| CVE-2026-50142 | 7.5 | 43.8 | strukturag | libheif | CWE-190 | libheif: unbounded heap allocation in HEIF sequence parser (stsz fixed-size m… |
| CVE-2026-52607 | 6.5 | 43.8 | n/a | n/a | CWE-22 | A directory traversal vulnerability in reportico-web <= 8.1.0 allows remote a… |
| CVE-2026-61241 | 10.0 | 43.3 | Oracle Corporation | Oracle Internet Directory | CWE-284 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middl… |
| CVE-2026-74990 | 9.8 | 42.7 | Mozilla | Firefox | CWE-119 | Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefo… |
| CVE-2026-73366 | 9.8 | 42.2 | supsystic | Easy Google Maps | CWE-502 | WordPress Easy Google Maps plugin <= 1.13.0 - PHP Object Injection vulnerability |
| CVE-2026-73380 | 9.8 | 42.2 | supsystic | Popup by Supsystic | CWE-502 | WordPress Popup by Supsystic plugin <= 1.13.0 - PHP Object Injection vulnerab… |
| CVE-2026-75773 | 2.9 | 42.1 | karakeep-app | karakeep | CWE-307 | karakeep-app karakeep Login Endpoint auth.ts authorize excessive authentication |
| CVE-2026-74987 | 9.8 | 42.0 | Mozilla | Firefox | CWE-119 | Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Fire… |
| CVE-2026-56684 | 7.5 | 42.0 | valkey-io | valkey | CWE-416 | Valkey: TLS pending-data processing use-after-free may allow remote code exec… |
| CVE-2026-62626 | 9.8 | 41.9 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62632 | 9.8 | 41.9 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62633 | 9.8 | 41.9 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62635 | 9.8 | 41.9 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-18963 | 9.1 | 41.8 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-640 | Keycloak-services: keycloak-services: unauthenticated account takeover via re… |
| CVE-2026-75090 | 2.1 | 41.5 | EricLBuehler | Mistral.rs | CWE-119 | EricLBuehler Mistral.rs GGUF Tokenizer gguf_tokenizer.rs convert_gguf_to_hf_t… |
| CVE-2026-73381 | 9.1 | 41.3 | supsystic | Popup by Supsystic | CWE-288 | WordPress Popup by Supsystic plugin <= 1.13.0 - Broken Authentication vulnera… |
| CVE-2026-60672 | 9.8 | 41.1 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60696 | 9.8 | 41.1 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60698 | 9.8 | 41.0 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60977 | 9.8 | 41.1 | Oracle Corporation | Oracle WebLogic Server | CWE-284 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-76040 | 8.8 | 41.0 | Google | Chrome | CWE-416 | Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 … |
| CVE-2026-60728 | 9.1 | 40.8 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-75897 | 8.7 | 40.8 | OpenSearch | OpenSearch Dashboards | CWE-1284 | Uncontrolled Resource Consumption in Capabilities Route in OpenSearch Dashboards |
| CVE-2026-75915 | 8.7 | 40.8 | Hmbown | CodeWhale | CWE-200 | CodeWhale before 0.8.64 Environment Variable Leak via js_execution |
| CVE-2026-34884 | 9.8 | 40.7 | Apache Software Foundation | Apache SkyWalking MCP | CWE-918 | Apache SkyWalking MCP: SSRF via set_skywalking_url Tool and GraphQL Expressio… |
| CVE-2026-70689 | 9.8 | 40.5 | Oracle Corporation | Oracle Essbase | — | Vulnerability in Oracle Essbase (component: Infrastructure). The supported ve… |
| CVE-2026-70820 | 7.2 | 40.5 | Oracle Corporation | Oracle Call Center Technology | CWE-284 | Vulnerability in the Oracle Call Center Technology product of Oracle E-Busine… |
| CVE-2026-76039 | 6.5 | 40.3 | Google | Chrome | CWE-706 | Incorrect reference resolution in Core in Google Chrome on on Android prior t… |
| CVE-2026-50187 | 8.8 | 40.2 | ohmyzsh | ohmyzsh | CWE-94 | Oh My Zsh: Arbitrary Code Execution in oh-my-zsh dotenv plugin via malicious … |
| CVE-2026-67440 | 6.9 | 39.9 | frangoteam | FUXA | CWE-862 | FUXA: Unauthenticated Socket.IO read events |
| CVE-2026-47720 | 5.3 | 39.9 | frangoteam | FUXA | CWE-89 | FUXA: SQL injection in TDengine DAQ connector via backslash bypass of escapeT… |
| CVE-2026-19500 | 7.5 | 39.8 | SureForms | SureForms | CWE-400 | SureForms contains an uncontrolled resource consumption vulnerability |
| CVE-2026-62457 | 9.8 | 39.7 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | CWE-284 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62544 | 9.8 | 39.7 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62609 | 9.8 | 39.7 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62611 | 9.8 | 39.7 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62614 | 9.8 | 39.7 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62617 | 9.8 | 39.7 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62621 | 9.8 | 39.7 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62622 | 9.8 | 39.7 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62624 | 9.8 | 39.7 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62630 | 9.8 | 39.7 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62634 | 9.8 | 39.7 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62639 | 9.8 | 39.7 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62640 | 9.8 | 39.7 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-70739 | 9.8 | 39.7 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70740 | 9.8 | 39.7 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70745 | 9.8 | 39.7 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70817 | 9.8 | 39.7 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70873 | 9.8 | 39.7 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-47719 | 8.2 | 39.5 | frangoteam | FUXA | CWE-918 | FUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PRO… |
| CVE-2026-17084 | 6.0 | 39.5 | Python Software Foundation | CPython | CWE-436 | stringprep.map_table_b2() deviates from RFC 3454 Table B.2 |
| CVE-2026-60858 | 9.8 | 39.4 | Oracle Corporation | Oracle Hyperion Calculation Manager | CWE-306 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-60958 | 9.8 | 39.4 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-61318 | 9.8 | 39.4 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-284 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-62592 | 9.8 | 39.4 | Oracle Corporation | Siebel CRM Integration | CWE-284 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-70926 | 9.8 | 39.4 | Oracle Corporation | Oracle Workflow | CWE-306 | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (comp… |
| CVE-2026-74012 | 8.8 | 39.4 | TaxoPress | TaxoPress | CWE-502 | WordPress TaxoPress plugin <= 3.51.0 - PHP Object Injection vulnerability |
| CVE-2026-70737 | 8.8 | 39.2 | Oracle Corporation | Oracle Enterprise Manager for Systems Infrastructure | — | Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure pro… |
| CVE-2026-70710 | 8.8 | 39.2 | Oracle Corporation | Oracle Sales Foundation | — | Vulnerability in the Oracle Sales Foundation product of Oracle E-Business Sui… |
| CVE-2026-70729 | 8.8 | 39.2 | Oracle Corporation | Oracle Teleservice | — | Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (c… |
| CVE-2026-70747 | 8.8 | 39.2 | Oracle Corporation | Oracle Customers Online | — | Vulnerability in the Oracle Customers Online product of Oracle E-Business Sui… |
| CVE-2026-70813 | 8.8 | 39.2 | Oracle Corporation | Oracle Call Center Technology | CWE-284 | Vulnerability in the Oracle Call Center Technology product of Oracle E-Busine… |
| CVE-2026-71878 | 9.2 | 39.1 | GBIF | Integrated Publishing Toolkit | CWE-306 | Authentication bypass in Integrated Publishing Toolkit |
| CVE-2026-71879 | 9.1 | 39.1 | GBIF | Integrated Publishing Toolkit | CWE-288 | Authentication bypass in Integrated Publishing Toolkit |
| CVE-2026-60821 | 9.8 | 38.8 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | CWE-284 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-63643 | 6.3 | 38.9 | MagicMirrorOrg | MagicMirror | CWE-441 | MagicMirror: ssrf calendar .js |
| CVE-2026-60721 | 9.8 | 38.8 | Oracle Corporation | Oracle Identity Manager | CWE-306 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-60727 | 9.8 | 38.8 | Oracle Corporation | Oracle Identity Manager | CWE-284 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-60921 | 9.8 | 38.8 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60946 | 9.8 | 38.8 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60947 | 9.8 | 38.8 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60970 | 9.8 | 38.8 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-70905 | 9.8 | 38.8 | Oracle Corporation | Oracle Access Manager | CWE-287 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-70854 | 9.1 | 38.8 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-61118 | 8.8 | 38.7 | Oracle Corporation | Oracle Identity Manager | CWE-284 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-65984 | 7.5 | 38.4 | frangoteam | FUXA | CWE-613 | FUXA: JWT lifecycle flaws allow deleted or demoted users to retain privileged… |
| CVE-2026-73181 | 7.5 | 38.4 | ThemeComplete | Extra Product Options & Add-Ons for WooCommerce | CWE-22 | WordPress Extra Product Options & Add-Ons for WooCommerce plugin < 7.6 - Arbi… |
| CVE-2026-74964 | 9.8 | 38.3 | Mozilla | Firefox | CWE-190 | Integer overflow in the Graphics component |
| CVE-2026-19501 | 8.8 | 38.3 | SureForms | SureForms | CWE-1236 | CVE-2026-19501 |
| CVE-2026-70876 | 9.1 | 38.2 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-70735 | 7.2 | 38.2 | Oracle Corporation | Oracle Hyperion Profitability and Cost Management | — | Vulnerability in the Oracle Hyperion Profitability and Cost Management produc… |
| CVE-2026-70781 | 7.2 | 38.2 | Oracle Corporation | Oracle Proposals | — | Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (com… |
| CVE-2026-75774 | 2.9 | 38.2 | karakeep-app | karakeep | CWE-287 | karakeep-app karakeep OAuth Sign-In auth.ts improper authentication |
| CVE-2026-67271 | 9.8 | 38.0 | Dell | PowerStore 500T | CWE-787 | Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the S… |
| CVE-2026-70700 | 7.5 | 37.9 | Oracle Corporation | Oracle Payables | — | Vulnerability in the Oracle Payables product of Oracle E-Business Suite (comp… |
| CVE-2026-47627 | 9.8 | 37.8 | NVIDIA | Triton Inference Server | CWE-22 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-70688 | 8.8 | 37.8 | Oracle Corporation | Oracle Essbase | — | Vulnerability in Oracle Essbase (component: Calculator). The supported versio… |
| CVE-2026-70906 | 7.5 | 37.4 | Oracle Corporation | Oracle Java SE | CWE-400 | Vulnerability in Oracle Java SE (component: 2D). Supported versions that are … |
| CVE-2026-60883 | 7.2 | 37.4 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | CWE-284 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-59949 | 6.5 | 37.4 | yawkat | lz4-java | CWE-476 | yawkat LZ4 Java: JVM Crash via Null Byte Array in lz4-java Streaming XXHash J… |
| CVE-2026-75852 | 9.3 | 37.3 | ArcadeData | arcadedb | CWE-306 | ArcadeDB MongoDB wire protocol authentication bypass cross-database |
| CVE-2026-60782 | 9.8 | 37.2 | Oracle Corporation | Oracle Payments | CWE-306 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (comp… |
| CVE-2026-70970 | 9.8 | 37.2 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-71040 | 9.8 | 37.2 | Oracle Corporation | Oracle Agile PLM | CWE-284 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-71074 | 9.8 | 37.2 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-71152 | 9.8 | 37.2 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-71164 | 9.8 | 37.2 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-60754 | 9.1 | 37.2 | Oracle Corporation | Siebel Apps - Marketing | CWE-284 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co… |
| CVE-2026-62292 | 8.7 | 37.2 | strukturag | libheif | CWE-125 | libheif: Out-of-bounds read in uncompressed unci tile range slicing |
| CVE-2026-76043 | 8.8 | 37.1 | Google | Chrome | CWE-682 | Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed … |
| CVE-2026-32474 | 9.9 | 37.0 | wpWax | Templatiq | CWE-434 | WordPress Templatiq plugin <= 0.2.5 - Arbitrary File Upload vulnerability |
| CVE-2026-62608 | 9.9 | 37.0 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-66627 | 9.9 | 37.0 | EDGE22 Studios Ltd. | GP Premium | CWE-434 | WordPress GP Premium plugin <= 2.5.5 - Arbitrary File Upload vulnerability |
| CVE-2026-61002 | 8.8 | 37.0 | Oracle Corporation | Oracle SOA Suite | CWE-284 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co… |
| CVE-2026-61319 | 8.8 | 37.0 | Oracle Corporation | Oracle U.S. Federal Financials | CWE-284 | Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Busin… |
| CVE-2026-62450 | 8.8 | 37.0 | Oracle Corporation | Oracle Flow Manufacturing | CWE-284 | Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business S… |
| CVE-2026-62500 | 8.8 | 37.0 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62612 | 8.8 | 37.0 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-70686 | 8.8 | 37.0 | Oracle Corporation | Oracle General Ledger | — | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite… |
| CVE-2026-70742 | 8.8 | 37.0 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70761 | 8.8 | 37.0 | Oracle Corporation | Oracle Risk Management | — | Vulnerability in the Oracle Risk Management product of Oracle E-Business Suit… |
| CVE-2026-70818 | 8.8 | 37.0 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70821 | 8.8 | 37.0 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70863 | 8.8 | 37.0 | Oracle Corporation | Oracle Application Testing Suite | CWE-284 | Vulnerability in Oracle Application Testing Suite. The supported version that… |
| CVE-2026-70877 | 8.8 | 37.0 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-52736 | 8.7 | 36.8 | ZcashFoundation | zebra | CWE-459 | ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cache |
| CVE-2026-75627 | 9.3 | 36.7 | bastillion-io | Bastillion | CWE-288 | Bastillion Authentication Bypass via Path-Prefix Routing Mismatch |
| CVE-2026-74945 | 6.5 | 36.7 | Mozilla | Firefox | CWE-200 | Information disclosure in the Graphics: Text component |
| CVE-2026-61003 | 9.9 | 36.5 | Oracle Corporation | Oracle Managed File Transfer | CWE-284 | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Mi… |
| CVE-2026-57580 | 9.4 | 36.6 | goauthentik | authentik | CWE-436 | authentik: Account Takeover via SAML NameID Comment Truncation |
| CVE-2026-62638 | 9.1 | 36.5 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-60722 | 8.8 | 36.5 | Oracle Corporation | Oracle Identity Manager | CWE-306 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-60731 | 8.8 | 36.5 | Oracle Corporation | Oracle WebCenter Portal | CWE-306 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-75935 | 8.7 | 36.5 | Amazon Ion | Amazon Ion Java | CWE-789 | Memory-amplification denial of service via declared-length preallocation in A… |
| CVE-2026-75936 | 8.7 | 36.5 | Amazon Ion | Amazon Ion Java | CWE-409 | Memory-amplification denial of service via GZIP decompression bomb in Amazon … |
| CVE-2026-70908 | 7.5 | 36.5 | Oracle Corporation | Helidon | CWE-400 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-70927 | 7.5 | 36.5 | Oracle Corporation | Oracle Workflow | CWE-400 | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (comp… |
| CVE-2026-32444 | 9.9 | 36.3 | Cwicly | Cwicly | CWE-94 | WordPress Cwicly plugin <= 1.4.4 - Remote Code Execution (RCE) vulnerability |
| CVE-2026-44472 | 8.1 | 36.4 | saleor | saleor | CWE-287 | Saleor: Account pre-hijacking vulnerability due to unverified anonymous order… |
| CVE-2026-73400 | 8.1 | 36.1 | jetmonsters | Restaurant Menu by MotoPress | CWE-98 | WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Local File Inclusio… |
| CVE-2026-18929 | 6.9 | 36.0 | Carbone | Carbone | CWE-409 | Resource Exhaustion in Carbone |
| CVE-2026-52854 | 8.6 | 35.8 | ProfessionalWiki | Maps | CWE-79 | mediawiki/maps: Stored XSS through the overlays parameter in the display_map … |
| CVE-2026-50186 | 8.8 | 35.7 | RARgames | 4gaBoards | CWE-22 | 4gaBoards: Path Traversal leading to Arbitrary File Read and Deletion in Boar… |
| CVE-2026-60716 | 8.8 | 35.8 | Oracle Corporation | Oracle Identity Manager | CWE-306 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-52829 | 7.5 | 35.7 | ZcashFoundation | zebra | CWE-617 | ZEBRA: IPv4-Mapped Mempool Misbehavior Update Aborts Zebra Address Book |
| CVE-2026-70861 | 7.2 | 35.7 | Oracle Corporation | PeopleSoft Enterprise FIN Common Objects Brazil | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product … |
| CVE-2026-71099 | 7.2 | 35.7 | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | CWE-284 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-70939 | 7.2 | 35.6 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70950 | 7.2 | 35.6 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-73997 | 7.5 | 35.4 | Nexcess | Starter Templates by Kadence WP | CWE-770 | WordPress Starter Templates by Kadence WP plugin <= 2.3.3 - Denial of Service… |
| CVE-2026-54543 | 5.4 | 35.5 | froxlor | froxlor | CWE-74 | Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields |
| CVE-2026-60737 | 9.1 | 35.2 | Oracle Corporation | Oracle Web Services Manager | CWE-284 | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Mid… |
| CVE-2026-49224 | 8.3 | 35.1 | givanz | Vvveb | CWE-639 | Vvveb post revision authorization bypass allows Authors to read, restore, or … |
| CVE-2026-49225 | 8.3 | 35.1 | givanz | Vvveb | CWE-639 | Vvveb product revision authorization bypass allows Vendors to read, restore, … |
| CVE-2026-70909 | 8.2 | 35.1 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-76035 | 9.6 | 35.0 | Google | Chrome | CWE-20 | Inappropriate implementation in Media in Google Chrome on on Mac prior to 151… |
| CVE-2026-75914 | 8.7 | 35.0 | Hmbown | CodeWhale | CWE-22 | CodeWhale before 0.8.64 Path Traversal via image_analyze symlink |
| CVE-2026-76038 | 8.8 | 35.0 | Google | Chrome | CWE-843 | Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remot… |
| CVE-2026-69219 | 8.7 | 35.0 | rabbitmq | rabbitmq-java-client | CWE-789 | RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers … |
| CVE-2026-50167 | 5.3 | 35.0 | kurrier-org | kurrier | CWE-639 | Kurrier: Authenticated cross-user authorization bypass in Kurrier API |
| CVE-2026-61302 | 8.2 | 34.9 | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | CWE-284 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-70743 | 8.2 | 34.9 | Oracle Corporation | Oracle Hyperion Financial Reporting | CWE-284 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-60976 | 8.8 | 34.5 | Oracle Corporation | Oracle Scripting | CWE-284 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (com… |
| CVE-2026-61206 | 9.9 | 34.5 | Oracle Corporation | Oracle Hyperion Calculation Manager | CWE-284 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-61317 | 9.9 | 34.5 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-284 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-70920 | 9.9 | 34.5 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-71102 | 9.1 | 34.4 | Oracle Corporation | Oracle Database Server | CWE-284 | Vulnerability in the Portable Clusterware component of Oracle Database Server… |
| CVE-2026-60751 | 8.8 | 34.5 | Oracle Corporation | Siebel Apps - Marketing | CWE-284 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co… |
| CVE-2026-61276 | 8.8 | 34.5 | Oracle Corporation | Oracle Hyperion Calculation Manager | CWE-284 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-70918 | 8.8 | 34.5 | Oracle Corporation | Oracle Product Hub | CWE-306 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c… |
| CVE-2026-70922 | 8.8 | 34.5 | Oracle Corporation | Oracle Financial Services Enterprise Case Management | CWE-287 | Vulnerability in the Oracle Financial Services Enterprise Case Management pro… |
| CVE-2026-68924 | 4.9 | 34.4 | MobSF | Mobile-Security-Framework-MobSF | CWE-400 | MobSF: Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK E… |
| CVE-2026-62550 | 7.5 | 34.3 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62554 | 7.5 | 34.3 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70752 | 7.5 | 34.3 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70772 | 7.5 | 34.3 | Oracle Corporation | Oracle Warehouse Management | CWE-284 | Vulnerability in the Oracle Warehouse Management product of Oracle E-Business… |
| CVE-2026-70799 | 7.5 | 34.3 | Oracle Corporation | Oracle SDP Number Portability | — | Vulnerability in the Oracle SDP Number Portability product of Oracle E-Busine… |
| CVE-2026-70822 | 7.5 | 34.3 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70832 | 7.5 | 34.3 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-73927 | 7.5 | 34.4 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73936 | 7.5 | 34.4 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-60707 | 8.7 | 34.3 | Oracle Corporation | Oracle Identity Manager | CWE-284 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-75859 | 8.7 | 34.2 | Hmbown | CodeWhale | CWE-22 | CodeWhale before 0.8.64 Arbitrary File Read via instructions |
| CVE-2026-60699 | 8.6 | 34.2 | Oracle Corporation | Oracle WebLogic Server | CWE-284 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-62586 | 8.6 | 34.2 | Oracle Corporation | Siebel CRM Administration | CWE-284 | Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (… |
| CVE-2026-74940 | 9.8 | 34.0 | Mozilla | Firefox | CWE-416 | Use-after-free in the Graphics: Text component |
| CVE-2026-62588 | 9.9 | 33.9 | Oracle Corporation | Siebel CRM Integration | CWE-284 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-60715 | 8.8 | 33.9 | Oracle Corporation | Oracle Identity Manager | CWE-284 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-60729 | 8.8 | 33.9 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-61032 | 8.8 | 33.9 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-61040 | 8.8 | 33.9 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-70886 | 8.8 | 33.9 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-47606 | 6.5 | 33.7 | NVIDIA | Triton Inference Server | CWE-36 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-62629 | 9.4 | 33.7 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-71113 | 7.5 | 33.6 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-60591 | 9.1 | 33.6 | Oracle Corporation | Oracle Hospitality Simphony | CWE-306 | Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and B… |
| CVE-2026-70977 | 9.1 | 33.6 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-306 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-70981 | 9.1 | 33.6 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-70984 | 9.1 | 33.6 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71153 | 7.5 | 33.6 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-53959 | 6.5 | 33.6 | RARgames | 4gaBoards | CWE-200 | 4gaBoards: Mass Information Disclosure (Internal PII Leakage) on /api/users t… |
| CVE-2026-15806 | 6.0 | 33.6 | Python Software Foundation | CPython | CWE-319 | `HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorr… |
| CVE-2026-73916 | 9.1 | 33.3 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-70921 | 10.0 | 33.3 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2021-43717 | 9.8 | 33.3 | n/a | n/a | CWE-798 | An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identi… |
| CVE-2026-70675 | 8.1 | 33.2 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-70684 | 8.1 | 33.2 | Oracle Corporation | Oracle Enterprise Manager Base Platform | — | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-70704 | 8.1 | 33.2 | Oracle Corporation | Oracle Trading Community | — | Vulnerability in the Oracle Trading Community product of Oracle E-Business Su… |
| CVE-2026-70814 | 8.1 | 33.2 | Oracle Corporation | Oracle Call Center Technology | CWE-284 | Vulnerability in the Oracle Call Center Technology product of Oracle E-Busine… |
| CVE-2026-45734 | 5.3 | 33.3 | mybb | mybb | CWE-837 | MyBB: Default CAPTCHA missing invalidation |
| CVE-2026-75874 | 10.0 | 33.1 | Mozilla | Firefox | CWE-693 | Sandbox escape in the Remote Settings Client component |
| CVE-2026-60702 | 9.9 | 33.1 | Oracle Corporation | Oracle WebLogic Server | CWE-284 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60730 | 9.9 | 33.1 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-74936 | 9.8 | 33.2 | Mozilla | Firefox | CWE-416 | Use-after-free in the JavaScript: WebAssembly component |
| CVE-2026-74944 | 9.8 | 33.2 | Mozilla | Firefox | CWE-416 | Use-after-free in the DOM: Core & HTML component |
| CVE-2026-71166 | 9.4 | 33.2 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-60879 | 8.8 | 33.1 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | CWE-284 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-60796 | 8.2 | 33.2 | Oracle Corporation | Siebel CRM Integration | CWE-284 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-70952 | 8.2 | 33.2 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-60720 | 9.9 | 33.1 | Oracle Corporation | Oracle Identity Manager | CWE-306 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-60726 | 8.8 | 33.1 | Oracle Corporation | Oracle Access Manager | CWE-284 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-61017 | 8.8 | 33.1 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-61022 | 8.8 | 33.1 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-61058 | 8.8 | 33.1 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-75783 | 8.6 | 32.9 | TRENDnet | TEW-WLC100P | CWE-119 | TRENDnet TEW-WLC100P DHCP blobmsg netifd stack-based overflow |
| CVE-2026-71055 | 8.8 | 32.9 | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | CWE-284 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-69220 | 8.7 | 32.8 | rabbitmq | rabbitmq-java-client | CWE-674 | RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting cau… |
| CVE-2026-73399 | 6.5 | 32.8 | flutterwave | Flutterwave WooCommerce | CWE-288 | WordPress Flutterwave WooCommerce plugin <= 3.3.0 - Broken Authentication vul… |
| CVE-2026-70730 | 9.1 | 32.6 | Oracle Corporation | Oracle Hyperion Profitability and Cost Management | — | Vulnerability in the Oracle Hyperion Profitability and Cost Management produc… |
| CVE-2026-70741 | 9.1 | 32.6 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70884 | 9.1 | 32.6 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-62599 | 8.6 | 32.6 | Oracle Corporation | Oracle Trading Community | — | Vulnerability in the Oracle Trading Community product of Oracle E-Business Su… |
| CVE-2026-62628 | 8.6 | 32.6 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-70721 | 8.6 | 32.6 | Oracle Corporation | Oracle Hyperion Profitability and Cost Management | — | Vulnerability in the Oracle Hyperion Profitability and Cost Management produc… |
| CVE-2026-60393 | 7.5 | 32.6 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | CWE-200 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70810 | 7.5 | 32.6 | Oracle Corporation | Oracle Scripting | — | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (com… |
| CVE-2026-73878 | 7.5 | 32.6 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73883 | 7.5 | 32.6 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73884 | 7.5 | 32.6 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-61008 | 9.1 | 32.5 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-73917 | 9.1 | 32.5 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-60415 | 8.1 | 32.4 | Oracle Corporation | Oracle WebLogic Server | CWE-200 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60850 | 7.5 | 32.5 | Oracle Corporation | Oracle Unified Directory | CWE-284 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60889 | 7.5 | 32.5 | Oracle Corporation | Oracle Unified Directory | CWE-284 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60914 | 7.5 | 32.5 | Oracle Corporation | Oracle Unified Directory | CWE-284 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-61007 | 7.5 | 32.5 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-73907 | 7.5 | 32.5 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73938 | 7.5 | 32.5 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-21580 | 9.3 | 32.3 | Atlassian | Confluence Data Center | CWE-79 | This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Securi… |
| CVE-2026-73350 | 8.2 | 32.4 | PSM Plugins | SupportCandy | CWE-266 | WordPress SupportCandy plugin <= 3.5.1 - Broken Authentication vulnerability |
| CVE-2026-61001 | 9.6 | 32.3 | Oracle Corporation | Oracle Web Services Manager | CWE-284 | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Mid… |
| CVE-2026-47628 | 7.5 | 32.2 | NVIDIA | Triton Inference Server | CWE-770 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-47629 | 7.5 | 32.2 | NVIDIA | Triton Inference Server | CWE-20 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-70889 | 7.5 | 32.2 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-70891 | 7.5 | 32.2 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-52739 | 5.9 | 32.2 | ZcashFoundation | zebra | CWE-248 | ZEBRA: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplic… |
| CVE-2026-21582 | 8.8 | 32.1 | Atlassian | Crowd Data Center | CWE-287 | This High severity BASM (Broken Authentication & Session Management) vulnerab… |
| CVE-2026-75853 | 8.7 | 32.1 | ArcadeData | arcadedb | CWE-862 | ArcadeDB Gremlin Wire Protocol Authorization Bypass Cross-Database |
| CVE-2026-62684 | 2.7 | 32.1 | filebrowser | filebrowser | CWE-200 | File Browser: Share API exposes the password hash and bypass token |
| CVE-2026-62463 | 9.6 | 32.0 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62619 | 8.8 | 31.9 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-60849 | 8.5 | 32.0 | Oracle Corporation | Oracle Unified Directory | — | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-70722 | 8.2 | 31.9 | Oracle Corporation | Oracle Advanced Inbound Telephony | CWE-284 | Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Bu… |
| CVE-2026-60992 | 8.1 | 32.0 | Oracle Corporation | Oracle Identity Manager Connector | CWE-284 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-62477 | 8.1 | 32.0 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | CWE-284 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62491 | 8.1 | 32.0 | Oracle Corporation | Oracle Purchasing | — | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co… |
| CVE-2026-62502 | 8.1 | 32.0 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70701 | 8.1 | 32.0 | Oracle Corporation | Oracle Payables | — | Vulnerability in the Oracle Payables product of Oracle E-Business Suite (comp… |
| CVE-2026-70762 | 8.1 | 32.0 | Oracle Corporation | Oracle Risk Management | — | Vulnerability in the Oracle Risk Management product of Oracle E-Business Suit… |
| CVE-2026-70811 | 8.1 | 32.0 | Oracle Corporation | Oracle Purchasing | CWE-284 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co… |
| CVE-2026-70815 | 8.1 | 32.0 | Oracle Corporation | Oracle Internet Procurement Connector | CWE-284 | Vulnerability in the Oracle Internet Procurement Connector product of Oracle … |
| CVE-2026-70835 | 8.1 | 32.0 | Oracle Corporation | Oracle iRecruitment | CWE-284 | Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (… |
| CVE-2026-70878 | 8.1 | 32.0 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-70881 | 8.1 | 32.0 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-70924 | 8.1 | 32.0 | Oracle Corporation | Oracle Web Services Manager | CWE-306 | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Mid… |
| CVE-2026-71676 | 7.5 | 32.0 | n/a | n/a | CWE-122 | Buffer Overflow vulnerability in Open5GS v.2.7.0 allows a remote attacker to … |
| CVE-2026-66046 | 8.7 | 31.9 | libexpat project | libexpat | CWE-407 | Expat Denial of Service via storeAtts() Quadratic Complexity |
| CVE-2026-75855 | 8.4 | 31.8 | ArcadeData | arcadedb | CWE-22 | ArcadeDB before 26.8.1 Path Traversal via create/drop database |
| CVE-2026-62512 | 9.9 | 31.7 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-284 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-60767 | 8.8 | 31.7 | Oracle Corporation | Siebel Apps - Marketing | CWE-284 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co… |
| CVE-2026-61284 | 8.8 | 31.7 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-61330 | 8.8 | 31.7 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-284 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-61341 | 8.8 | 31.7 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-284 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-70928 | 8.8 | 31.7 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-269 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70940 | 8.8 | 31.7 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-306 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70944 | 8.8 | 31.7 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70948 | 8.8 | 31.7 | Oracle Corporation | Oracle Purchasing | CWE-284 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co… |
| CVE-2026-70949 | 8.8 | 31.7 | Oracle Corporation | Siebel CRM Deployment | CWE-284 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-70966 | 8.8 | 31.7 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | CWE-284 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-71039 | 8.8 | 31.7 | Oracle Corporation | Oracle Agile PLM | CWE-284 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-71067 | 8.8 | 31.7 | Oracle Corporation | Oracle Agile PLM MCAD Connector | CWE-306 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply… |
| CVE-2026-61066 | 9.9 | 31.6 | Oracle Corporation | Oracle Identity Manager | CWE-284 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-61248 | 9.9 | 31.6 | Oracle Corporation | Oracle Internet Directory | — | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middl… |
| CVE-2026-61231 | 8.8 | 31.6 | Oracle Corporation | Oracle Virtual Directory | — | Vulnerability in the Oracle Virtual Directory product of Oracle Fusion Middle… |
| CVE-2026-76047 | 8.8 | 31.6 | Google | Chrome | CWE-843 | Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remot… |
| CVE-2026-61332 | 8.7 | 31.5 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-284 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-76044 | 8.3 | 31.5 | Google | Chrome | CWE-367 | Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remo… |
| CVE-2026-73341 | 9.8 | 31.4 | Metagauss | RegistrationMagic | CWE-502 | WordPress RegistrationMagic plugin <= 6.0.9.7 - PHP Object Injection vulnerab… |
| CVE-2026-73376 | 9.8 | 31.4 | supsystic | Ultimate Maps by Supsystic | CWE-502 | WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - PHP Object Injection vu… |
| CVE-2026-73397 | 9.8 | 31.4 | Youzify | Youzify | CWE-502 | WordPress Youzify plugin <= 1.3.7 - Deserialization of untrusted data vulnera… |
| CVE-2026-73937 | 8.2 | 31.4 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-70690 | 8.0 | 31.4 | Oracle Corporation | Oracle HRMS (US) | — | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (com… |
| CVE-2026-70802 | 8.0 | 31.4 | Oracle Corporation | Oracle Public Sector Human Resources | — | Vulnerability in the Oracle Public Sector Human Resources product of Oracle E… |
| CVE-2026-71675 | 7.5 | 31.4 | n/a | n/a | CWE-401 | An issue in Open5GS v.2.7.0 allows a remote attacker to cause a denial of ser… |
| CVE-2026-62475 | 6.6 | 31.4 | Oracle Corporation | Oracle Shipping Execution | CWE-284 | Vulnerability in the Oracle Shipping Execution product of Oracle E-Business S… |
| CVE-2026-73396 | 7.1 | 31.3 | MakeWebBetter | MWB HubSpot for WooCommerce | CWE-288 | WordPress MWB HubSpot for WooCommerce plugin <= 1.6.7 - Broken Authentication… |
| CVE-2026-53533 | 6.9 | 31.3 | cole | aiosmtplib | CWE-77 | aiosmtplib: SMTP command injection via CR/LF in sender/recipient address |
| CVE-2026-70669 | 9.8 | 31.1 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-45118 | 9.3 | 31.1 | mybb | mybb | CWE-83 | MyBB: Contact page reflected XSS |
| CVE-2026-50161 | 9.3 | 31.2 | baresip | re | CWE-190 | libre: Integer overflow in websock_decode() masked frame length check leads t… |
| CVE-2026-74959 | 9.1 | 31.1 | Mozilla | Firefox | CWE-693 | Mitigation bypass in the Storage: Cache API component |
| CVE-2026-62357 | 8.8 | 31.1 | dragonflydb | dragonfly | CWE-190 | DragonflyDB `CMS.INITBYDIM` integer overflow leads to a remote, attacker-cont… |
| CVE-2026-73187 | 9.3 | 31.1 | gingerplugins | Sticky Chat Widget | CWE-89 | WordPress Sticky Chat Widget plugin <= 1.4.2 - SQL Injection vulnerability |
| CVE-2026-73339 | 9.3 | 31.1 | Webnus Inc. | Modern Events Calendar | CWE-89 | WordPress Modern Events Calendar plugin < 7.35.0 - SQL Injection vulnerability |
| CVE-2026-73355 | 9.3 | 31.1 | wp.insider | Affiliates Manager | CWE-89 | WordPress Affiliates Manager plugin <= 2.9.53 - SQL Injection vulnerability |
| CVE-2026-73365 | 9.3 | 31.1 | Crocoblock. Jetimpex Inc. | JetAppointment | CWE-89 | WordPress JetAppointment plugin <= 2.5.2 - SQL Injection vulnerability |
| CVE-2026-73392 | 9.3 | 31.1 | highwarden | Super Store Finder | CWE-89 | WordPress Super Store Finder plugin <= 7.8 - SQL Injection vulnerability |
| CVE-2026-45532 | 8.7 | 30.9 | dataease | dataease | CWE-22 | DataEase has a Path Traversal Vulnerability |
| CVE-2026-54347 | 8.7 | 30.9 | froxlor | froxlor | CWE-79 | Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Accoun… |
| CVE-2026-62607 | 8.7 | 30.8 | Oracle Corporation | Oracle Customer Care | — | Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite … |
| CVE-2026-71085 | 4.9 | 30.8 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-200 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-61258 | 9.8 | 30.8 | Oracle Corporation | Oracle Internet Directory | CWE-284 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middl… |
| CVE-2026-49221 | 8.8 | 30.7 | givanz | Vvveb | CWE-639 | Vvveb digital asset authorization bypass allows Vendors to list, read, edit, … |
| CVE-2026-49228 | 8.8 | 30.7 | givanz | Vvveb | CWE-639 | Vvveb product authorization bypass allows Vendors to read, duplicate, or dele… |
| CVE-2026-48798 | 7.1 | 30.8 | sshnet | SSH.NET | CWE-22 | SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-… |
| CVE-2026-73930 | 9.9 | 30.6 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-71880 | 7.6 | 30.7 | GBIF | Integrated Publishing Toolkit | CWE-1336 | Server-side template injection in Integrated Publishing Toolkit |
| CVE-2026-60865 | 6.8 | 30.7 | Oracle Corporation | Service Delivery Platform | CWE-284 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-74044 | 7.0 | 30.5 | Wazuh | wazuh-manager | CWE-22 | Wazuh 4.0.0 < 4.14.6 Path Traversal Arbitrary Directory Deletion via Cluster … |
| CVE-2026-70978 | 9.1 | 30.4 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71015 | 9.1 | 30.4 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-306 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71026 | 9.1 | 30.4 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-73866 | 9.1 | 30.4 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-32472 | 7.5 | 30.4 | wbolt.com | Online Contact Widget | CWE-862 | WordPress Online Contact Widget plugin <= 1.3.0 - Broken Access Control vulne… |
| CVE-2026-32549 | 7.5 | 30.4 | Codexpert, Inc | ThumbPress | CWE-862 | WordPress ThumbPress plugin < 6.5 - Broken Access Control vulnerability |
| CVE-2026-60391 | 7.5 | 30.4 | Oracle Corporation | Oracle Hyperion Financial Reporting | CWE-284 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-60590 | 7.5 | 30.4 | Oracle Corporation | Oracle Hospitality Simphony | CWE-284 | Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and B… |
| CVE-2026-60906 | 7.5 | 30.4 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-70896 | 7.5 | 30.4 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-70910 | 7.5 | 30.4 | Oracle Corporation | Siebel CRM Integration | CWE-284 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-70986 | 7.5 | 30.4 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-70987 | 7.5 | 30.4 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71034 | 7.5 | 30.4 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71107 | 7.5 | 30.5 | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | CWE-284 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-71142 | 7.5 | 30.4 | Oracle Corporation | Oracle Communications Unified Inventory Management | CWE-284 | Vulnerability in the Oracle Communications Unified Inventory Management produ… |
| CVE-2026-71158 | 7.5 | 30.4 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-53455 | 8.6 | 30.4 | ha-china | blueprint-studio | CWE-78 | Blueprint Studio Git credential helper command injection |
| CVE-2026-62501 | 8.1 | 30.3 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62531 | 8.1 | 30.3 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70744 | 8.1 | 30.3 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70749 | 8.1 | 30.3 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70868 | 8.1 | 30.3 | Oracle Corporation | Oracle Application Testing Suite | CWE-284 | Vulnerability in Oracle Application Testing Suite. The supported version that… |
| CVE-2026-71068 | 8.1 | 30.3 | Oracle Corporation | Oracle Agile PLM MCAD Connector | CWE-306 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply… |
| CVE-2026-52731 | 6.5 | 30.3 | ZcashFoundation | zebra | CWE-248 | ZEBRA: Full node denial of service via non-ASCII LongPollId in getblocktemplate |
| CVE-2026-32470 | 9.8 | 30.2 | Roxnor | FundEngine | CWE-502 | WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability |
| CVE-2026-52481 | 7.5 | 30.2 | n/a | n/a | CWE-200 | An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote att… |
| CVE-2026-61029 | 9.0 | 30.1 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-54730 | 8.6 | 30.1 | goauthentik | authentik | CWE-284 | authentik: Authentication Flow Bypass via Unguarded challenge_valid() in Auth… |
| CVE-2026-70770 | 8.3 | 30.1 | Oracle Corporation | Oracle Warehouse Management | CWE-284 | Vulnerability in the Oracle Warehouse Management product of Oracle E-Business… |
| CVE-2026-62595 | 8.1 | 30.2 | Oracle Corporation | Siebel CRM Integration | CWE-284 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-61011 | 8.2 | 30.0 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-61016 | 8.2 | 30.0 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-61265 | 8.1 | 30.0 | Oracle Corporation | JD Edwards EnterpriseOne Orchestrator | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle … |
| CVE-2026-15585 | 7.5 | 30.0 | AKIN Software Computer Import Export Industry and Trade Ltd. | AKINSOFT Wolvox9 ERP / KontrolPanel.exe | CWE-22 | Path Traversal in AKIN Software's Wolvox9 ERP |
| CVE-2026-43971 | 6.3 | 29.9 | ninenines | cowlib | CWE-116 | Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in co… |
| CVE-2026-73502 | 5.3 | 29.9 | getkin | kin-openapi | CWE-476 | kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating… |
| CVE-2026-62467 | 7.7 | 29.8 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62571 | 7.7 | 29.8 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-70771 | 7.7 | 29.8 | Oracle Corporation | Oracle Warehouse Management | CWE-284 | Vulnerability in the Oracle Warehouse Management product of Oracle E-Business… |
| CVE-2026-70827 | 7.7 | 29.8 | Oracle Corporation | Oracle MES for Process Manufacturing | — | Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E… |
| CVE-2026-70828 | 7.7 | 29.8 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-52738 | 6.9 | 29.8 | ZcashFoundation | zebra | CWE-248 | ZEBRA: Finalized address balance credit-first overflow on consensus-valid blocks |
| CVE-2026-62506 | 6.5 | 29.8 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70720 | 6.5 | 29.8 | Oracle Corporation | Oracle Production Scheduling | — | Vulnerability in the Oracle Production Scheduling product of Oracle E-Busines… |
| CVE-2026-70767 | 6.5 | 29.8 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70826 | 6.5 | 29.8 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70831 | 6.5 | 29.8 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-52732 | 5.3 | 29.8 | ZcashFoundation | zebra | CWE-770 | ZEBRA: Mempool transaction admission denial via single-peer inbound queue sat… |
| CVE-2026-52734 | 5.3 | 29.8 | ZcashFoundation | zebra | CWE-401 | ZEBRA: Unbounded memory leak in mempool download pipeline via timeout path ca… |
| CVE-2026-75856 | 9.2 | 29.7 | Hmbown | CodeWhale | CWE-918 | CodeWhale before 0.8.64 SSRF Bypass via DNS Pinning TOCTOU |
| CVE-2026-60956 | 7.5 | 29.8 | Oracle Corporation | JD Edwards EnterpriseOne US Payroll | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne US Payroll product of Oracle JD… |
| CVE-2026-70713 | 7.5 | 29.8 | Oracle Corporation | Oracle iSetup | — | Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (compon… |
| CVE-2026-70829 | 7.5 | 29.8 | Oracle Corporation | Oracle Process Manufacturing Systems | CWE-284 | Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E… |
| CVE-2026-66620 | 7.2 | 29.7 | Derek Herman | OptionTree | CWE-502 | WordPress OptionTree plugin <= 2.7.3 - PHP Object Injection vulnerability |