trino",
      "cwe": "CWE-601",
      "title": "trinodb trino OAuth2/OIDC ExternalUriInfo.java redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16336"
    },
    {
      "rank": 963,
      "cve_id": "CVE-2026-60166",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00258,
      "epss_percentile": 0.17679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE",
      "cwe": "CWE-693",
      "title": "Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60166"
    },
    {
      "rank": 964,
      "cve_id": "CVE-2026-16413",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16413"
    },
    {
      "rank": 965,
      "cve_id": "CVE-2026-61138",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Complex Maintenance, Repair and Overhaul",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. While the vulnerability is in Oracle Complex Maintenance, Repair and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Complex Maintenance, Repair and Overhaul accessible data as well as unauthorized update, insert or delete access to some of Oracle Complex Maintenance, Repair and Overhaul accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61138"
    },
    {
      "rank": 966,
      "cve_id": "CVE-2026-60317",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Connectors",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60317"
    },
    {
      "rank": 967,
      "cve_id": "CVE-2026-45383",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libde265",
      "cwe": "CWE-125",
      "title": "libde265 has a heap buffer overflow (OOB read) in decode_slice_unit_WPP() via out-of-bounds CtbAddrRStoTS access — libde265 <= v1.0.18",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45383"
    },
    {
      "rank": 968,
      "cve_id": "CVE-2026-16405",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17431,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-200",
      "title": "Information disclosure in the Networking: WebSockets component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16405"
    },
    {
      "rank": 969,
      "cve_id": "CVE-2026-47063",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47063"
    },
    {
      "rank": 970,
      "cve_id": "CVE-2026-16419",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00255,
      "epss_percentile": 0.17294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16419"
    },
    {
      "rank": 971,
      "cve_id": "CVE-2026-16423",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16423"
    },
    {
      "rank": 972,
      "cve_id": "CVE-2026-60214",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Coherence executes to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60214"
    },
    {
      "rank": 973,
      "cve_id": "CVE-2026-60315",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.17123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-200",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster and unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60315"
    },
    {
      "rank": 974,
      "cve_id": "CVE-2026-60522",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.17187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60522"
    },
    {
      "rank": 975,
      "cve_id": "CVE-2026-61181",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.17186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Product Lifecycle Management for Process",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile Product Lifecycle Management for Process, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile Product Lifecycle Management for Process accessible data as well as unauthorized update, insert or delete access to some of Oracle Agile Product Lifecycle Management for Process accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61181"
    },
    {
      "rank": 976,
      "cve_id": "CVE-2026-55084",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.17057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dhis2",
      "product": "dhis2-core",
      "cwe": "CWE-89",
      "title": "SQL Injection in SqlView Filter Parameter Leading to Arbitrary Database Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55084"
    },
    {
      "rank": 977,
      "cve_id": "CVE-2026-61049",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.16968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Production Scheduling",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Production Scheduling executes to compromise Oracle Production Scheduling. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Production Scheduling. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61049"
    },
    {
      "rank": 978,
      "cve_id": "CVE-2026-45382",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libde265",
      "cwe": "CWE-125",
      "title": "libde265 has a heap-buffer-overflow READ in decode_slice_unit_tiles via unvalidated PPS tile geometry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45382"
    },
    {
      "rank": 979,
      "cve_id": "CVE-2026-61069",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN General Ledger Argentina",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN General Ledger Argentina product of Oracle PeopleSoft (component: General Ledger). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN General Ledger Argentina. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN General Ledger Argentina accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN General Ledger Argentina. CVSS 3.1 Base Score 5.9 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61069"
    },
    {
      "rank": 980,
      "cve_id": "CVE-2026-46936",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.1698,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46936"
    },
    {
      "rank": 981,
      "cve_id": "CVE-2026-60188",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.1695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60188"
    },
    {
      "rank": 982,
      "cve_id": "CVE-2026-60950",
      "cvss_base": 2.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00252,
      "epss_percentile": 0.16941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (Ireland)",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle HRMS (Ireland) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Ireland). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle HRMS (Ireland) accessible data. CVSS 3.1 Base Score 2.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60950"
    },
    {
      "rank": 983,
      "cve_id": "CVE-2026-61214",
      "cvss_base": 2.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00252,
      "epss_percentile": 0.16913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (UK)",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 2.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61214"
    },
    {
      "rank": 984,
      "cve_id": "CVE-2026-16394",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00251,
      "epss_percentile": 0.1674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "title": "Mitigation bypass in the DOM: Security component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16394"
    },
    {
      "rank": 985,
      "cve_id": "CVE-2026-65055",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Taiga",
      "product": "taiga-back",
      "cwe": "CWE-862",
      "title": "Taiga taiga-back Private Project Member Roster Disclosure via Unauthenticated filters_data Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65055"
    },
    {
      "rank": 986,
      "cve_id": "CVE-2026-60572",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.1677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle E-Business Suite Integrated SOA Gateway",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle E-Business Suite Integrated SOA Gateway product of Oracle E-Business Suite (component: Web Service Provider). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Suite Integrated SOA Gateway. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle E-Business Suite Integrated SOA Gateway accessible data as well as unauthorized read access to a subset of Oracle E-Business Suite Integrated SOA Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle E-Business Suite Integrated SOA Gateway. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60572"
    },
    {
      "rank": 987,
      "cve_id": "CVE-2026-60575",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Workflow",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Workflow accessible data as well as unauthorized read access to a subset of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60575"
    },
    {
      "rank": 988,
      "cve_id": "CVE-2026-60777",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Object Library",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Object Library accessible data as well as unauthorized read access to a subset of Oracle Application Object Library accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Application Object Library. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60777"
    },
    {
      "rank": 989,
      "cve_id": "CVE-2026-60811",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16773,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Supply Chain Trading Connector",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Supply Chain Trading Connector. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Supply Chain Trading Connector accessible data as well as unauthorized read access to a subset of Oracle Supply Chain Trading Connector accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Supply Chain Trading Connector. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60811"
    },
    {
      "rank": 990,
      "cve_id": "CVE-2026-61216",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16773,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payroll",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Payroll accessible data as well as unauthorized read access to a subset of Oracle Payroll accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Payroll. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61216"
    },
    {
      "rank": 991,
      "cve_id": "CVE-2026-61269",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Product Workbench",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: WebUI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Product Workbench accessible data as well as unauthorized read access to a subset of Oracle Product Workbench accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Product Workbench. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61269"
    },
    {
      "rank": 992,
      "cve_id": "CVE-2026-61278",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Workflow",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Workflow accessible data as well as unauthorized read access to a subset of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61278"
    },
    {
      "rank": 993,
      "cve_id": "CVE-2026-61282",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Advanced Benefits",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self Service Benefits). Supported versions that are affected are 12.2.4-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Advanced Benefits accessible data as well as unauthorized read access to a subset of Oracle Advanced Benefits accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Advanced Benefits. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61282"
    },
    {
      "rank": 994,
      "cve_id": "CVE-2026-61283",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16773,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Bills of Material",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Web Services). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Bills of Material accessible data as well as unauthorized read access to a subset of Oracle Bills of Material accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Bills of Material. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61283"
    },
    {
      "rank": 995,
      "cve_id": "CVE-2026-62519",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Succession planning",
      "cwe": "CWE-20",
      "title": "Vulnerability in the Oracle Succession planning product of Oracle E-Business Suite (component: Succession plan). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Succession planning. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Succession planning accessible data as well as unauthorized read access to a subset of Oracle Succession planning accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Succession planning. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62519"
    },
    {
      "rank": 996,
      "cve_id": "CVE-2026-60617",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Campus Community",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Campus Community accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60617"
    },
    {
      "rank": 997,
      "cve_id": "CVE-2026-60491",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Advanced Inbound Telephony",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: SDK client integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Inbound Telephony. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Advanced Inbound Telephony accessible data as well as unauthorized read access to a subset of Oracle Advanced Inbound Telephony accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Advanced Inbound Telephony. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60491"
    },
    {
      "rank": 998,
      "cve_id": "CVE-2026-60573",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Partner Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Partner Management product of Oracle E-Business Suite (component: Partner Dashboard). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Partner Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Partner Management accessible data as well as unauthorized read access to a subset of Oracle Partner Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Partner Management. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60573"
    },
    {
      "rank": 999,
      "cve_id": "CVE-2026-60574",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Content Manager",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Cover Letter). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Content Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Content Manager accessible data as well as unauthorized read access to a subset of Oracle Content Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Content Manager. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60574"
    },
    {
      "rank": 1000,
      "cve_id": "CVE-2026-60587",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Project Foundation",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Project Definition). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Foundation. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Project Foundation accessible data as well as unauthorized read access to a subset of Oracle Project Foundation accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Project Foundation. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60587"
    },
    {
      "rank": 1001,
      "cve_id": "CVE-2026-60688",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Scheduler",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Scheduler product of Oracle E-Business Suite (component: Rules UI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scheduler. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Scheduler accessible data as well as unauthorized read access to a subset of Oracle Scheduler accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Scheduler. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60688"
    },
    {
      "rank": 1002,
      "cve_id": "CVE-2026-61304",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Price Protection",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Price Protection. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Price Protection accessible data as well as unauthorized read access to a subset of Oracle Price Protection accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Price Protection. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61304"
    },
    {
      "rank": 1003,
      "cve_id": "CVE-2026-47685",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOGProject",
      "product": "fogproject",
      "cwe": "CWE-79",
      "title": "FOGProject has stored XSS via unauthenticated inventory service renders unescaped in Host Management page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47685"
    },
    {
      "rank": 1004,
      "cve_id": "CVE-2023-37507",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "DevOps Plan",
      "cwe": "CWE-497",
      "title": "An information disclosure vulnerability affects HCL DevOps Plan",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-37507"
    },
    {
      "rank": 1005,
      "cve_id": "CVE-2026-10675",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-400",
      "title": "Bluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (re)provisioning (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10675"
    },
    {
      "rank": 1006,
      "cve_id": "CVE-2026-61051",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Concurrent Processing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Concurrent Processing accessible data as well as unauthorized read access to a subset of Oracle Concurrent Processing accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Concurrent Processing. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61051"
    },
    {
      "rank": 1007,
      "cve_id": "CVE-2026-61256",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Advanced Inbound Telephony",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Servers). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Inbound Telephony. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Advanced Inbound Telephony accessible data as well as unauthorized read access to a subset of Oracle Advanced Inbound Telephony accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Advanced Inbound Telephony. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61256"
    },
    {
      "rank": 1008,
      "cve_id": "CVE-2026-61274",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Product Hub",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Product Hub accessible data as well as unauthorized read access to a subset of Oracle Product Hub accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Product Hub. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61274"
    },
    {
      "rank": 1009,
      "cve_id": "CVE-2026-61275",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Product Hub",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Role Based Security). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Product Hub accessible data as well as unauthorized read access to a subset of Oracle Product Hub accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Product Hub. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61275"
    },
    {
      "rank": 1010,
      "cve_id": "CVE-2026-61277",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Marketing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Marketing accessible data as well as unauthorized read access to a subset of Oracle Marketing accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Marketing. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61277"
    },
    {
      "rank": 1011,
      "cve_id": "CVE-2026-61280",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.1656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Sales for Handhelds",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Sales for Handhelds product of Oracle E-Business Suite (component: Outlook Sync Win 32). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales for Handhelds. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Sales for Handhelds accessible data as well as unauthorized read access to a subset of Oracle Sales for Handhelds accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Sales for Handhelds. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61280"
    },
    {
      "rank": 1012,
      "cve_id": "CVE-2026-61036",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00249,
      "epss_percentile": 0.16582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (Norway)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Norway). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (Norway) accessible data as well as unauthorized read access to a subset of Oracle HRMS (Norway) accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61036"
    },
    {
      "rank": 1013,
      "cve_id": "CVE-2026-15791",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00249,
      "epss_percentile": 0.16492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moby",
      "product": "BuildKit",
      "cwe": "CWE-22",
      "title": "LLB file operation can be tricked to remove /tmp directory contents",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15791"
    },
    {
      "rank": 1014,
      "cve_id": "CVE-2026-60193",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Connectors",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60193"
    },
    {
      "rank": 1015,
      "cve_id": "CVE-2026-16400",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-200",
      "title": "Information disclosure in the DOM: Security component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16400"
    },
    {
      "rank": 1016,
      "cve_id": "CVE-2026-62495",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Process Execution",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Process Manufacturing Process Execution product of Oracle E-Business Suite (component: Internal Operations). The supported version that is affected is 12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Process Execution. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Process Execution. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62495"
    },
    {
      "rank": 1017,
      "cve_id": "CVE-2026-62493",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Purchasing",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.11-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in takeover of Oracle Purchasing. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62493"
    },
    {
      "rank": 1018,
      "cve_id": "CVE-2026-64822",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thiagopena",
      "product": "djangoSIGE",
      "cwe": "CWE-203",
      "title": "djangoSIGE 1.10 User Enumeration via ForgotPasswordView",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64822"
    },
    {
      "rank": 1019,
      "cve_id": "CVE-2026-16266",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "mongo-object",
      "cwe": "CWE-1321",
      "title": "Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript prototype chain by supplying a crafted property path containing special keys such as __proto__.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16266"
    },
    {
      "rank": 1020,
      "cve_id": "CVE-2026-62490",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Contracts Integration",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62490"
    },
    {
      "rank": 1021,
      "cve_id": "CVE-2026-65057",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00246,
      "epss_percentile": 0.16106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "keephq",
      "product": "keep",
      "cwe": "CWE-918",
      "title": "Keep Unauthenticated Server-Side Request Forgery via POST /providers/healthcheck",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65057"
    },
    {
      "rank": 1022,
      "cve_id": "CVE-2026-60671",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Business Intelligence Enterprise Edition",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition as well as unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data and unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60671"
    },
    {
      "rank": 1023,
      "cve_id": "CVE-2026-56147",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-639",
      "title": "Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Information Disclosure and Case Attachment Integrity Compromise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56147"
    },
    {
      "rank": 1024,
      "cve_id": "CVE-2026-60985",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.1617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Project Portfolio Analysis",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Portfolio Analysis accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60985"
    },
    {
      "rank": 1025,
      "cve_id": "CVE-2026-60324",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60324"
    },
    {
      "rank": 1026,
      "cve_id": "CVE-2026-60411",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "TimesTen In-Memory Database",
      "cwe": "CWE-400",
      "title": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: ttcserver). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60411"
    },
    {
      "rank": 1027,
      "cve_id": "CVE-2026-16406",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00245,
      "epss_percentile": 0.1609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "title": "Mitigation bypass in the Networking component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16406"
    },
    {
      "rank": 1028,
      "cve_id": "CVE-2026-60313",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.15983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via RMI to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60313"
    },
    {
      "rank": 1029,
      "cve_id": "CVE-2026-62478",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.15983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Public Sector Financials",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Financials. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62478"
    },
    {
      "rank": 1030,
      "cve_id": "CVE-2026-62534",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.15983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Applications Framework",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62534"
    },
    {
      "rank": 1031,
      "cve_id": "CVE-2026-62476",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00244,
      "epss_percentile": 0.15945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Public Sector Payroll",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62476"
    },
    {
      "rank": 1032,
      "cve_id": "CVE-2026-62496",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00244,
      "epss_percentile": 0.15945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Yard Management",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Yard Management. Successful attacks of this vulnerability can result in takeover of Oracle Yard Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62496"
    },
    {
      "rank": 1033,
      "cve_id": "CVE-2026-59849",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00244,
      "epss_percentile": 0.159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-835",
      "title": "Libssh: libssh: denial of service via automatic certificate authentication loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59849"
    },
    {
      "rank": 1034,
      "cve_id": "CVE-2026-47010",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00244,
      "epss_percentile": 0.15863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47010"
    },
    {
      "rank": 1035,
      "cve_id": "CVE-2026-46989",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00243,
      "epss_percentile": 0.15769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Manager Base Platform accessible data as well as unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46989"
    },
    {
      "rank": 1036,
      "cve_id": "CVE-2026-60533",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.1579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager Connector",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Generic Unix Connector). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Identity Manager Connector. CVSS 3.1 Base Score 8.0 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60533"
    },
    {
      "rank": 1037,
      "cve_id": "CVE-2026-60579",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Command Center Framework",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Enterprise Command Center Framework executes to compromise Oracle Enterprise Command Center Framework. While the vulnerability is in Oracle Enterprise Command Center Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Command Center Framework accessible data as well as unauthorized access to critical data or complete access to all Oracle Enterprise Command Center Framework accessible data. CVSS 3.1 Base Score 8.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60579"
    },
    {
      "rank": 1038,
      "cve_id": "CVE-2026-21577",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Atlassian",
      "product": "Confluence Data Center",
      "cwe": "CWE-400",
      "title": "This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.17 Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.7 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Penetration Testing program.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21577"
    },
    {
      "rank": 1039,
      "cve_id": "CVE-2026-15792",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moby",
      "product": "BuildKit",
      "cwe": "CWE-20",
      "title": "Possible panic when incorrect parameters sent from frontend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15792"
    },
    {
      "rank": 1040,
      "cve_id": "CVE-2026-16396",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "title": "Privilege escalation in WebExtensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16396"
    },
    {
      "rank": 1041,
      "cve_id": "CVE-2026-15145",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.1554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevteam",
      "product": "Essential Addons for Elementor – Popular Elementor Templates & Widgets",
      "cwe": "CWE-79",
      "title": "Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15145"
    },
    {
      "rank": 1042,
      "cve_id": "CVE-2026-63136",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-400",
      "title": "Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63136"
    },
    {
      "rank": 1043,
      "cve_id": "CVE-2026-63140",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-617",
      "title": "Reachable Assertion in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63140"
    },
    {
      "rank": 1044,
      "cve_id": "CVE-2026-63144",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-674",
      "title": "Uncontrolled Recursion in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63144"
    },
    {
      "rank": 1045,
      "cve_id": "CVE-2026-63263",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-400",
      "title": "Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63263"
    },
    {
      "rank": 1046,
      "cve_id": "CVE-2026-16439",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "OpenJ9",
      "cwe": "CWE-124",
      "title": "Eclipse OpenJ9 : Using -Xtrace to trace method arguments can lead to buffer underflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16439"
    },
    {
      "rank": 1047,
      "cve_id": "CVE-2026-60657",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60657"
    },
    {
      "rank": 1048,
      "cve_id": "CVE-2026-61046",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Production Scheduling",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Production Scheduling. While the vulnerability is in Oracle Production Scheduling, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Production Scheduling accessible data as well as unauthorized read access to a subset of Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 6.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61046"
    },
    {
      "rank": 1049,
      "cve_id": "CVE-2026-61190",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Engineering Data Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61190"
    },
    {
      "rank": 1050,
      "cve_id": "CVE-2026-61081",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00239,
      "epss_percentile": 0.15313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-200",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61081"
    },
    {
      "rank": 1051,
      "cve_id": "CVE-2026-47407",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00238,
      "epss_percentile": 0.15137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "praisonai-platform",
      "cwe": "CWE-269",
      "title": "PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47407"
    },
    {
      "rank": 1052,
      "cve_id": "CVE-2026-62559",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (US)",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (US). While the vulnerability is in Oracle HRMS (US), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (US) accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62559"
    },
    {
      "rank": 1053,
      "cve_id": "CVE-2026-60307",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60307"
    },
    {
      "rank": 1054,
      "cve_id": "CVE-2026-63080",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.15035,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aptabase",
      "product": "aptabase",
      "cwe": "CWE-89",
      "title": "Aptabase SQL Injection via ClickHouse query backend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63080"
    },
    {
      "rank": 1055,
      "cve_id": "CVE-2026-46985",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46985"
    },
    {
      "rank": 1056,
      "cve_id": "CVE-2026-60357",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00237,
      "epss_percentile": 0.14984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Integration",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Siebel Server Sync for Exchange). Supported versions that are affected are 17.0-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60357"
    },
    {
      "rank": 1057,
      "cve_id": "CVE-2026-60339",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00237,
      "epss_percentile": 0.14977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Project Manufacturing",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center). The supported version that is affected is V16. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Manufacturing. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Project Manufacturing accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60339"
    },
    {
      "rank": 1058,
      "cve_id": "CVE-2026-60922",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00237,
      "epss_percentile": 0.14949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iSupplier Portal",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSupplier Portal. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle iSupplier Portal accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60922"
    },
    {
      "rank": 1059,
      "cve_id": "CVE-2026-60930",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00237,
      "epss_percentile": 0.14977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Public Sector Financials",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Public Sector Financials accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60930"
    },
    {
      "rank": 1060,
      "cve_id": "CVE-2026-60939",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00237,
      "epss_percentile": 0.14949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Project Contracts",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Contracts. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Project Contracts accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60939"
    },
    {
      "rank": 1061,
      "cve_id": "CVE-2026-60312",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60312"
    },
    {
      "rank": 1062,
      "cve_id": "CVE-2026-62547",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Workflow",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in takeover of Oracle Workflow. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62547"
    },
    {
      "rank": 1063,
      "cve_id": "CVE-2026-60620",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Configurator",
      "cwe": "CWE-20",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Configurator product of Oracle JD Edwards (component: Configuration Management). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Configurator. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Configurator as well as unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Configurator accessible data and unauthorized read access to a subset of JD Edwards EnterpriseOne Configurator accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60620"
    },
    {
      "rank": 1064,
      "cve_id": "CVE-2026-8285",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Universal Software Inc.",
      "product": "FlexCity",
      "cwe": "CWE-307",
      "title": "OTP Bypass in Universal Sotware's FlexCity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8285"
    },
    {
      "rank": 1065,
      "cve_id": "CVE-2026-59143",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::RoaringBitmap::Shared",
      "cwe": "CWE-125",
      "title": "Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offset and cardinality in rb_contains_locked",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59143"
    },
    {
      "rank": 1066,
      "cve_id": "CVE-2026-61103",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Campus Community",
      "cwe": "CWE-200",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the PeopleSoft Enterprise CS Campus Community executes to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61103"
    },
    {
      "rank": 1067,
      "cve_id": "CVE-2026-12548",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Libsoup: heap out-of-bounds read in libsoup due to integer truncation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12548"
    },
    {
      "rank": 1068,
      "cve_id": "CVE-2026-56144",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Elasticsearch Leading to Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56144"
    },
    {
      "rank": 1069,
      "cve_id": "CVE-2026-60832",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Interaction Blending",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via RMI to compromise Oracle Interaction Blending. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Interaction Blending accessible data as well as unauthorized read access to a subset of Oracle Interaction Blending accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Interaction Blending. CVSS 3.1 Base Score 4.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60832"
    },
    {
      "rank": 1070,
      "cve_id": "CVE-2026-47030",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00232,
      "epss_percentile": 0.14356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE",
      "cwe": "CWE-284",
      "title": "Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47030"
    },
    {
      "rank": 1071,
      "cve_id": "CVE-2026-47034",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00232,
      "epss_percentile": 0.14356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE",
      "cwe": "CWE-284",
      "title": "Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47034"
    },
    {
      "rank": 1072,
      "cve_id": "CVE-2026-62508",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00232,
      "epss_percentile": 0.14295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Time and Labor",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Time and Labor. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62508"
    },
    {
      "rank": 1073,
      "cve_id": "CVE-2026-47017",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PeopleTools",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Process Scheduler). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47017"
    },
    {
      "rank": 1074,
      "cve_id": "CVE-2026-60470",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebCenter Content: Imaging",
      "cwe": "CWE-284",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all WebCenter Content: Imaging accessible data as well as unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60470"
    },
    {
      "rank": 1075,
      "cve_id": "CVE-2026-65056",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mzxrai",
      "product": "mcp-webresearch",
      "cwe": "CWE-918",
      "title": "mcp-webresearch Server-Side Request Forgery in visit_page Due to Missing Internal-IP Filtering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65056"
    },
    {
      "rank": 1076,
      "cve_id": "CVE-2026-47406",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "praisonai-platform",
      "cwe": "CWE-639",
      "title": "praisonai-platform: Dependency endpoints accept any issue_id and dep_id without workspace ownership check, cross-workspace issue linking + read + delete IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47406"
    },
    {
      "rank": 1077,
      "cve_id": "CVE-2026-47408",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "praisonai-platform",
      "cwe": "CWE-639",
      "title": "praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47408"
    },
    {
      "rank": 1078,
      "cve_id": "CVE-2026-47002",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-601",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47002"
    },
    {
      "rank": 1079,
      "cve_id": "CVE-2026-60802",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle E-Business Intelligence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Intelligence. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle E-Business Intelligence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle E-Business Intelligence accessible data as well as unauthorized read access to a subset of Oracle E-Business Intelligence accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60802"
    },
    {
      "rank": 1080,
      "cve_id": "CVE-2026-60815",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iStore",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle iStore accessible data as well as unauthorized read access to a subset of Oracle iStore accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60815"
    },
    {
      "rank": 1081,
      "cve_id": "CVE-2026-62444",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Contracts Integration",
      "cwe": "CWE-285",
      "title": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Contracts Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Contracts Integration accessible data as well as unauthorized read access to a subset of Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62444"
    },
    {
      "rank": 1082,
      "cve_id": "CVE-2026-62505",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Time and Labor",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Time and Labor, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Time and Labor accessible data as well as unauthorized read access to a subset of Oracle Time and Labor accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62505"
    },
    {
      "rank": 1083,
      "cve_id": "CVE-2026-60152",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PeopleTools",
      "cwe": "CWE-285",
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60152"
    },
    {
      "rank": 1084,
      "cve_id": "CVE-2026-60912",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Property Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Property Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Property Manager accessible data as well as unauthorized read access to a subset of Oracle Property Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60912"
    },
    {
      "rank": 1085,
      "cve_id": "CVE-2026-60868",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Advanced Pricing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation). Supported versions that are affected are 12.2.14-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Pricing. While the vulnerability is in Oracle Advanced Pricing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Pricing accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Pricing accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60868"
    },
    {
      "rank": 1086,
      "cve_id": "CVE-2026-60623",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.14005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Connectors",
      "cwe": "CWE-306",
      "title": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60623"
    },
    {
      "rank": 1087,
      "cve_id": "CVE-2026-61143",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Communications Convergent Charging Controller",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: Prov IF). Supported versions that are affected are 15.0.0.0.0 and 15.2.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Convergent Charging Controller. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Convergent Charging Controller. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61143"
    },
    {
      "rank": 1088,
      "cve_id": "CVE-2026-47121",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sparkle-project",
      "product": "Sparkle",
      "cwe": "CWE-22",
      "title": "Sparkle: Binary delta apply intermediate-symlink traversal in malicious .delta",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47121"
    },
    {
      "rank": 1089,
      "cve_id": "CVE-2026-46990",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46990"
    },
    {
      "rank": 1090,
      "cve_id": "CVE-2026-65314",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ElectricSQL",
      "product": "Electric Postgres Sync",
      "cwe": "CWE-203",
      "title": "Electric Postgres Sync Excluded-Column Value Inference via Subset Where Clauses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65314"
    },
    {
      "rank": 1091,
      "cve_id": "CVE-2026-12547",
      "cvss_base": 3.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00228,
      "epss_percentile": 0.13774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-201",
      "title": "Libsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12547"
    },
    {
      "rank": 1092,
      "cve_id": "CVE-2026-16461",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-121",
      "title": "Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16461"
    },
    {
      "rank": 1093,
      "cve_id": "CVE-2026-60397",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle GoldenGate",
      "cwe": "CWE-404",
      "title": "Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle GoldenGate executes to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GoldenGate. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60397"
    },
    {
      "rank": 1094,
      "cve_id": "CVE-2026-47060",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.13598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Database Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise JDBC. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JDBC accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47060"
    },
    {
      "rank": 1095,
      "cve_id": "CVE-2026-15342",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Plane",
      "product": "Plane",
      "cwe": "CWE-552",
      "title": "CVE-2026-15342",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15342"
    },
    {
      "rank": 1096,
      "cve_id": "CVE-2026-60408",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "TimesTen In-Memory Database",
      "cwe": "CWE-200",
      "title": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database. Successful attacks of this vulnerability can result in unauthorized read access to a subset of TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60408"
    },
    {
      "rank": 1097,
      "cve_id": "CVE-2026-46999",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery Framework). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46999"
    },
    {
      "rank": 1098,
      "cve_id": "CVE-2026-62484",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Contracts Integration",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62484"
    },
    {
      "rank": 1099,
      "cve_id": "CVE-2026-47032",
      "cvss_base": 2.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00224,
      "epss_percentile": 0.13301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM End User",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Redwood UI). Supported versions that are affected are 24.4-26.3. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM End User. CVSS 3.1 Base Score 2.6 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47032"
    },
    {
      "rank": 1100,
      "cve_id": "CVE-2026-8988",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00223,
      "epss_percentile": 0.13159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autel",
      "product": "MaxiCharger Single",
      "cwe": "CWE-1191",
      "title": "Access to Bootloader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8988"
    },
    {
      "rank": 1101,
      "cve_id": "CVE-2026-60739",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00223,
      "epss_percentile": 0.13154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Field Service",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Field Service accessible data as well as unauthorized update, insert or delete access to some of Oracle Field Service accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60739"
    },
    {
      "rank": 1102,
      "cve_id": "CVE-2026-46975",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Database Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of RDBMS accessible data. CVSS 3.1 Base Score 5.8 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46975"
    },
    {
      "rank": 1103,
      "cve_id": "CVE-2026-60426",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data as well as unauthorized update, insert or delete access to some of Oracle Unified Directory accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60426"
    },
    {
      "rank": 1104,
      "cve_id": "CVE-2026-60421",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.12998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Unified Directory accessible data as well as unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60421"
    },
    {
      "rank": 1105,
      "cve_id": "CVE-2026-62456",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.12999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (UK)",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle HRMS (UK). While the vulnerability is in Oracle HRMS (UK), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HRMS (UK) accessible data as well as unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62456"
    },
    {
      "rank": 1106,
      "cve_id": "CVE-2026-60468",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebCenter Content: Imaging",
      "cwe": "CWE-284",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data as well as unauthorized update, insert or delete access to some of WebCenter Content: Imaging accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60468"
    },
    {
      "rank": 1107,
      "cve_id": "CVE-2026-62557",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (UK)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data as well as unauthorized update, insert or delete access to some of Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62557"
    },
    {
      "rank": 1108,
      "cve_id": "CVE-2026-60666",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.12999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise HCM Human Resources",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via Oracle Net to compromise PeopleSoft Enterprise HCM Human Resources. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise HCM Human Resources accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise HCM Human Resources accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60666"
    },
    {
      "rank": 1109,
      "cve_id": "CVE-2026-60864",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Order Management",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. While the vulnerability is in Oracle Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Order Management accessible data as well as unauthorized read access to a subset of Oracle Order Management accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60864"
    },
    {
      "rank": 1110,
      "cve_id": "CVE-2026-47001",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Web Services Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47001"
    },
    {
      "rank": 1111,
      "cve_id": "CVE-2026-60154",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Object Library",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Object Library accessible data as well as unauthorized read access to a subset of Oracle Application Object Library accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60154"
    },
    {
      "rank": 1112,
      "cve_id": "CVE-2026-60231",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Coherence accessible data as well as unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60231"
    },
    {
      "rank": 1113,
      "cve_id": "CVE-2026-60344",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (France)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (France). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (France) accessible data as well as unauthorized read access to a subset of Oracle HRMS (France) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60344"
    },
    {
      "rank": 1114,
      "cve_id": "CVE-2026-60588",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Asset Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Work Definition Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Asset Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Asset Management accessible data as well as unauthorized read access to a subset of Oracle Enterprise Asset Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60588"
    },
    {
      "rank": 1115,
      "cve_id": "CVE-2026-60717",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Complex Maintenance, Repair and Overhaul",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Common Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Complex Maintenance, Repair and Overhaul accessible data as well as unauthorized read access to a subset of Oracle Complex Maintenance, Repair and Overhaul accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60717"
    },
    {
      "rank": 1116,
      "cve_id": "CVE-2026-60794",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle TeleSales",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle TeleSales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle TeleSales. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle TeleSales accessible data as well as unauthorized read access to a subset of Oracle TeleSales accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60794"
    },
    {
      "rank": 1117,
      "cve_id": "CVE-2026-61060",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle E-Business Suite Secure Enterprise Search",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search Integration Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Suite Secure Enterprise Search. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle E-Business Suite Secure Enterprise Search accessible data as well as unauthorized read access to a subset of Oracle E-Business Suite Secure Enterprise Search accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61060"
    },
    {
      "rank": 1118,
      "cve_id": "CVE-2026-61064",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iRecruitment",
      "cwe": "CWE-639",
      "title": "Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Install / Upgrade Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iRecruitment. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle iRecruitment accessible data as well as unauthorized read access to a subset of Oracle iRecruitment accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61064"
    },
    {
      "rank": 1119,
      "cve_id": "CVE-2026-61075",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Self-Service Human Resources",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Self-Service Human Resources. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Self-Service Human Resources accessible data as well as unauthorized read access to a subset of Oracle Self-Service Human Resources accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61075"
    },
    {
      "rank": 1120,
      "cve_id": "CVE-2026-61080",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Public Sector Human Resources",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (component: Regression Testing). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Human Resources. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Public Sector Human Resources accessible data as well as unauthorized read access to a subset of Oracle Public Sector Human Resources accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61080"
    },
    {
      "rank": 1121,
      "cve_id": "CVE-2026-61083",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Performance Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Performance Management product of Oracle E-Business Suite (component: Appraisals). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Performance Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Performance Management accessible data as well as unauthorized read access to a subset of Oracle Performance Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61083"
    },
    {
      "rank": 1122,
      "cve_id": "CVE-2026-61152",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61152"
    },
    {
      "rank": 1123,
      "cve_id": "CVE-2026-61200",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Labor Distribution",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Labor Distribution accessible data as well as unauthorized read access to a subset of Oracle Labor Distribution accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61200"
    },
    {
      "rank": 1124,
      "cve_id": "CVE-2026-61221",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Item Master",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Item Master product of Oracle E-Business Suite (component: iSet-up bugs). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Item Master. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Item Master accessible data as well as unauthorized read access to a subset of Oracle Item Master accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61221"
    },
    {
      "rank": 1125,
      "cve_id": "CVE-2026-61252",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (Hong Kong)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle HRMS (Hong Kong) product of Oracle E-Business Suite (component: Hong Kong Payroll). Supported versions that are affected are 12.2.13-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (Hong Kong). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (Hong Kong) accessible data as well as unauthorized read access to a subset of Oracle HRMS (Hong Kong) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61252"
    },
    {
      "rank": 1126,
      "cve_id": "CVE-2026-61255",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (New Zealand)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle HRMS (New Zealand) product of Oracle E-Business Suite (component: New Zealand Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (New Zealand). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (New Zealand) accessible data as well as unauthorized read access to a subset of Oracle HRMS (New Zealand) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61255"
    },
    {
      "rank": 1127,
      "cve_id": "CVE-2026-61260",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (UK)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (UK) accessible data as well as unauthorized read access to a subset of Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61260"
    },
    {
      "rank": 1128,
      "cve_id": "CVE-2026-61264",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Call Center Technology",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: RDBMS and UI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Call Center Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Call Center Technology accessible data as well as unauthorized read access to a subset of Oracle Call Center Technology accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61264"
    },
    {
      "rank": 1129,
      "cve_id": "CVE-2026-60816",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iStore",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60816"
    },
    {
      "rank": 1130,
      "cve_id": "CVE-2026-16454",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "eclipse-hawkbit/hawkbit",
      "cwe": "CWE-284",
      "title": "Privilege Escalation in Eclipse hawkBit DDI allows Tenant-Isolated Firmware Exfiltration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16454"
    },
    {
      "rank": 1131,
      "cve_id": "CVE-2026-60724",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Customer Interaction History",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Interaction History. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Customer Interaction History accessible data as well as unauthorized read access to a subset of Oracle Customer Interaction History accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60724"
    },
    {
      "rank": 1132,
      "cve_id": "CVE-2026-61261",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Knowledge Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Knowledge Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Knowledge Management accessible data as well as unauthorized read access to a subset of Oracle Knowledge Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61261"
    },
    {
      "rank": 1133,
      "cve_id": "CVE-2026-61263",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Scripting",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Scripting Admin). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Scripting accessible data as well as unauthorized read access to a subset of Oracle Scripting accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61263"
    },
    {
      "rank": 1134,
      "cve_id": "CVE-2026-61257",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iSupport",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Call Back). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle iSupport accessible data as well as unauthorized read access to a subset of Oracle iSupport accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61257"
    },
    {
      "rank": 1135,
      "cve_id": "CVE-2026-60249",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00219,
      "epss_percentile": 0.12724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Coherence executes to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60249"
    },
    {
      "rank": 1136,
      "cve_id": "CVE-2026-61240",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00219,
      "epss_percentile": 0.12665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Common Objects Argentina",
      "cwe": "CWE-200",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eSettlements). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the PeopleSoft Enterprise FIN Common Objects Argentina executes to compromise PeopleSoft Enterprise FIN Common Objects Argentina. While the vulnerability is in PeopleSoft Enterprise FIN Common Objects Argentina, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Argentina accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Common Objects Argentina accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61240"
    },
    {
      "rank": 1137,
      "cve_id": "CVE-2026-46997",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46997"
    },
    {
      "rank": 1138,
      "cve_id": "CVE-2026-62488",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Contracts Integration",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62488"
    },
    {
      "rank": 1139,
      "cve_id": "CVE-2026-16358",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00216,
      "epss_percentile": 0.12324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-346",
      "title": "Site isolation issue in the Graphics: WebRender component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16358"
    },
    {
      "rank": 1140,
      "cve_id": "CVE-2026-52475",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the UploadController.java file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52475"
    },
    {
      "rank": 1141,
      "cve_id": "CVE-2026-16349",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00215,
      "epss_percentile": 0.12242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-346",
      "title": "Same-origin policy bypass in the DOM: Navigation component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16349"
    },
    {
      "rank": 1142,
      "cve_id": "CVE-2026-8933",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12246,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "snapd",
      "cwe": "CWE-250",
      "title": "snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Execution Environment Setup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8933"
    },
    {
      "rank": 1143,
      "cve_id": "CVE-2026-47414",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "praisonai-platform",
      "cwe": "CWE-639",
      "title": "praisonai-platform: Label endpoints accept any label_id and any issue_id without workspace ownership check, cross-workspace label edit/delete and issue-label-link IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47414"
    },
    {
      "rank": 1144,
      "cve_id": "CVE-2026-47657",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "humhub",
      "product": "humhub",
      "cwe": "CWE-862",
      "title": "HumHub Missing Authorization on Remove All Space Members Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47657"
    },
    {
      "rank": 1145,
      "cve_id": "CVE-2026-16401",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.1205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "title": "Privilege escalation in the Data Loss Prevention component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16401"
    },
    {
      "rank": 1146,
      "cve_id": "CVE-2026-60305",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.12009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60305"
    },
    {
      "rank": 1147,
      "cve_id": "CVE-2026-60322",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Applications Manager",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Manager accessible data as well as unauthorized read access to a subset of Oracle Applications Manager accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60322"
    },
    {
      "rank": 1148,
      "cve_id": "CVE-2026-60638",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.1196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-20",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60638"
    },
    {
      "rank": 1149,
      "cve_id": "CVE-2026-60664",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.11959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-79",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60664"
    },
    {
      "rank": 1150,
      "cve_id": "CVE-2026-60351",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle JDeveloper",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle JDeveloper accessible data as well as unauthorized read access to a subset of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60351"
    },
    {
      "rank": 1151,
      "cve_id": "CVE-2026-61056",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Grants",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Grants product of Oracle PeopleSoft (component: Grants). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Grants. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Grants accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise FIN Grants accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61056"
    },
    {
      "rank": 1152,
      "cve_id": "CVE-2026-61057",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN eSettlements",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN eSettlements. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN eSettlements accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise FIN eSettlements accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61057"
    },
    {
      "rank": 1153,
      "cve_id": "CVE-2026-61123",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (US)",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle HRMS (US) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HRMS (US). CVSS 3.1 Base Score 4.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61123"
    },
    {
      "rank": 1154,
      "cve_id": "CVE-2026-47038",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00213,
      "epss_percentile": 0.11938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Database Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows high privileged attacker having None privilege with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of RDBMS accessible data. CVSS 3.1 Base Score 2.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47038"
    },
    {
      "rank": 1155,
      "cve_id": "CVE-2026-62567",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.11768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (UK)",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). While the vulnerability is in Oracle HRMS (UK), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62567"
    },
    {
      "rank": 1156,
      "cve_id": "CVE-2026-47709",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-476",
      "title": "libheif has a NULL pointer dereference in heif_image_handle_get_image_tiling for malformed unci image missing ispe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47709"
    },
    {
      "rank": 1157,
      "cve_id": "CVE-2026-62562",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (US)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (US) accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62562"
    },
    {
      "rank": 1158,
      "cve_id": "CVE-2026-47061",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Database Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the JDBC executes to compromise JDBC. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JDBC, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JDBC accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47061"
    },
    {
      "rank": 1159,
      "cve_id": "CVE-2026-60164",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00212,
      "epss_percentile": 0.11811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE",
      "cwe": "CWE-693",
      "title": "Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60164"
    },
    {
      "rank": 1160,
      "cve_id": "CVE-2026-60353",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00212,
      "epss_percentile": 0.11838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle JDeveloper",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60353"
    },
    {
      "rank": 1161,
      "cve_id": "CVE-2026-62494",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Time and Labor",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data as well as unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62494"
    },
    {
      "rank": 1162,
      "cve_id": "CVE-2026-62497",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.1174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Flow Manufacturing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.13-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Flow Manufacturing accessible data as well as unauthorized access to critical data or complete access to all Oracle Flow Manufacturing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62497"
    },
    {
      "rank": 1163,
      "cve_id": "CVE-2026-62504",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Time and Labor",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data as well as unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62504"
    },
    {
      "rank": 1164,
      "cve_id": "CVE-2026-62530",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (France)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (France). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HRMS (France) accessible data as well as unauthorized access to critical data or complete access to all Oracle HRMS (France) accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62530"
    },
    {
      "rank": 1165,
      "cve_id": "CVE-2026-62560",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.1174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (Norway)",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (Norway). While the vulnerability is in Oracle HRMS (Norway), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (Norway) accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62560"
    },
    {
      "rank": 1166,
      "cve_id": "CVE-2026-60929",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00211,
      "epss_percentile": 0.11607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Public Sector Financials",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Public Sector Financials accessible data. CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60929"
    },
    {
      "rank": 1167,
      "cve_id": "CVE-2026-60937",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00211,
      "epss_percentile": 0.11606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Labor Distribution",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Labor Distribution accessible data. CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60937"
    },
    {
      "rank": 1168,
      "cve_id": "CVE-2026-16375",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00209,
      "epss_percentile": 0.11407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-346",
      "title": "Site isolation issue in the Networking: HTTP component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16375"
    },
    {
      "rank": 1169,
      "cve_id": "CVE-2026-47413",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00209,
      "epss_percentile": 0.11349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "praisonai-platform",
      "cwe": "CWE-269",
      "title": "praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47413"
    },
    {
      "rank": 1170,
      "cve_id": "CVE-2026-47416",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00209,
      "epss_percentile": 0.11349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "praisonai-platform",
      "cwe": "CWE-269",
      "title": "praisonai-platform: Any workspace member can promote themselves (or any other member) to owner via PATCH /workspaces/{id}/members/{user_id}",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47416"
    },
    {
      "rank": 1171,
      "cve_id": "CVE-2026-47417",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00209,
      "epss_percentile": 0.1135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "praisonai-platform",
      "cwe": "CWE-639",
      "title": "praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47417"
    },
    {
      "rank": 1172,
      "cve_id": "CVE-2026-46556",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flaskbb",
      "product": "flaskbb",
      "cwe": "CWE-918",
      "title": "FlaskBB: SSRF in get_image_info() via unrestricted avatar URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46556"
    },
    {
      "rank": 1173,
      "cve_id": "CVE-2026-60669",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.1123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise HCM Global Payroll Mexico",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Mexico product of Oracle PeopleSoft (component: Global Payroll for Mexico). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Global Payroll Mexico. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise HCM Global Payroll Mexico accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise HCM Global Payroll Mexico. CVSS 3.1 Base Score 5.9 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60669"
    },
    {
      "rank": 1174,
      "cve_id": "CVE-2026-8593",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Checkmk GmbH",
      "product": "Checkmk",
      "cwe": "CWE-862",
      "title": "Fix Business Intelligence API Pack permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8593"
    },
    {
      "rank": 1175,
      "cve_id": "CVE-2026-60494",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.11031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne General Ledger",
      "cwe": "CWE-284",
      "title": "Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne General Ledger. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne General Ledger as well as unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne General Ledger accessible data and unauthorized read access to a subset of JD Edwards EnterpriseOne General Ledger accessible data. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60494"
    },
    {
      "rank": 1176,
      "cve_id": "CVE-2026-16417",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00206,
      "epss_percentile": 0.10924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16417"
    },
    {
      "rank": 1177,
      "cve_id": "CVE-2026-16387",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00204,
      "epss_percentile": 0.1075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-200",
      "title": "Site isolation issue in the Networking component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16387"
    },
    {
      "rank": 1178,
      "cve_id": "CVE-2026-1372",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeum",
      "product": "Tutor LMS Elementor Addons",
      "cwe": "CWE-862",
      "title": "Tutor LMS Elementor Addons <= 4.0.0 - Missing Authorization to Authenticated (Subscriber+) Tutor LMS and Elementor Plugin Activation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1372"
    },
    {
      "rank": 1179,
      "cve_id": "CVE-2026-13694",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Bit Form",
      "cwe": "CWE-862",
      "title": "Bit Form < 3.1.0 - Unauthenticated Workflow Trigger via Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13694"
    },
    {
      "rank": 1180,
      "cve_id": "CVE-2026-61071",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00203,
      "epss_percentile": 0.10658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Engineering Argentina",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Engineering Argentina product of Oracle PeopleSoft (component: Engineering). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Engineering Argentina. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Engineering Argentina accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise FIN Engineering Argentina accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61071"
    },
    {
      "rank": 1181,
      "cve_id": "CVE-2026-65054",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaCMS",
      "product": "MediaCMS",
      "cwe": "CWE-863",
      "title": "MediaCMS Private Media Metadata Disclosure via Playlist Ownership Loophole",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65054"
    },
    {
      "rank": 1182,
      "cve_id": "CVE-2026-15793",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moby",
      "product": "BuildKit",
      "cwe": "CWE-88",
      "title": "Git source checkout from a bundle file could lead to command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15793"
    },
    {
      "rank": 1183,
      "cve_id": "CVE-2026-46981",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Utilities Network Management System",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Mobile). Supported versions that are affected are 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8 and 25.12.0.0.0-25.12.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Network Management System. While the vulnerability is in Oracle Utilities Network Management System, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Utilities Network Management System accessible data as well as unauthorized read access to a subset of Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46981"
    },
    {
      "rank": 1184,
      "cve_id": "CVE-2026-46996",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10425,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46996"
    },
    {
      "rank": 1185,
      "cve_id": "CVE-2026-60772",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Financials Common Modules",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financials Common Modules accessible data as well as unauthorized read access to a subset of Oracle Financials Common Modules accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60772"
    },
    {
      "rank": 1186,
      "cve_id": "CVE-2026-60987",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10451,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Project Portfolio Analysis",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Portfolio Analysis accessible data as well as unauthorized read access to a subset of Oracle Project Portfolio Analysis accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60987"
    },
    {
      "rank": 1187,
      "cve_id": "CVE-2026-21954",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10425,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Retail Xstore Point of Service",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Retail Xstore Point of Service accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21954"
    },
    {
      "rank": 1188,
      "cve_id": "CVE-2026-46980",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Utilities Network Management System",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Mobile). Supported versions that are affected are 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8 and 25.12.0.0.0-25.12.0.0.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilities Network Management System. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46980"
    },
    {
      "rank": 1189,
      "cve_id": "CVE-2026-60434",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10425,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Transportation Management",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Authentication). The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Transportation Management accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60434"
    },
    {
      "rank": 1190,
      "cve_id": "CVE-2026-6792",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Universal Software Inc.",
      "product": "FlexCity",
      "cwe": "CWE-862",
      "title": "Improper Authorization in Universal Sotware's FlexCity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6792"
    },
    {
      "rank": 1191,
      "cve_id": "CVE-2026-15156",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevteam",
      "product": "Essential Addons for Elementor – Popular Elementor Templates & Widgets",
      "cwe": "CWE-79",
      "title": "Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15156"
    },
    {
      "rank": 1192,
      "cve_id": "CVE-2026-61266",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Supply Chain Globalization",
      "cwe": "CWE-89",
      "title": "Vulnerability in the Oracle Supply Chain Globalization product of Oracle E-Business Suite (component: Copy Inventory Organization). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Supply Chain Globalization. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Supply Chain Globalization accessible data as well as unauthorized read access to a subset of Oracle Supply Chain Globalization accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Supply Chain Globalization. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61266"
    },
    {
      "rank": 1193,
      "cve_id": "CVE-2026-62527",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Learning Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Import And Export). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Learning Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Learning Management accessible data as well as unauthorized read access to a subset of Oracle Learning Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Learning Management. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62527"
    },
    {
      "rank": 1194,
      "cve_id": "CVE-2026-62528",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HCM Configuration Workbench",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HCM Configuration Workbench. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HCM Configuration Workbench accessible data as well as unauthorized read access to a subset of Oracle HCM Configuration Workbench accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HCM Configuration Workbench. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62528"
    },
    {
      "rank": 1195,
      "cve_id": "CVE-2026-16451",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00201,
      "epss_percentile": 0.10395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zsadmin2025",
      "product": "ZS-Admin",
      "cwe": "CWE-284",
      "title": "zsadmin2025 ZS-Admin com.zs.file.controller.SysFileController upload unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16451"
    },
    {
      "rank": 1196,
      "cve_id": "CVE-2026-60804",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00201,
      "epss_percentile": 0.1031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle E-Business Intelligence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Definition). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle E-Business Intelligence. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle E-Business Intelligence accessible data. CVSS 3.1 Base Score 2.0 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60804"
    },
    {
      "rank": 1197,
      "cve_id": "CVE-2026-16415",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16415"
    },
    {
      "rank": 1198,
      "cve_id": "CVE-2026-63143",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Kibana Leading to Unauthorized Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63143"
    },
    {
      "rank": 1199,
      "cve_id": "CVE-2026-16334",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System prescriptionorder.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16334"
    },
    {
      "rank": 1200,
      "cve_id": "CVE-2026-47178",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-787",
      "title": "libheif has Heap Out Of Bounds Write in unci subsystem",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47178"
    },
    {
      "rank": 1201,
      "cve_id": "CVE-2026-16403",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-451",
      "title": "Spoofing issue in the Address Bar component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16403"
    },
    {
      "rank": 1202,
      "cve_id": "CVE-2026-60907",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Installed Base",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.4-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Installed Base accessible data as well as unauthorized read access to a subset of Oracle Installed Base accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Installed Base. CVSS 3.1 Base Score 5.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60907"
    },
    {
      "rank": 1203,
      "cve_id": "CVE-2026-60834",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00197,
      "epss_percentile": 0.0985,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Solaris",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with network access via RAD to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Solaris accessible data as well as unauthorized update, insert or delete access to some of Oracle Solaris accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60834"
    },
    {
      "rank": 1204,
      "cve_id": "CVE-2026-60628",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00197,
      "epss_percentile": 0.0985,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": "CWE-284",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60628"
    },
    {
      "rank": 1205,
      "cve_id": "CVE-2026-60634",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00196,
      "epss_percentile": 0.0964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-20",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60634"
    },
    {
      "rank": 1206,
      "cve_id": "CVE-2026-60637",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00196,
      "epss_percentile": 0.0964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-20",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60637"
    },
    {
      "rank": 1207,
      "cve_id": "CVE-2026-60694",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Asset Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Asset Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Asset Management accessible data as well as unauthorized read access to a subset of Oracle Enterprise Asset Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60694"
    },
    {
      "rank": 1208,
      "cve_id": "CVE-2026-62479",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Public Sector Financials",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Public Sector Financials, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Public Sector Financials accessible data as well as unauthorized read access to a subset of Oracle Public Sector Financials accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62479"
    },
    {
      "rank": 1209,
      "cve_id": "CVE-2026-60684",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Applications Framework",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data as well as unauthorized read access to a subset of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60684"
    },
    {
      "rank": 1210,
      "cve_id": "CVE-2026-47411",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "praisonai-platform",
      "cwe": "CWE-269",
      "title": "praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47411"
    },
    {
      "rank": 1211,
      "cve_id": "CVE-2026-60697",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Site Hub",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (component: Site Hierarchy Flows). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Site Hub. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Site Hub accessible data as well as unauthorized read access to a subset of Oracle Site Hub accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Site Hub. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60697"
    },
    {
      "rank": 1212,
      "cve_id": "CVE-2026-62453",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (UK)",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (UK) accessible data as well as unauthorized read access to a subset of Oracle HRMS (UK) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HRMS (UK). CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62453"
    },
    {
      "rank": 1213,
      "cve_id": "CVE-2026-62474",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Lease and Finance Management",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Lease Authoring). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Lease and Finance Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Lease and Finance Management accessible data as well as unauthorized read access to a subset of Oracle Lease and Finance Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Lease and Finance Management. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62474"
    },
    {
      "rank": 1214,
      "cve_id": "CVE-2026-62524",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (US)",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - General). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (US) accessible data as well as unauthorized read access to a subset of Oracle HRMS (US) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HRMS (US). CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62524"
    },
    {
      "rank": 1215,
      "cve_id": "CVE-2026-62525",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Quality",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Quality Workbench HTML system). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quality. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Quality accessible data as well as unauthorized read access to a subset of Oracle Quality accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Quality. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62525"
    },
    {
      "rank": 1216,
      "cve_id": "CVE-2026-62542",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Advanced Benefits",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self Service Benefits). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Advanced Benefits accessible data as well as unauthorized read access to a subset of Oracle Advanced Benefits accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Advanced Benefits. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62542"
    },
    {
      "rank": 1217,
      "cve_id": "CVE-2026-16449",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00192,
      "epss_percentile": 0.09267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zsadmin2025",
      "product": "ZS-Admin",
      "cwe": "CWE-74",
      "title": "zsadmin2025 ZS-Admin com.zs.sys.dept.controller.SysDeptController page OrderItem.desc sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16449"
    },
    {
      "rank": 1218,
      "cve_id": "CVE-2026-64877",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00191,
      "epss_percentile": 0.09176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenable, Inc.",
      "product": "Security Center",
      "cwe": "CWE-20",
      "title": "An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64877"
    },
    {
      "rank": 1219,
      "cve_id": "CVE-2026-47035",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00191,
      "epss_percentile": 0.09108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE",
      "cwe": "CWE-284",
      "title": "Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47035"
    },
    {
      "rank": 1220,
      "cve_id": "CVE-2026-62507",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.09056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Time and Labor",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62507"
    },
    {
      "rank": 1221,
      "cve_id": "CVE-2026-62483",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.08965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Project Contracts",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Contracts. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Project Contracts accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62483"
    },
    {
      "rank": 1222,
      "cve_id": "CVE-2026-47254",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.0883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-125",
      "title": "libheif Has Heap Buffer Overflow in `Track::get_next_sample_raw_data()` -- OOB Chunk Vector Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47254"
    },
    {
      "rank": 1223,
      "cve_id": "CVE-2026-16317",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "s2n-tls",
      "cwe": "CWE-354",
      "title": "Silent Drop of TLS 1.3 Encrypted Records in s2n-tls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16317"
    },
    {
      "rank": 1224,
      "cve_id": "CVE-2026-63141",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Kibana Leading to Unauthorized Access to Cloud Connect Management Functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63141"
    },
    {
      "rank": 1225,
      "cve_id": "CVE-2026-15432",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Tink-Java",
      "cwe": "CWE-208",
      "title": "Observable Timing Discrepancy in Tink-Java and Tink-Android ChunkedMacVerification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15432"
    },
    {
      "rank": 1226,
      "cve_id": "CVE-2026-60643",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-352",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60643"
    },
    {
      "rank": 1227,
      "cve_id": "CVE-2026-60709",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data as well as unauthorized read access to a subset of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60709"
    },
    {
      "rank": 1228,
      "cve_id": "CVE-2026-64880",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.08273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenable, Inc.",
      "product": "Security Center",
      "cwe": "CWE-89",
      "title": "Blind SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64880"
    },
    {
      "rank": 1229,
      "cve_id": "CVE-2026-47688",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00183,
      "epss_percentile": 0.08204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOGProject",
      "product": "fogproject",
      "cwe": "CWE-862",
      "title": "FOGProject has unauthenticated clearAES and clearPMTasks that allow remote destruction of host encryption keys and power schedules",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47688"
    },
    {
      "rank": 1230,
      "cve_id": "CVE-2026-60648",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00183,
      "epss_percentile": 0.08215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-20",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60648"
    },
    {
      "rank": 1231,
      "cve_id": "CVE-2026-65009",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openremote",
      "product": "openremote",
      "cwe": "CWE-200",
      "title": "OpenRemote before 1.26.2 Information Disclosure via Syslog REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65009"
    },
    {
      "rank": 1232,
      "cve_id": "CVE-2026-11876",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zenml-io",
      "product": "zenml-io/zenml",
      "cwe": "CWE-862",
      "title": "Missing Authorization in get_deployed_stack Endpoint in zenml-io/zenml",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11876"
    },
    {
      "rank": 1233,
      "cve_id": "CVE-2026-64823",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00183,
      "epss_percentile": 0.08171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "home-assistant",
      "product": "Home Assistant Core",
      "cwe": "CWE-79",
      "title": "Home Assistant Core < 2026.5.4 XSS via Shelly media_player.py thumb URI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64823"
    },
    {
      "rank": 1234,
      "cve_id": "CVE-2026-56820",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00182,
      "epss_percentile": 0.08102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-295",
      "title": "Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56820"
    },
    {
      "rank": 1235,
      "cve_id": "CVE-2026-15782",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smub",
      "product": "WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More",
      "cwe": "CWE-79",
      "title": "WPForms <= 2.0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15782"
    },
    {
      "rank": 1236,
      "cve_id": "CVE-2026-47697",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.08039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shelf-nu",
      "product": "shelf.nu",
      "cwe": "CWE-863",
      "title": "Shelf has cross-organization IDOR: authenticated users could read/attach another workspace's assets, tags, custodians, bookings, QR codes and audit data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47697"
    },
    {
      "rank": 1237,
      "cve_id": "CVE-2026-60775",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Pasta",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Pasta product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Pasta executes to compromise Pasta. Successful attacks of this vulnerability can result in takeover of Pasta. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60775"
    },
    {
      "rank": 1238,
      "cve_id": "CVE-2026-60776",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Object Library",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: AOL Generic Loader). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Application Object Library executes to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in takeover of Oracle Application Object Library. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60776"
    },
    {
      "rank": 1239,
      "cve_id": "CVE-2026-63259",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.0804,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-639",
      "title": "Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63259"
    },
    {
      "rank": 1240,
      "cve_id": "CVE-2026-62513",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Regulatory Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Regulatory Management. While the vulnerability is in Oracle Process Manufacturing Regulatory Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Process Manufacturing Regulatory Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Process Manufacturing Regulatory Management accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62513"
    },
    {
      "rank": 1241,
      "cve_id": "CVE-2026-62565",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (US)",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Year End). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (US) accessible data as well as unauthorized update, insert or delete access to some of Oracle HRMS (US) accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62565"
    },
    {
      "rank": 1242,
      "cve_id": "CVE-2026-47251",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-125",
      "title": "libheif has an incomplete fix for CVE-2026-3949: integer overflow bypass in vvdec_push_data2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47251"
    },
    {
      "rank": 1243,
      "cve_id": "CVE-2026-60527",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00179,
      "epss_percentile": 0.07727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebLogic Server executes to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60527"
    },
    {
      "rank": 1244,
      "cve_id": "CVE-2026-34316",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Service Center",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Service Center. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Service Center, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Service Center accessible data as well as unauthorized read access to a subset of Oracle Commerce Service Center accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34316"
    },
    {
      "rank": 1245,
      "cve_id": "CVE-2026-60146",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Access Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Access Manager accessible data as well as unauthorized read access to a subset of Oracle Access Manager accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60146"
    },
    {
      "rank": 1246,
      "cve_id": "CVE-2026-61254",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.0773,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (Republic of Korea)",
      "cwe": "CWE-601",
      "title": "Vulnerability in the Oracle HRMS (Republic of Korea) product of Oracle E-Business Suite (component: Korean Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HRMS (Republic of Korea). Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (Republic of Korea) accessible data as well as unauthorized read access to a subset of Oracle HRMS (Republic of Korea) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61254"
    },
    {
      "rank": 1247,
      "cve_id": "CVE-2026-11925",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00178,
      "epss_percentile": 0.07625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tanium",
      "product": "Tanium Server",
      "cwe": "CWE-451",
      "title": "Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Tanium Server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11925"
    },
    {
      "rank": 1248,
      "cve_id": "CVE-2026-60646",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00177,
      "epss_percentile": 0.07533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-79",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60646"
    },
    {
      "rank": 1249,
      "cve_id": "CVE-2026-60650",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00177,
      "epss_percentile": 0.07533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-20",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60650"
    },
    {
      "rank": 1250,
      "cve_id": "CVE-2026-56580",
      "cvss_base": 2.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00177,
      "epss_percentile": 0.07522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "MyCloud",
      "cwe": "CWE-1104",
      "title": "HCL MyCloud was affected by Using Components with Known Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56580"
    },
    {
      "rank": 1251,
      "cve_id": "CVE-2026-60163",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00176,
      "epss_percentile": 0.07468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60163"
    },
    {
      "rank": 1252,
      "cve_id": "CVE-2026-47015",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00176,
      "epss_percentile": 0.07394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PeopleTools",
      "cwe": "CWE-601",
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). The supported version that is affected is 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47015"
    },
    {
      "rank": 1253,
      "cve_id": "CVE-2026-15829",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "MCP Toolbox for Databases (googleapis/mcp-toolbox)",
      "cwe": "CWE-89",
      "title": "SQL Injection and Security Boundary Bypass in googleapis/mcp-toolbox",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15829"
    },
    {
      "rank": 1254,
      "cve_id": "CVE-2026-60238",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Coherence accessible data as well as unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60238"
    },
    {
      "rank": 1255,
      "cve_id": "CVE-2026-61174",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00174,
      "epss_percentile": 0.07163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Product Lifecycle Analytics",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Product Lifecycle Analytics executes to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 9.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61174"
    },
    {
      "rank": 1256,
      "cve_id": "CVE-2026-16397",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-1021",
      "title": "Clickjacking issue in the WebExtensions component in Firefox for Android",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16397"
    },
    {
      "rank": 1257,
      "cve_id": "CVE-2026-56146",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-863",
      "title": "Improper Access Control in Kibana Leading to Unauthorized Data Modification and Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56146"
    },
    {
      "rank": 1258,
      "cve_id": "CVE-2026-16381",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00173,
      "epss_percentile": 0.07126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-346",
      "title": "Same-origin policy bypass in the Networking: DNS component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16381"
    },
    {
      "rank": 1259,
      "cve_id": "CVE-2026-61097",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00172,
      "epss_percentile": 0.07013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Banking Trade Finance Process Management",
      "cwe": "CWE-601",
      "title": "Vulnerability in the Oracle Banking Trade Finance Process Management product of Oracle Financial Services Applications (component: Common). Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Trade Finance Process Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Trade Finance Process Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance Process Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Banking Trade Finance Process Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Trade Finance Process Management. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61097"
    },
    {
      "rank": 1260,
      "cve_id": "CVE-2026-61220",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Banking Origination",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Configuration). The supported version that is affected is 14.5.0.16.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Origination, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Origination accessible data as well as unauthorized read access to a subset of Oracle Banking Origination accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61220"
    },
    {
      "rank": 1261,
      "cve_id": "CVE-2026-60282",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Coherence accessible data as well as unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60282"
    },
    {
      "rank": 1262,
      "cve_id": "CVE-2026-62482",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Public Sector Financials",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Public Sector Financials accessible data as well as unauthorized read access to a subset of Oracle Public Sector Financials accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62482"
    },
    {
      "rank": 1263,
      "cve_id": "CVE-2026-56584",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "IntelliOps Event Management",
      "cwe": "CWE-200",
      "title": "HCL IEM was affected with the Information disclosure nginx server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56584"
    },
    {
      "rank": 1264,
      "cve_id": "CVE-2026-63142",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-863",
      "title": "Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63142"
    },
    {
      "rank": 1265,
      "cve_id": "CVE-2026-47011",
      "cvss_base": 2.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00172,
      "epss_percentile": 0.06984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Deployment",
      "cwe": "CWE-203",
      "title": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface). Supported versions that are affected are 17.0-26.4. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 2.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47011"
    },
    {
      "rank": 1266,
      "cve_id": "CVE-2026-60600",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Project Costing",
      "cwe": "CWE-306",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Project Costing product of Oracle PeopleSoft (component: Projects). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Project Costing executes to compromise PeopleSoft Enterprise FIN Project Costing. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Project Costing. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60600"
    },
    {
      "rank": 1267,
      "cve_id": "CVE-2026-60633",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00169,
      "epss_percentile": 0.06658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-20",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60633"
    },
    {
      "rank": 1268,
      "cve_id": "CVE-2026-61204",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00168,
      "epss_percentile": 0.06525,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Program Management",
      "cwe": "CWE-269",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Program Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise FIN Program Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Program Management. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61204"
    },
    {
      "rank": 1269,
      "cve_id": "CVE-2026-63092",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "medienbaecker",
      "product": "kirby-modules",
      "cwe": "CWE-862",
      "title": "kirby-modules License Key Disclosure via modules/activate Dialog",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63092"
    },
    {
      "rank": 1270,
      "cve_id": "CVE-2026-56577",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "MyCloud",
      "cwe": "CWE-521",
      "title": "HCL MyCloud affected by Weak Password Policy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56577"
    },
    {
      "rank": 1271,
      "cve_id": "CVE-2026-60265",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60265"
    },
    {
      "rank": 1272,
      "cve_id": "CVE-2026-49092",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-863",
      "title": "Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Unauthorized Information Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49092"
    },
    {
      "rank": 1273,
      "cve_id": "CVE-2026-63262",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Kibana Leading to Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63262"
    },
    {
      "rank": 1274,
      "cve_id": "CVE-2026-47390",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-918",
      "title": "PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47390"
    },
    {
      "rank": 1275,
      "cve_id": "CVE-2026-15812",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-290",
      "title": "Kronosnet: kronosnet: access control list bypass via link id spoofing on unencrypted dynamic links",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15812"
    },
    {
      "rank": 1276,
      "cve_id": "CVE-2026-56578",
      "cvss_base": 2.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00164,
      "epss_percentile": 0.06053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "MyCloud",
      "cwe": "CWE-200",
      "title": "HCL MyCloud was affected by Server Version Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56578"
    },
    {
      "rank": 1277,
      "cve_id": "CVE-2026-14183",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Classified Listing",
      "cwe": "CWE-639",
      "title": "Classified Listing < 5.3.9 - Subscriber+ Payment Receipt Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14183"
    },
    {
      "rank": 1278,
      "cve_id": "CVE-2026-47043",
      "cvss_base": 3.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00162,
      "epss_percentile": 0.05864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47043"
    },
    {
      "rank": 1279,
      "cve_id": "CVE-2026-60631",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00161,
      "epss_percentile": 0.05788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60631"
    },
    {
      "rank": 1280,
      "cve_id": "CVE-2026-60625",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00161,
      "epss_percentile": 0.05782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Data Integrator",
      "cwe": "CWE-863",
      "title": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Studio). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Data Integrator executes to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60625"
    },
    {
      "rank": 1281,
      "cve_id": "CVE-2026-60350",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle JDeveloper",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle JDeveloper executes to compromise Oracle JDeveloper. While the vulnerability is in Oracle JDeveloper, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60350"
    },
    {
      "rank": 1282,
      "cve_id": "CVE-2026-60607",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Financial Aid",
      "cwe": "CWE-200",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: FM Need Analysis Calculator). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise CS Financial Aid executes to compromise PeopleSoft Enterprise CS Financial Aid. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Financial Aid accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60607"
    },
    {
      "rank": 1283,
      "cve_id": "CVE-2026-63145",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Kibana Leading to Machine Learning Audit Log Integrity Compromise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63145"
    },
    {
      "rank": 1284,
      "cve_id": "CVE-2026-60640",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-20",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60640"
    },
    {
      "rank": 1285,
      "cve_id": "CVE-2026-16404",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-290",
      "title": "Spoofing issue in Firefox for Android",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16404"
    },
    {
      "rank": 1286,
      "cve_id": "CVE-2026-60723",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Data Integrator",
      "cwe": "CWE-863",
      "title": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Market Place). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Data Integrator executes to compromise Oracle Data Integrator. While the vulnerability is in Oracle Data Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Data Integrator accessible data as well as unauthorized access to critical data or complete access to all Oracle Data Integrator accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60723"
    },
    {
      "rank": 1287,
      "cve_id": "CVE-2026-60837",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Price Protection",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Price Protection executes to compromise Oracle Price Protection. While the vulnerability is in Oracle Price Protection, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Price Protection accessible data as well as unauthorized access to critical data or complete access to all Oracle Price Protection accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60837"
    },
    {
      "rank": 1288,
      "cve_id": "CVE-2026-15370",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-121",
      "title": "Libssh: libssh: stack buffer overflow in sftp server longname construction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15370"
    },
    {
      "rank": 1289,
      "cve_id": "CVE-2026-56579",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00156,
      "epss_percentile": 0.05319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "MyCloud",
      "cwe": "CWE-200",
      "title": "HCL MyCloud was affected with Exposure of Sensitive Information to an Unauthorized Actor.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56579"
    },
    {
      "rank": 1290,
      "cve_id": "CVE-2026-60635",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.0516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-79",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60635"
    },
    {
      "rank": 1291,
      "cve_id": "CVE-2026-60636",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.0516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-20",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60636"
    },
    {
      "rank": 1292,
      "cve_id": "CVE-2026-60639",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.0516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-20",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60639"
    },
    {
      "rank": 1293,
      "cve_id": "CVE-2026-56587",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00155,
      "epss_percentile": 0.05199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "IntelliOps Event Management",
      "cwe": "CWE-523",
      "title": "HCL IEM was affected with Strict transport security not enforced",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56587"
    },
    {
      "rank": 1294,
      "cve_id": "CVE-2026-16422",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.05079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged network position to perform domain spoofing via malicious network traffic. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16422"
    },
    {
      "rank": 1295,
      "cve_id": "CVE-2026-62443",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.0506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Contracts Integration",
      "cwe": "CWE-352",
      "title": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Contracts Integration accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Contracts Integration. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62443"
    },
    {
      "rank": 1296,
      "cve_id": "CVE-2026-60712",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": "CWE-862",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60712"
    },
    {
      "rank": 1297,
      "cve_id": "CVE-2026-60595",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Pay/Bill Management",
      "cwe": "CWE-306",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Pay/Bill Management product of Oracle PeopleSoft (component: Paybill Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Pay/Bill Management executes to compromise PeopleSoft Enterprise FIN Pay/Bill Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Pay/Bill Management accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60595"
    },
    {
      "rank": 1298,
      "cve_id": "CVE-2026-60596",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00153,
      "epss_percentile": 0.04996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN eSettlements",
      "cwe": "CWE-306",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN eSettlements executes to compromise PeopleSoft Enterprise FIN eSettlements. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise FIN eSettlements accessible data. CVSS 3.1 Base Score 2.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60596"
    },
    {
      "rank": 1299,
      "cve_id": "CVE-2026-47024",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PeopleTools",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). The supported version that is affected is 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47024"
    },
    {
      "rank": 1300,
      "cve_id": "CVE-2026-47048",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PeopleTools",
      "cwe": "CWE-601",
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47048"
    },
    {
      "rank": 1301,
      "cve_id": "CVE-2026-47051",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PeopleTools",
      "cwe": "CWE-601",
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47051"
    },
    {
      "rank": 1302,
      "cve_id": "CVE-2026-46948",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Utilities Network Management System",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Security). Supported versions that are affected are 2.4.0.1.0-2.4.0.1.32, 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.2.0-2.6.0.2.7 and 25.12.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilities Network Management System. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Utilities Network Management System accessible data as well as unauthorized read access to a subset of Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46948"
    },
    {
      "rank": 1303,
      "cve_id": "CVE-2026-14185",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPBot",
      "cwe": "CWE-862",
      "title": "WPBot AI ChatBot < 8.2.0 - Subscriber+ RAG Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14185"
    },
    {
      "rank": 1304,
      "cve_id": "CVE-2026-60763",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04773,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Applications Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Applications Manager executes to compromise Oracle Applications Manager. Successful attacks of this vulnerability can result in takeover of Oracle Applications Manager. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60763"
    },
    {
      "rank": 1305,
      "cve_id": "CVE-2026-62486",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.04762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Contracts Integration",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Contracts Integration accessible data as well as unauthorized read access to a subset of Oracle Contracts Integration accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Contracts Integration. CVSS 3.1 Base Score 5.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62486"
    },
    {
      "rank": 1306,
      "cve_id": "CVE-2026-60960",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle SDP Number Portability",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle SDP Number Portability executes to compromise Oracle SDP Number Portability. While the vulnerability is in Oracle SDP Number Portability, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle SDP Number Portability. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60960"
    },
    {
      "rank": 1307,
      "cve_id": "CVE-2026-61062",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Cash Management",
      "cwe": "CWE-269",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Cash Management product of Oracle PeopleSoft (component: Cash Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Cash Management executes to compromise PeopleSoft Enterprise FIN Cash Management. While the vulnerability is in PeopleSoft Enterprise FIN Cash Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Cash Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61062"
    },
    {
      "rank": 1308,
      "cve_id": "CVE-2026-60150",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60150"
    },
    {
      "rank": 1309,
      "cve_id": "CVE-2026-60271",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60271"
    },
    {
      "rank": 1310,
      "cve_id": "CVE-2026-60530",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HTTP Server",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_http2.so). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60530"
    },
    {
      "rank": 1311,
      "cve_id": "CVE-2026-60973",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle E-Business Tax",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle E-Business Tax executes to compromise Oracle E-Business Tax. Successful attacks of this vulnerability can result in takeover of Oracle E-Business Tax. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60973"
    },
    {
      "rank": 1312,
      "cve_id": "CVE-2026-61055",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise SCM Order Management",
      "cwe": "CWE-269",
      "title": "Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise SCM Order Management executes to compromise PeopleSoft Enterprise SCM Order Management. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise SCM Order Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61055"
    },
    {
      "rank": 1313,
      "cve_id": "CVE-2026-61090",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Project Foundation",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Project Foundation executes to compromise Oracle Project Foundation. Successful attacks of this vulnerability can result in takeover of Oracle Project Foundation. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61090"
    },
    {
      "rank": 1314,
      "cve_id": "CVE-2026-61091",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Communications Billing and Revenue Management",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: BRM Server). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Billing and Revenue Management executes to compromise Oracle Communications Billing and Revenue Management. Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61091"
    },
    {
      "rank": 1315,
      "cve_id": "CVE-2026-61126",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Communications Billing and Revenue Management",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: Platform). Supported versions that are affected are 15.0.0.0.0-15.0.1.0.0 and 15.1.0.0.0-15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Billing and Revenue Management executes to compromise Oracle Communications Billing and Revenue Management. Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61126"
    },
    {
      "rank": 1316,
      "cve_id": "CVE-2026-60658",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-352",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60658"
    },
    {
      "rank": 1317,
      "cve_id": "CVE-2026-64628",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.04715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-79",
      "title": "Grav Stored Cross-Site Scripting via Shortcode Attribute Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64628"
    },
    {
      "rank": 1318,
      "cve_id": "CVE-2026-16398",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.04628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-200",
      "title": "Site isolation issue in the Graphics component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16398"
    },
    {
      "rank": 1319,
      "cve_id": "CVE-2026-16399",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.04628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-346",
      "title": "Site isolation issue in the DOM: Navigation component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16399"
    },
    {
      "rank": 1320,
      "cve_id": "CVE-2026-64821",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thiagopena",
      "product": "djangoSIGE",
      "cwe": "CWE-352",
      "title": "djangoSIGE 1.10 CSRF via GET-based Order Cancellation Views",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64821"
    },
    {
      "rank": 1321,
      "cve_id": "CVE-2026-60760",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Asset Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Asset Management accessible data as well as unauthorized read access to a subset of Oracle Enterprise Asset Management accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60760"
    },
    {
      "rank": 1322,
      "cve_id": "CVE-2026-62489",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Contracts Integration",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Contracts Integration accessible data as well as unauthorized read access to a subset of Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62489"
    },
    {
      "rank": 1323,
      "cve_id": "CVE-2026-61162",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61162"
    },
    {
      "rank": 1324,
      "cve_id": "CVE-2026-60401",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "TimesTen In-Memory Database",
      "cwe": "CWE-284",
      "title": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60401"
    },
    {
      "rank": 1325,
      "cve_id": "CVE-2026-60893",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04545,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payroll",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Payroll executes to compromise Oracle Payroll. While the vulnerability is in Oracle Payroll, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Payroll accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60893"
    },
    {
      "rank": 1326,
      "cve_id": "CVE-2026-61111",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04544,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Object Library",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Application Object Library executes to compromise Oracle Application Object Library. While the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61111"
    },
    {
      "rank": 1327,
      "cve_id": "CVE-2026-61169",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM executes to compromise Oracle Agile PLM. While the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61169"
    },
    {
      "rank": 1328,
      "cve_id": "CVE-2026-61189",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Engineering Data Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. While the vulnerability is in Oracle Agile Engineering Data Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61189"
    },
    {
      "rank": 1329,
      "cve_id": "CVE-2026-60630",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04544,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle APEX",
      "cwe": "CWE-284",
      "title": "Vulnerability in Oracle APEX (component: Installation). Supported versions that are affected are 24.1, 24.2 and 26.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle APEX executes to compromise Oracle APEX. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle APEX accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60630"
    },
    {
      "rank": 1330,
      "cve_id": "CVE-2026-60405",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00148,
      "epss_percentile": 0.04549,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "TimesTen In-Memory Database",
      "cwe": "CWE-200",
      "title": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60405"
    },
    {
      "rank": 1331,
      "cve_id": "CVE-2026-60847",
      "cvss_base": 3.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00148,
      "epss_percentile": 0.04504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Order Entry",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Order Entry product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Order Entry executes to compromise Oracle Order Entry. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Order Entry accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Order Entry. CVSS 3.1 Base Score 3.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60847"
    },
    {
      "rank": 1332,
      "cve_id": "CVE-2026-47425",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04464,
      "kev": false,
      "kev_due_at": null,
      "vendor": "conda",
      "product": "rattler",
      "cwe": "CWE-22",
      "title": "Rattler vulnerable to entry-point path traversal in noarch:python install (arbitrary file write)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47425"
    },
    {
      "rank": 1333,
      "cve_id": "CVE-2026-61082",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Connectors",
      "cwe": "CWE-200",
      "title": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61082"
    },
    {
      "rank": 1334,
      "cve_id": "CVE-2026-64613",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::Buffer::Shared",
      "cwe": "CWE-59",
      "title": "Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOLLOW",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64613"
    },
    {
      "rank": 1335,
      "cve_id": "CVE-2026-62517",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Production Scheduling",
      "cwe": "CWE-345",
      "title": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Production Scheduling. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62517"
    },
    {
      "rank": 1336,
      "cve_id": "CVE-2026-60449",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebCenter Content executes to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60449"
    },
    {
      "rank": 1337,
      "cve_id": "CVE-2026-61132",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.04298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Platform",
      "cwe": "CWE-352",
      "title": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61132"
    },
    {
      "rank": 1338,
      "cve_id": "CVE-2026-47050",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47050"
    },
    {
      "rank": 1339,
      "cve_id": "CVE-2026-61052",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Solaris",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61052"
    },
    {
      "rank": 1340,
      "cve_id": "CVE-2026-56585",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "IntelliOps Event Management",
      "cwe": "CWE-693",
      "title": "HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56585"
    },
    {
      "rank": 1341,
      "cve_id": "CVE-2026-60762",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.04221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Applications Technology Stack",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Configuration). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Applications Technology Stack executes to compromise Oracle Applications Technology Stack. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Applications Technology Stack accessible data as well as unauthorized access to critical data or complete access to all Oracle Applications Technology Stack accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60762"
    },
    {
      "rank": 1342,
      "cve_id": "CVE-2026-59776",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00143,
      "epss_percentile": 0.04079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sony Corporation",
      "product": "FeliCa IC chips",
      "cwe": "CWE-325",
      "title": "Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, information stored in the IC chip may be read or tampered with.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59776"
    },
    {
      "rank": 1343,
      "cve_id": "CVE-2026-47022",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00143,
      "epss_percentile": 0.04058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "GoldenGate Stream Analytics",
      "cwe": "CWE-400",
      "title": "Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security). The supported version that is affected is 26.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where GoldenGate Stream Analytics executes to compromise GoldenGate Stream Analytics. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of GoldenGate Stream Analytics. CVSS 3.1 Base Score 3.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47022"
    },
    {
      "rank": 1344,
      "cve_id": "CVE-2026-8284",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Universal Software Inc.",
      "product": "FlexCity",
      "cwe": "CWE-601",
      "title": "Open Redirect in Universal Sotware's FlexCity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8284"
    },
    {
      "rank": 1345,
      "cve_id": "CVE-2026-60310",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Performance Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Performance Management product of Oracle E-Business Suite (component: Appraisals). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Performance Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Performance Management accessible data as well as unauthorized read access to a subset of Oracle Performance Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60310"
    },
    {
      "rank": 1346,
      "cve_id": "CVE-2026-60569",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Cluster",
      "cwe": "CWE-306",
      "title": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that are affected are 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Cluster executes to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Cluster accessible data. CVSS 3.1 Base Score 5.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60569"
    },
    {
      "rank": 1347,
      "cve_id": "CVE-2026-60248",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0014,
      "epss_percentile": 0.03878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60248"
    },
    {
      "rank": 1348,
      "cve_id": "CVE-2026-62561",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.03853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (US)",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HRMS (US) executes to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (US). CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62561"
    },
    {
      "rank": 1349,
      "cve_id": "CVE-2026-60526",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE",
      "cwe": "CWE-20",
      "title": "Vulnerability in Oracle Java SE (component: Installation). Supported versions that are affected are Oracle Java SE: 8u491 and 8u491-perf. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Java SE executes to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60526"
    },
    {
      "rank": 1350,
      "cve_id": "CVE-2026-24232",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Tranformers4Rec",
      "cwe": "CWE-502",
      "title": "NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24232"
    },
    {
      "rank": 1351,
      "cve_id": "CVE-2026-56583",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0014,
      "epss_percentile": 0.03865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "MyCloud",
      "cwe": "CWE-613",
      "title": "HCL MyCloud was affected with Concurrent Login Vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56583"
    },
    {
      "rank": 1352,
      "cve_id": "CVE-2026-59146",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::SpatialHash::Shared",
      "cwe": "CWE-125",
      "title": "Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sph_walk_cell and sph_alloc_slot",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59146"
    },
    {
      "rank": 1353,
      "cve_id": "CVE-2026-60886",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Work in Process",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Work in Process, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Work in Process accessible data as well as unauthorized update, insert or delete access to some of Oracle Work in Process accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60886"
    },
    {
      "rank": 1354,
      "cve_id": "CVE-2026-60713",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data as well as unauthorized read access to a subset of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60713"
    },
    {
      "rank": 1355,
      "cve_id": "CVE-2026-60181",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Configurator). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60181"
    },
    {
      "rank": 1356,
      "cve_id": "CVE-2026-60319",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Data Integrator",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Data Integrator executes to compromise Oracle Data Integrator. While the vulnerability is in Oracle Data Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Data Integrator accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60319"
    },
    {
      "rank": 1357,
      "cve_id": "CVE-2026-60747",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.2 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60747"
    },
    {
      "rank": 1358,
      "cve_id": "CVE-2026-14184",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Academy LMS",
      "cwe": "CWE-639",
      "title": "Academy LMS < 3.8.1 - Subscriber+ Cross-User Lesson Note and Progress Modification via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14184"
    },
    {
      "rank": 1359,
      "cve_id": "CVE-2026-60318",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00138,
      "epss_percentile": 0.03657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Data Integrator",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Data Integrator executes to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Data Integrator accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60318"
    },
    {
      "rank": 1360,
      "cve_id": "CVE-2026-65069",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.0358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::DisjointSet::Shared",
      "cwe": "CWE-59",
      "title": "Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65069"
    },
    {
      "rank": 1361,
      "cve_id": "CVE-2026-60183",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-269",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60183"
    },
    {
      "rank": 1362,
      "cve_id": "CVE-2026-60331",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60331"
    },
    {
      "rank": 1363,
      "cve_id": "CVE-2026-60332",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication GCS). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60332"
    },
    {
      "rank": 1364,
      "cve_id": "CVE-2026-61023",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Inventory Management",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Inventory Management executes to compromise Oracle Inventory Management. Successful attacks of this vulnerability can result in takeover of Oracle Inventory Management. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61023"
    },
    {
      "rank": 1365,
      "cve_id": "CVE-2026-60608",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Financial Aid",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Institutional Methodology Need Analysis). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise CS Financial Aid executes to compromise PeopleSoft Enterprise CS Financial Aid. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Financial Aid accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise CS Financial Aid accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60608"
    },
    {
      "rank": 1366,
      "cve_id": "CVE-2026-61053",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.03414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Communications BRM - Elastic Charging Engine",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Diameter Gateway and SDK). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications BRM - Elastic Charging Engine executes to compromise Oracle Communications BRM - Elastic Charging Engine. Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61053"
    },
    {
      "rank": 1367,
      "cve_id": "CVE-2026-60659",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Solaris",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Solaris accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60659"
    },
    {
      "rank": 1368,
      "cve_id": "CVE-2026-60406",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.03388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "TimesTen In-Memory Database",
      "cwe": "CWE-269",
      "title": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. Successful attacks of this vulnerability can result in takeover of TimesTen In-Memory Database. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60406"
    },
    {
      "rank": 1369,
      "cve_id": "CVE-2026-61182",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.03389,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Product Lifecycle Management for Process",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Data Import). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile Product Lifecycle Management for Process executes to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61182"
    },
    {
      "rank": 1370,
      "cve_id": "CVE-2026-60162",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.03352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60162"
    },
    {
      "rank": 1371,
      "cve_id": "CVE-2026-60336",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.03399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Project Manufacturing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center). The supported version that is affected is V16. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to compromise Oracle Project Manufacturing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Manufacturing accessible data as well as unauthorized access to critical data or complete access to all Oracle Project Manufacturing accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60336"
    },
    {
      "rank": 1372,
      "cve_id": "CVE-2026-61187",
      "cvss_base": 2.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00134,
      "epss_percentile": 0.03369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Engineering Data Management",
      "cwe": "CWE-404",
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 2.8 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61187"
    },
    {
      "rank": 1373,
      "cve_id": "CVE-2026-61303",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00134,
      "epss_percentile": 0.03329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle EDI Gateway",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle EDI Gateway executes to compromise Oracle EDI Gateway. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle EDI Gateway accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61303"
    },
    {
      "rank": 1374,
      "cve_id": "CVE-2026-61217",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Security Service",
      "cwe": "CWE-290",
      "title": "Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: Oracle SSL API). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Security Service. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Security Service accessible data as well as unauthorized access to critical data or complete access to all Oracle Security Service accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61217"
    },
    {
      "rank": 1375,
      "cve_id": "CVE-2026-60501",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Service Delivery Platform executes to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Service Delivery Platform accessible data as well as unauthorized read access to a subset of Service Delivery Platform accessible data. CVSS 3.1 Base Score 5.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60501"
    },
    {
      "rank": 1376,
      "cve_id": "CVE-2026-61084",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle GoldenGate",
      "cwe": "CWE-284",
      "title": "Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle GoldenGate accessible data as well as unauthorized read access to a subset of Oracle GoldenGate accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61084"
    },
    {
      "rank": 1377,
      "cve_id": "CVE-2026-60913",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00133,
      "epss_percentile": 0.03317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Property Manager",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Property Manager executes to compromise Oracle Property Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Property Manager accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60913"
    },
    {
      "rank": 1378,
      "cve_id": "CVE-2026-60172",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Autonomous Health Framework",
      "cwe": "CWE-284",
      "title": "Vulnerability in Oracle Autonomous Health Framework (component: Developer triaging platform). Supported versions that are affected are 26.0.0, 26.1.0 and 26.2.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework executes to compromise Oracle Autonomous Health Framework. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Autonomous Health Framework. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60172"
    },
    {
      "rank": 1379,
      "cve_id": "CVE-2026-61147",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.0321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 6.2 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61147"
    },
    {
      "rank": 1380,
      "cve_id": "CVE-2026-60337",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.03176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Project Manufacturing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center). The supported version that is affected is V16. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to compromise Oracle Project Manufacturing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Project Manufacturing accessible data as well as unauthorized update, insert or delete access to some of Oracle Project Manufacturing accessible data. CVSS 3.1 Base Score 4.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60337"
    },
    {
      "rank": 1381,
      "cve_id": "CVE-2026-61191",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.03158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Engineering Data Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Document Management). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile Engineering Data Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 4.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61191"
    },
    {
      "rank": 1382,
      "cve_id": "CVE-2026-47016",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00131,
      "epss_percentile": 0.0314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Integration",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Event Publish and Subscribe). Supported versions that are affected are 17.0-26.4. Difficult to exploit vulnerability allows physical access to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel CRM Integration accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47016"
    },
    {
      "rank": 1383,
      "cve_id": "CVE-2026-60833",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.03079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Solaris",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60833"
    },
    {
      "rank": 1384,
      "cve_id": "CVE-2026-61043",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Production Scheduling",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Production Scheduling executes to compromise Oracle Production Scheduling. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Production Scheduling, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Production Scheduling accessible data as well as unauthorized read access to a subset of Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 6.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61043"
    },
    {
      "rank": 1385,
      "cve_id": "CVE-2026-10679",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-369",
      "title": "Divide-by-zero in DesignWare SPI driver reachable from spi_transceive syscall (local DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10679"
    },
    {
      "rank": 1386,
      "cve_id": "CVE-2023-37508",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0013,
      "epss_percentile": 0.03057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "DevOps Plan",
      "cwe": "CWE-79",
      "title": "HCL DevOps Plan is susceptible to a Cross-Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-37508"
    },
    {
      "rank": 1387,
      "cve_id": "CVE-2026-61028",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0013,
      "epss_percentile": 0.03057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Inventory Management",
      "cwe": "CWE-404",
      "title": "Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Inventory Management executes to compromise Oracle Inventory Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Inventory Management. CVSS 3.1 Base Score 1.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61028"
    },
    {
      "rank": 1388,
      "cve_id": "CVE-2026-47395",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.02985,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-200",
      "title": "PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47395"
    },
    {
      "rank": 1389,
      "cve_id": "CVE-2026-60160",
      "cvss_base": 3.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00129,
      "epss_percentile": 0.02972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60160"
    },
    {
      "rank": 1390,
      "cve_id": "CVE-2026-61096",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00129,
      "epss_percentile": 0.02998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61096"
    },
    {
      "rank": 1391,
      "cve_id": "CVE-2026-60703",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Interaction Blending",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Interaction Blending executes to compromise Oracle Interaction Blending. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Interaction Blending accessible data as well as unauthorized access to critical data or complete access to all Oracle Interaction Blending accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60703"
    },
    {
      "rank": 1392,
      "cve_id": "CVE-2026-47000",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00127,
      "epss_percentile": 0.02783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-352",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Security Framework). The supported version that is affected is 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 3.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47000"
    },
    {
      "rank": 1393,
      "cve_id": "CVE-2026-61101",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle MES for Process Manufacturing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MES for Process Manufacturing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle MES for Process Manufacturing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle MES for Process Manufacturing accessible data as well as unauthorized update, insert or delete access to some of Oracle MES for Process Manufacturing accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61101"
    },
    {
      "rank": 1394,
      "cve_id": "CVE-2026-47041",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47041"
    },
    {
      "rank": 1395,
      "cve_id": "CVE-2026-15226",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02655,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "snapd",
      "cwe": "CWE-250",
      "title": "snapd snap-confine Sandbox Confinement Bypass via Omission of setuid Restriction in Seccomp Templates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15226"
    },
    {
      "rank": 1396,
      "cve_id": "CVE-2026-60685",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iSupport",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iSupport, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle iSupport accessible data as well as unauthorized read access to a subset of Oracle iSupport accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60685"
    },
    {
      "rank": 1397,
      "cve_id": "CVE-2026-60842",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Knowledge Management",
      "cwe": "CWE-285",
      "title": "Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Search). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Knowledge Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Knowledge Management accessible data as well as unauthorized read access to a subset of Oracle Knowledge Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60842"
    },
    {
      "rank": 1398,
      "cve_id": "CVE-2026-62487",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.0266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Contracts Integration",
      "cwe": "CWE-352",
      "title": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Contracts Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Contracts Integration accessible data as well as unauthorized read access to a subset of Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62487"
    },
    {
      "rank": 1399,
      "cve_id": "CVE-2026-60321",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Project Manufacturing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center). The supported version that is affected is V16. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to compromise Oracle Project Manufacturing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Manufacturing accessible data as well as unauthorized access to critical data or complete access to all Oracle Project Manufacturing accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60321"
    },
    {
      "rank": 1400,
      "cve_id": "CVE-2026-61253",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.0266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (Japanese)",
      "cwe": "CWE-352",
      "title": "Vulnerability in the Oracle HRMS (Japanese) product of Oracle E-Business Suite (component: Oracle Payroll Japanese). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HRMS (Japanese). Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (Japanese) accessible data as well as unauthorized read access to a subset of Oracle HRMS (Japanese) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61253"
    },
    {
      "rank": 1401,
      "cve_id": "CVE-2026-60149",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Workflow",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Workflow executes to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Workflow as well as unauthorized update, insert or delete access to some of Oracle Workflow accessible data and unauthorized read access to a subset of Oracle Workflow accessible data. CVSS 3.1 Base Score 5.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60149"
    },
    {
      "rank": 1402,
      "cve_id": "CVE-2026-60191",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60191"
    },
    {
      "rank": 1403,
      "cve_id": "CVE-2026-63358",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02543,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FileGator",
      "product": "FileGator",
      "cwe": "CWE-732",
      "title": "FileGator privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63358"
    },
    {
      "rank": 1404,
      "cve_id": "CVE-2026-60938",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.02527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Labor Distribution",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Labor Distribution executes to compromise Oracle Labor Distribution. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Labor Distribution accessible data. CVSS 3.1 Base Score 4.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60938"
    },
    {
      "rank": 1405,
      "cve_id": "CVE-2026-60761",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Applications DBA",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Applications DBA executes to compromise Oracle Applications DBA. While the vulnerability is in Oracle Applications DBA, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications DBA accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60761"
    },
    {
      "rank": 1406,
      "cve_id": "CVE-2026-65065",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.0251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::RoaringBitmap::Shared",
      "cwe": "CWE-732",
      "title": "Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65065"
    },
    {
      "rank": 1407,
      "cve_id": "CVE-2026-61047",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00123,
      "epss_percentile": 0.02518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Production Scheduling",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Production Scheduling executes to compromise Oracle Production Scheduling. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 1.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61047"
    },
    {
      "rank": 1408,
      "cve_id": "CVE-2026-63729",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TeX Live",
      "product": "TeX Live",
      "cwe": "CWE-416",
      "title": "TeX Live SyncTeX Parser Heap Use-After-Free via Malformed SyncTeX File",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63729"
    },
    {
      "rank": 1409,
      "cve_id": "CVE-2026-60161",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-362",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60161"
    },
    {
      "rank": 1410,
      "cve_id": "CVE-2026-56586",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "IntelliOps Event Management",
      "cwe": "CWE-16",
      "title": "HCL IEM was affected with X-Content-Type-Options Header Missing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56586"
    },
    {
      "rank": 1411,
      "cve_id": "CVE-2026-60896",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00122,
      "epss_percentile": 0.02318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Work in Process",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Work in Process executes to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Work in Process accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Work in Process. CVSS 3.1 Base Score 3.6 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60896"
    },
    {
      "rank": 1412,
      "cve_id": "CVE-2026-60661",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.02301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Solaris",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60661"
    },
    {
      "rank": 1413,
      "cve_id": "CVE-2026-61061",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.02294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle JDeveloper",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle JDeveloper executes to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61061"
    },
    {
      "rank": 1414,
      "cve_id": "CVE-2026-61120",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.02301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (US)",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HRMS (US) executes to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (US). CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61120"
    },
    {
      "rank": 1415,
      "cve_id": "CVE-2026-47047",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47047"
    },
    {
      "rank": 1416,
      "cve_id": "CVE-2026-47054",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability applies to Windows host only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47054"
    },
    {
      "rank": 1417,
      "cve_id": "CVE-2026-61077",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise SCM Mobile Inventory Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise SCM Mobile Inventory Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise SCM Mobile Inventory Management executes to compromise PeopleSoft Enterprise SCM Mobile Inventory Management. While the vulnerability is in PeopleSoft Enterprise SCM Mobile Inventory Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Mobile Inventory Management accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Mobile Inventory Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61077"
    },
    {
      "rank": 1418,
      "cve_id": "CVE-2026-61226",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Communications Converged Application Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: RTP Proxy). The supported version that is affected is 8.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Converged Application Server executes to compromise Oracle Communications Converged Application Server. While the vulnerability is in Oracle Communications Converged Application Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61226"
    },
    {
      "rank": 1419,
      "cve_id": "CVE-2026-61063",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00119,
      "epss_percentile": 0.02114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise SCM Supplier Contract Management",
      "cwe": "CWE-269",
      "title": "Vulnerability in the PeopleSoft Enterprise SCM Supplier Contract Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise SCM Supplier Contract Management executes to compromise PeopleSoft Enterprise SCM Supplier Contract Management. While the vulnerability is in PeopleSoft Enterprise SCM Supplier Contract Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise SCM Supplier Contract Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61063"
    },
    {
      "rank": 1420,
      "cve_id": "CVE-2026-60454",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00119,
      "epss_percentile": 0.02114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HTTP Server",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60454"
    },
    {
      "rank": 1421,
      "cve_id": "CVE-2026-60570",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00119,
      "epss_percentile": 0.02115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle GoldenGate",
      "cwe": "CWE-284",
      "title": "Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60570"
    },
    {
      "rank": 1422,
      "cve_id": "CVE-2026-60409",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "TimesTen In-Memory Database",
      "cwe": "CWE-284",
      "title": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of TimesTen In-Memory Database accessible data as well as unauthorized read access to a subset of TimesTen In-Memory Database accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of TimesTen In-Memory Database. CVSS 3.1 Base Score 5.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60409"
    },
    {
      "rank": 1423,
      "cve_id": "CVE-2026-59846",
      "cvss_base": 3.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00119,
      "epss_percentile": 0.02121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-78",
      "title": "Libssh: libssh: information disclosure via proxycommand %r username expansion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59846"
    },
    {
      "rank": 1424,
      "cve_id": "CVE-2026-64614",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00119,
      "epss_percentile": 0.02084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::Deque::Shared",
      "cwe": "CWE-59",
      "title": "Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64614"
    },
    {
      "rank": 1425,
      "cve_id": "CVE-2026-64615",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00119,
      "epss_percentile": 0.02084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::Graph::Shared",
      "cwe": "CWE-59",
      "title": "Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64615"
    },
    {
      "rank": 1426,
      "cve_id": "CVE-2026-60383",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.01998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Service Delivery Platform executes to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Service Delivery Platform accessible data as well as unauthorized access to critical data or complete access to all Service Delivery Platform accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60383"
    },
    {
      "rank": 1427,
      "cve_id": "CVE-2026-62469",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.01997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Human Resources",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Enterprise Command Center). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Human Resources executes to compromise Oracle Human Resources. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Human Resources accessible data as well as unauthorized access to critical data or complete access to all Oracle Human Resources accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62469"
    },
    {
      "rank": 1428,
      "cve_id": "CVE-2026-60626",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.02009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": "CWE-284",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). The supported version that is affected is 9.2.26.3. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools. While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.0 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60626"
    },
    {
      "rank": 1429,
      "cve_id": "CVE-2026-47055",
      "cvss_base": 3.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00118,
      "epss_percentile": 0.02009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47055"
    },
    {
      "rank": 1430,
      "cve_id": "CVE-2026-60642",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Content. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60642"
    },
    {
      "rank": 1431,
      "cve_id": "CVE-2026-64617",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00117,
      "epss_percentile": 0.01936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::PubSub::Shared",
      "cwe": "CWE-59",
      "title": "Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64617"
    },
    {
      "rank": 1432,
      "cve_id": "CVE-2026-65061",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00117,
      "epss_percentile": 0.01936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::ReqRep::Shared",
      "cwe": "CWE-59",
      "title": "Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65061"
    },
    {
      "rank": 1433,
      "cve_id": "CVE-2026-65062",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00117,
      "epss_percentile": 0.01936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::SortedSet::Shared",
      "cwe": "CWE-59",
      "title": "Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65062"
    },
    {
      "rank": 1434,
      "cve_id": "CVE-2026-65063",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00117,
      "epss_percentile": 0.01937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::RadixTree::Shared",
      "cwe": "CWE-59",
      "title": "Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65063"
    },
    {
      "rank": 1435,
      "cve_id": "CVE-2026-65064",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00117,
      "epss_percentile": 0.01938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::HashMap::Shared",
      "cwe": "CWE-59",
      "title": "Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65064"
    },
    {
      "rank": 1436,
      "cve_id": "CVE-2026-65066",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00117,
      "epss_percentile": 0.01937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::RingBuffer::Shared",
      "cwe": "CWE-59",
      "title": "Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65066"
    },
    {
      "rank": 1437,
      "cve_id": "CVE-2026-65067",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00117,
      "epss_percentile": 0.01938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::Intern::Shared",
      "cwe": "CWE-59",
      "title": "Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65067"
    },
    {
      "rank": 1438,
      "cve_id": "CVE-2026-65068",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00117,
      "epss_percentile": 0.01936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::SpatialHash::Shared",
      "cwe": "CWE-59",
      "title": "Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65068"
    },
    {
      "rank": 1439,
      "cve_id": "CVE-2026-64616",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00117,
      "epss_percentile": 0.01937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGOR",
      "product": "Data::NDArray::Shared",
      "cwe": "CWE-59",
      "title": "Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64616"
    },
    {
      "rank": 1440,
      "cve_id": "CVE-2026-47044",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47044"
    },
    {
      "rank": 1441,
      "cve_id": "CVE-2026-47007",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Communications Pricing Design Center",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise Deployment). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Pricing Design Center executes to compromise Oracle Communications Pricing Design Center. While the vulnerability is in Oracle Communications Pricing Design Center, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Pricing Design Center accessible data as well as unauthorized update, insert or delete access to some of Oracle Communications Pricing Design Center accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47007"
    },
    {
      "rank": 1442,
      "cve_id": "CVE-2026-60155",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00114,
      "epss_percentile": 0.01719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60155"
    },
    {
      "rank": 1443,
      "cve_id": "CVE-2026-60159",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00114,
      "epss_percentile": 0.01726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60159"
    },
    {
      "rank": 1444,
      "cve_id": "CVE-2026-60245",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00114,
      "epss_percentile": 0.01758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60245"
    },
    {
      "rank": 1445,
      "cve_id": "CVE-2026-60911",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Property Manager",
      "cwe": "CWE-285",
      "title": "Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Property Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Property Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Property Manager accessible data as well as unauthorized read access to a subset of Oracle Property Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60911"
    },
    {
      "rank": 1446,
      "cve_id": "CVE-2026-60957",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Transportation Execution",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Execution. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Transportation Execution, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Transportation Execution accessible data as well as unauthorized read access to a subset of Oracle Transportation Execution accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60957"
    },
    {
      "rank": 1447,
      "cve_id": "CVE-2026-60962",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Flow Manufacturing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Flow Manufacturing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Flow Manufacturing accessible data as well as unauthorized read access to a subset of Oracle Flow Manufacturing accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60962"
    },
    {
      "rank": 1448,
      "cve_id": "CVE-2026-62574",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Install). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition executes to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62574"
    },
    {
      "rank": 1449,
      "cve_id": "CVE-2026-60601",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Common Objects",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Common Objects executes to compromise PeopleSoft Enterprise FIN Common Objects. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Common Objects accessible data. CVSS 3.1 Base Score 4.4 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60601"
    },
    {
      "rank": 1450,
      "cve_id": "CVE-2026-60891",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00112,
      "epss_percentile": 0.01553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Work in Process",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Work in Process executes to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Work in Process accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60891"
    },
    {
      "rank": 1451,
      "cve_id": "CVE-2026-10680",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00111,
      "epss_percentile": 0.01497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-125",
      "title": "Out-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling via `uint16_t` length underflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10680"
    },
    {
      "rank": 1452,
      "cve_id": "CVE-2026-12139",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tanium",
      "product": "Connect",
      "cwe": "CWE-214",
      "title": "Tanium addressed an information disclosure vulnerability in Connect.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12139"
    },
    {
      "rank": 1453,
      "cve_id": "CVE-2026-60144",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00109,
      "epss_percentile": 0.01437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Workflow",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Workflow executes to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 3.6 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60144"
    },
    {
      "rank": 1454,
      "cve_id": "CVE-2026-60347",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00109,
      "epss_percentile": 0.01425,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": "CWE-284",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 3.6 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60347"
    },
    {
      "rank": 1455,
      "cve_id": "CVE-2026-21953",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00109,
      "epss_percentile": 0.01396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Retail Xstore Point of Service",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Retail Xstore Point of Service executes to compromise Oracle Retail Xstore Point of Service. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Retail Xstore Point of Service accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21953"
    },
    {
      "rank": 1456,
      "cve_id": "CVE-2026-62465",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (US)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HRMS (US) executes to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HRMS (US) as well as unauthorized update, insert or delete access to some of Oracle HRMS (US) accessible data and unauthorized read access to a subset of Oracle HRMS (US) accessible data. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62465"
    },
    {
      "rank": 1457,
      "cve_id": "CVE-2026-10677",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-401",
      "title": "Kernel heap memory leak in `z_vrfy_k_poll()` lets an unprivileged user thread exhaust the kernel resource pool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10677"
    },
    {
      "rank": 1458,
      "cve_id": "CVE-2026-47714",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.0129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-190",
      "title": "libheif has integer overflow in inline mask size calculation that causes undersized buffer allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47714"
    },
    {
      "rank": 1459,
      "cve_id": "CVE-2026-59845",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-390",
      "title": "Libssh: libssh: denial of service via unchecked proxycommand fork() failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59845"
    },
    {
      "rank": 1460,
      "cve_id": "CVE-2026-10674",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-617",
      "title": "DoS (hard fault) in NXP LPUART driver: unsupported runtime UART config leaves clocks disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10674"
    },
    {
      "rank": 1461,
      "cve_id": "CVE-2026-47062",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.01279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47062"
    },
    {
      "rank": 1462,
      "cve_id": "CVE-2026-46991",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.01265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Manager Base Platform executes to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46991"
    },
    {
      "rank": 1463,
      "cve_id": "CVE-2026-56582",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00103,
      "epss_percentile": 0.01106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "MyCloud",
      "cwe": "CWE-327",
      "title": "HCL MyCloud was affected with SSL/TLS Protocol Affected with LUCKY13 Vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56582"
    },
    {
      "rank": 1464,
      "cve_id": "CVE-2026-47053",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00101,
      "epss_percentile": 0.01026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-285",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 5.6 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47053"
    },
    {
      "rank": 1465,
      "cve_id": "CVE-2026-61202",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.001,
      "epss_percentile": 0.00987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Solaris",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affected are 11.3 and 11.4. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Solaris accessible data as well as unauthorized access to critical data or complete access to all Oracle Solaris accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61202"
    },
    {
      "rank": 1466,
      "cve_id": "CVE-2026-60407",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "TimesTen In-Memory Database",
      "cwe": "CWE-284",
      "title": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60407"
    },
    {
      "rank": 1467,
      "cve_id": "CVE-2026-56581",
      "cvss_base": 2.6,
      "cvss_severity": "LOW",
      "epss_score": 0.001,
      "epss_percentile": 0.00971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "MyCloud",
      "cwe": "CWE-614",
      "title": "HCL MyCloud was affected with Cookie Attribute Path Not Set",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56581"
    },
    {
      "rank": 1468,
      "cve_id": "CVE-2026-16416",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00099,
      "epss_percentile": 0.00945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-190",
      "title": "Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16416"
    },
    {
      "rank": 1469,
      "cve_id": "CVE-2024-5300",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00099,
      "epss_percentile": 0.00921,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "snapd",
      "cwe": "CWE-212",
      "title": "AppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbd",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-5300"
    },
    {
      "rank": 1470,
      "cve_id": "CVE-2026-16414",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00094,
      "epss_percentile": 0.00715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16414"
    },
    {
      "rank": 1471,
      "cve_id": "CVE-2026-60158",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00091,
      "epss_percentile": 0.00577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60158"
    },
    {
      "rank": 1472,
      "cve_id": "CVE-2026-60338",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00091,
      "epss_percentile": 0.00582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Project Manufacturing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center). The supported version that is affected is V16. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to compromise Oracle Project Manufacturing. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Project Manufacturing accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Project Manufacturing. CVSS 3.1 Base Score 3.6 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60338"
    },
    {
      "rank": 1473,
      "cve_id": "CVE-2026-61079",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00087,
      "epss_percentile": 0.00437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle GoldenGate",
      "cwe": "CWE-20",
      "title": "Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.2. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Oracle GoldenGate. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle GoldenGate accessible data as well as unauthorized update, insert or delete access to some of Oracle GoldenGate accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate. CVSS 3.1 Base Score 5.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61079"
    },
    {
      "rank": 1474,
      "cve_id": "CVE-2026-62563",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00085,
      "epss_percentile": 0.0035,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Work in Process",
      "cwe": "CWE-285",
      "title": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Work in Process, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Work in Process accessible data as well as unauthorized read access to a subset of Oracle Work in Process accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62563"
    },
    {
      "rank": 1475,
      "cve_id": "CVE-2026-47122",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00078,
      "epss_percentile": 0.0014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sparkle-project",
      "product": "Sparkle",
      "cwe": "CWE-306",
      "title": "Sparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47122"
    },
    {
      "rank": 1476,
      "cve_id": "CVE-2026-16517",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00078,
      "epss_percentile": 0.00157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-190",
      "title": "Libarchive: libarchive: signed integer overflow in archive_write_zip_header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16517"
    },
    {
      "rank": 1477,
      "cve_id": "CVE-2026-15811",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00062,
      "epss_percentile": 0.00012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-212",
      "title": "Kronosnet: kronosnet: encryption key exposure in memory after cryptographic configuration changes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15811"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-4692",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-4692 (grub). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-4693",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-4693 (Red Hat Enterprise Linux 8). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-11816",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-11816 (keras-team/keras). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13142",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13142 (Unknown Social Login, Passkeys, Magic Link & Email OTP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16324",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16324 (Metasoft 美特软件 MetaCRM). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16372",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16372 (Mozilla Firefox). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-24779",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-24779 (vllm-project vllm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25048",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25048 (mlc-ai xgrammar). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25960",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25960 (vllm-project vllm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33236",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33236 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47143",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47143 (capstone-engine capstone). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47178",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47178 (strukturag libheif). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47247",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47247 (strukturag libheif). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47251",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47251 (strukturag libheif). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47254",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47254 (strukturag libheif). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47671",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47671 (nhost cli). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47685",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47685 (fogproject). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47687",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47687 (fogproject). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47688",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47688 (fogproject). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47689",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47689 (fogproject). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47709",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47709 (strukturag libheif). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49978",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49978 (cure53 DOMPurify). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54293",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54293 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55831",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55831 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55833",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55833 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56816",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56816 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56819",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56819 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56820",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56820 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58049",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58049 (FFmpeg). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59197",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59197 (python-pillow Pillow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59204",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59204 (python-pillow Pillow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59732",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59732 (rclone). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63730",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63730 (hyperdxio hyperdx). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63731",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63731 (hyperdxio hyperdx). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63767",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63767 (kvcache-ai ktransformers). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63768",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63768 (calcom cal.diy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63769",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63769 (huginn). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63770",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63770 (glanceapp glance). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63771",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63771 (vrana adminer). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-3640",
      "detail": "RESCORED — CVE-2023-3640 (Red Hat Enterprise Linux 6). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-4692",
      "detail": "RESCORED — CVE-2023-4692 (grub). CVSS 7.5 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-4693",
      "detail": "RESCORED — CVE-2023-4693 (Red Hat Enterprise Linux 8). CVSS 5.3 → 4.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16014",
      "detail": "RESCORED — CVE-2026-16014 (code-projects Hospital Bed Management System). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16075",
      "detail": "RESCORED — CVE-2026-16075 (AstrBotDevs AstrBot). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16084",
      "detail": "RESCORED — CVE-2026-16084 (Sipeed PicoClaw). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16119",
      "detail": "RESCORED — CVE-2026-16119 (nextlevelbuilder GoClaw). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16125",
      "detail": "RESCORED — CVE-2026-16125 (zevorn rt-claw). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16131",
      "detail": "RESCORED — CVE-2026-16131 (itsourcecode Hospital Management System). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16155",
      "detail": "RESCORED — CVE-2026-16155 (SourceCodester Class and Exam Timetabling System). CVSS 5.1 → 2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16156",
      "detail": "RESCORED — CVE-2026-16156 (SourceCodester Class and Exam Timetabling System). CVSS 5.1 → 2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16198",
      "detail": "RESCORED — CVE-2026-16198 (Sipeed PicoClaw). CVSS 6.3 → 2.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16204",
      "detail": "RESCORED — CVE-2026-16204 (zevorn rt-claw). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16210",
      "detail": "RESCORED — CVE-2026-16210 (newpanjing simpleui). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16216",
      "detail": "RESCORED — CVE-2026-16216 (geex-arts django-jet). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16223",
      "detail": "RESCORED — CVE-2026-16223 (1Panel-dev CordysCRM). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16229",
      "detail": "RESCORED — CVE-2026-16229 (itsourcecode Courier Management System). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16327",
      "detail": "RESCORED — CVE-2026-16327 (D-Link DNS-320). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-22807",
      "detail": "RESCORED — CVE-2026-22807 (vllm-project vllm). CVSS 8.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-25960",
      "detail": "RESCORED — CVE-2026-25960 (vllm-project vllm). CVSS 7.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50377",
      "detail": "RESCORED — CVE-2026-50377 (Microsoft Windows 10 Version 1607). CVSS 5.5 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50485",
      "detail": "RESCORED — CVE-2026-50485 (Microsoft Windows 10 Version 1607). CVSS 4.5 → 5.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50489",
      "detail": "RESCORED — CVE-2026-50489 (Microsoft Windows 10 Version 1607). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50500",
      "detail": "RESCORED — CVE-2026-50500 (Microsoft Windows 10 Version 1607). CVSS 7.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-56169",
      "detail": "RESCORED — CVE-2026-56169 (Microsoft Windows Admin Center). CVSS 8.1 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-7754",
      "detail": "RESCORED — CVE-2026-7754 (IBM Langflow OSS). CVSS 7.7 → 6.5 (NVD)."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-46817",
      "detail": "ENRICHED — CVE-2026-46817 (Oracle E-Business Suite). Received CVSS 9.8 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
