Security Box Score — August 18, 2026 — page 2
Edition of August 18, 2026, continued — page 2 of 3. Back to page 1 · page 3
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2021-43718 | 5.3 | 29.7 | n/a | n/a | CWE-288 | An Authentication Bypass vulnerability exists in EPSON EH-TW5350 EPSON 150075… |
| CVE-2026-62636 | 8.6 | 29.5 | Oracle Corporation | Oracle Reports Developer | CWE-284 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-76046 | 8.3 | 29.3 | Chrome | CWE-122 | Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0.7922.1… | |
| CVE-2026-60742 | 8.1 | 29.3 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | CWE-284 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-60831 | 8.1 | 29.3 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | CWE-284 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-70846 | 9.6 | 29.2 | Oracle Corporation | Oracle Demand Planning | CWE-284 | Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (c… |
| CVE-2026-62600 | 8.1 | 29.2 | Oracle Corporation | Oracle Sales | — | Vulnerability in the Oracle Sales product of Oracle E-Business Suite (compone… |
| CVE-2026-70671 | 8.1 | 29.2 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-70708 | 8.1 | 29.2 | Oracle Corporation | Oracle Sales Foundation | — | Vulnerability in the Oracle Sales Foundation product of Oracle E-Business Sui… |
| CVE-2026-70738 | 8.1 | 29.2 | Oracle Corporation | Oracle Hyperion Profitability and Cost Management | — | Vulnerability in the Oracle Hyperion Profitability and Cost Management produc… |
| CVE-2026-70805 | 8.1 | 29.2 | Oracle Corporation | Oracle Project Planning and Control | CWE-306 | Vulnerability in the Oracle Project Planning and Control product of Oracle E-… |
| CVE-2026-71161 | 5.3 | 29.2 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-70680 | 7.1 | 29.1 | Oracle Corporation | Oracle Applications DBA | CWE-284 | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Sui… |
| CVE-2026-63642 | 6.3 | 29.1 | MagicMirrorOrg | MagicMirror | CWE-918 | MagicMirror newsfeed Socket.IO notification allows blind server-side request … |
| CVE-2026-60971 | 9.8 | 28.9 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-73912 | 9.8 | 28.9 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-70958 | 9.6 | 28.9 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | CWE-601 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-71106 | 8.8 | 28.9 | Oracle Corporation | Oracle Hospitality OPERA 5 Property Services | CWE-284 | Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of … |
| CVE-2026-71079 | 6.5 | 28.9 | Oracle Corporation | MySQL Connectors | CWE-284 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Con… |
| CVE-2026-71050 | 8.7 | 28.7 | Oracle Corporation | Oracle Product Lifecycle Analytics | CWE-284 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Sup… |
| CVE-2026-61033 | 8.6 | 28.8 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-62625 | 8.6 | 28.8 | Oracle Corporation | Oracle Reports Developer | CWE-284 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-71007 | 6.8 | 28.7 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-60905 | 9.6 | 28.6 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-70880 | 10.0 | 28.4 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-62452 | 9.9 | 28.5 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-284 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-62539 | 9.8 | 28.4 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62541 | 9.8 | 28.4 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62543 | 9.8 | 28.4 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70871 | 9.8 | 28.4 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-73996 | 9.8 | 28.4 | masteriyo | Masteriyo - LMS | CWE-434 | WordPress Masteriyo - LMS plugin <= 2.3.2 - Arbitrary File Upload vulnerability |
| CVE-2026-68922 | 5.5 | 28.5 | MobSF | Mobile-Security-Framework-MobSF | CWE-22 | MobSF: Arbitrary File Read via Path Traversal in ZIP Uploads |
| CVE-2026-61574 | 8.8 | 28.3 | goauthentik | authentik | CWE-639 | authentik RAC: access any endpoint via an unrelated application |
| CVE-2026-74904 | 8.7 | 28.3 | siyuan-note | siyuan | CWE-862 | SiYuan before v3.7.4 Missing Authorization via block API |
| CVE-2026-70849 | 6.5 | 28.4 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-61018 | 9.8 | 28.1 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-60592 | 8.2 | 28.2 | Oracle Corporation | MySQL Cluster | CWE-284 | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluste… |
| CVE-2026-70687 | 7.7 | 28.2 | Oracle Corporation | Oracle Marketing | — | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (com… |
| CVE-2026-70723 | 7.7 | 28.2 | Oracle Corporation | Oracle Hyperion Profitability and Cost Management | — | Vulnerability in the Oracle Hyperion Profitability and Cost Management produc… |
| CVE-2026-70942 | 7.7 | 28.2 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-200 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-71070 | 6.5 | 28.2 | Oracle Corporation | Oracle Agile PLM MCAD Connector | CWE-284 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply… |
| CVE-2026-62585 | 9.8 | 28.1 | Oracle Corporation | Siebel CRM Administration | CWE-284 | Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (… |
| CVE-2026-73905 | 9.8 | 28.1 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73921 | 9.8 | 28.1 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-60680 | 8.1 | 28.1 | Oracle Corporation | Oracle WebLogic Server | CWE-284 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60916 | 9.9 | 27.9 | Oracle Corporation | Oracle WebCenter Enterprise Capture | CWE-284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-21584 | 7.6 | 28.0 | Atlassian | Bamboo Data Center | — | This High severity Improper Authorization vulnerability was introduced in ver… |
| CVE-2026-70855 | 9.3 | 27.8 | Oracle Corporation | Siebel Apps - Self Service | — | Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM … |
| CVE-2026-62462 | 8.8 | 27.8 | Oracle Corporation | Oracle Work in Process | — | Vulnerability in the Oracle Work in Process product of Oracle E-Business Suit… |
| CVE-2026-70812 | 8.8 | 27.8 | Oracle Corporation | Oracle Call Center Technology | CWE-284 | Vulnerability in the Oracle Call Center Technology product of Oracle E-Busine… |
| CVE-2026-60779 | 8.1 | 27.8 | Oracle Corporation | Siebel Apps - Marketing | CWE-284 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co… |
| CVE-2026-70746 | 8.1 | 27.8 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70931 | 8.1 | 27.8 | Oracle Corporation | Oracle Workflow | CWE-284 | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (comp… |
| CVE-2026-70959 | 8.1 | 27.8 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | CWE-284 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-71042 | 8.1 | 27.8 | Oracle Corporation | Oracle Agile PLM | CWE-284 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-62593 | 7.7 | 27.8 | Oracle Corporation | Siebel CRM Integration | CWE-284 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-73383 | 4.9 | 27.8 | WebAppick | CTX Feed | CWE-22 | WordPress CTX Feed plugin <= 6.6.47 - Arbitrary File Download vulnerability |
| CVE-2026-62591 | 8.1 | 27.7 | Oracle Corporation | Siebel CRM Integration | CWE-284 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-74038 | 7.0 | 27.7 | Wazuh | wazuh-manager | CWE-22 | Wazuh 4.0.0 < 4.14.6 Path Traversal DoS via Agent Enrollment |
| CVE-2026-74988 | 9.8 | 27.6 | Mozilla | Firefox | CWE-119 | Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 |
| CVE-2026-62455 | 8.3 | 27.6 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-284 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-70925 | 8.1 | 27.6 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-76045 | 8.8 | 27.5 | Chrome | CWE-416 | Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a re… | |
| CVE-2026-71057 | 8.5 | 27.5 | Oracle Corporation | Oracle BI Publisher | CWE-284 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-71095 | 8.3 | 27.5 | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | CWE-284 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-70980 | 9.0 | 27.4 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-61307 | 8.1 | 27.4 | Oracle Corporation | PeopleSoft Enterprise CC Common Application Objects | CWE-284 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects prod… |
| CVE-2026-71035 | 8.1 | 27.4 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71053 | 8.1 | 27.4 | Oracle Corporation | Oracle Agile Engineering Data Management | CWE-284 | Vulnerability in the Oracle Agile Engineering Data Management product of Orac… |
| CVE-2026-71112 | 8.1 | 27.4 | Oracle Corporation | PeopleSoft Enterprise FIN Common Objects | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Orac… |
| CVE-2026-60752 | 7.1 | 27.4 | Oracle Corporation | Siebel Apps - Marketing | CWE-284 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co… |
| CVE-2026-61259 | 7.1 | 27.4 | Oracle Corporation | Oracle Hyperion Calculation Manager | CWE-284 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-70733 | 7.1 | 27.4 | Oracle Corporation | Oracle Hyperion Profitability and Cost Management | CWE-284 | Vulnerability in the Oracle Hyperion Profitability and Cost Management produc… |
| CVE-2026-70933 | 7.1 | 27.4 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70934 | 7.1 | 27.4 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-71365 | 7.7 | 27.3 | Red Hat | Red Hat Ansible Automation Platform 2 | CWE-918 | Awx: webhook status callback ssrf leaks the git pat |
| CVE-2026-59825 | 7.4 | 27.3 | mastodon | mastodon | CWE-295 | Mastodon: Unwanted deactivation of SSL/TLS certificate verification |
| CVE-2026-73896 | 6.5 | 27.1 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-70718 | 8.5 | 27.1 | Oracle Corporation | Oracle Bills of Material | — | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Su… |
| CVE-2026-70706 | 7.5 | 27.1 | Oracle Corporation | Oracle Sales | — | Vulnerability in the Oracle Sales product of Oracle E-Business Suite (compone… |
| CVE-2026-70763 | 7.5 | 27.1 | Oracle Corporation | Oracle Operations Intelligence | — | Vulnerability in the Oracle Operations Intelligence product of Oracle E-Busin… |
| CVE-2026-70865 | 7.5 | 27.1 | Oracle Corporation | Oracle Application Testing Suite | CWE-284 | Vulnerability in Oracle Application Testing Suite. The supported version that… |
| CVE-2026-71069 | 7.5 | 27.1 | Oracle Corporation | Oracle Agile PLM MCAD Connector | CWE-284 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply… |
| CVE-2026-73995 | 5.4 | 27.1 | wpeverest | User Registration | CWE-290 | WordPress User Registration plugin <= 5.2.6 - Broken Authentication vulnerabi… |
| CVE-2026-60861 | 9.6 | 26.9 | Oracle Corporation | Service Delivery Platform | CWE-284 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-74986 | 9.1 | 26.9 | Mozilla | Firefox | CWE-200 | Site isolation issue in the CSS Parsing and Computation component |
| CVE-2026-53454 | 6.9 | 26.9 | ha-china | blueprint-studio | CWE-522 | Blueprint Studio stored Git credentials in plaintext Git credential store |
| CVE-2026-75093 | 2.1 | 27.0 | sonos | tract | CWE-120 | sonos tract ONNX Initializer Loader tensor.rs from_raw_dt_align buffer size |
| CVE-2026-70870 | 8.2 | 26.8 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-73337 | 8.2 | 26.8 | Joomla! Project | Joomla! CMS | CWE-287 | Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 a… |
| CVE-2026-62540 | 7.2 | 26.8 | Oracle Corporation | Oracle Cost Management | — | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suit… |
| CVE-2026-70797 | 7.2 | 26.8 | Oracle Corporation | Oracle Purchasing | — | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co… |
| CVE-2026-70834 | 7.2 | 26.8 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-75842 | 8.3 | 26.6 | ArcadeData | arcadedb | CWE-22 | ArcadeDB before 26.8.1 Arbitrary File Read via LOAD CSV |
| CVE-2026-73879 | 7.5 | 26.6 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-62492 | 7.4 | 26.6 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62538 | 7.4 | 26.6 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70779 | 7.4 | 26.6 | Oracle Corporation | Oracle iSupplier Portal | CWE-284 | Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Sui… |
| CVE-2026-70783 | 7.4 | 26.6 | Oracle Corporation | Oracle Service Contracts | — | Vulnerability in the Oracle Service Contracts product of Oracle E-Business Su… |
| CVE-2026-70823 | 7.4 | 26.6 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-65985 | 6.0 | 26.6 | frangoteam | FUXA | CWE-918 | FUXA: SSRF hardening for `device-webapi-request` |
| CVE-2026-70673 | 9.3 | 26.3 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-75837 | 9.3 | 26.3 | getgrav | grav | CWE-269 | Grav before 2.0.14 Privilege Escalation via Group Access Field |
| CVE-2026-61034 | 9.1 | 26.4 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-70702 | 8.2 | 26.3 | Oracle Corporation | Oracle Payments | — | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (comp… |
| CVE-2026-70773 | 8.2 | 26.3 | Oracle Corporation | Oracle HCM Common Architecture | CWE-284 | Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Busin… |
| CVE-2026-60820 | 7.4 | 26.4 | Oracle Corporation | Siebel CRM Integration | CWE-1284 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-53458 | 5.3 | 26.3 | ha-china | blueprint-studio | CWE-209 | Blueprint Studio API exposed internal exception details |
| CVE-2026-53453 | 8.7 | 26.3 | ha-china | blueprint-studio | CWE-862 | Blueprint Studio API authorization bypass for non-admin Home Assistant users |
| CVE-2026-61038 | 8.2 | 26.2 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-61054 | 8.2 | 26.2 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-50143 | 8.1 | 26.2 | apify | apify-mcp-server | CWE-918 | Actor MCP path authority injection leaks Apify token |
| CVE-2026-70774 | 7.1 | 26.3 | Oracle Corporation | Oracle Warehouse Management | CWE-284 | Vulnerability in the Oracle Warehouse Management product of Oracle E-Business… |
| CVE-2026-71110 | 8.1 | 26.2 | Oracle Corporation | Helidon | CWE-269 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-74957 | 8.1 | 26.1 | Mozilla | Firefox | CWE-693 | Mitigation bypass in the Safe Browsing component |
| CVE-2026-71573 | 6.9 | 26.0 | Joomla! Project | Joomla! CMS | CWE-93 | Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5… |
| CVE-2026-66679 | 6.5 | 26.0 | codepeople | Appointment Hour Booking | CWE-1284 | WordPress Appointment Hour Booking plugin <= 1.5.91 - Broken Access Control v… |
| CVE-2026-71063 | 9.6 | 26.0 | Oracle Corporation | Oracle Database Server | CWE-284 | Vulnerability in the Portable Clusterware component of Oracle Database Server… |
| CVE-2026-71064 | 9.6 | 26.0 | Oracle Corporation | Oracle Database Server | CWE-284 | Vulnerability in the Portable Clusterware component of Oracle Database Server… |
| CVE-2026-52733 | 6.5 | 25.9 | ZcashFoundation | zebra | CWE-459 | ZEBRA: Persistent on-disk corruption of Sapling/Orchard subtree roots after c… |
| CVE-2026-71037 | 9.3 | 25.8 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-60841 | 8.5 | 25.8 | Oracle Corporation | Oracle Unified Directory | CWE-284 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-50138 | 8.1 | 25.8 | patrickhener | goshs | CWE-284 | goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mo… |
| CVE-2026-70901 | 8.1 | 25.8 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-74948 | 6.5 | 25.8 | Mozilla | Firefox | CWE-200 | Information disclosure in the Graphics component |
| CVE-2026-76041 | 4.3 | 25.8 | Chrome | CWE-200 | Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a r… | |
| CVE-2026-74907 | 8.2 | 25.7 | getgrav | grav | CWE-22 | Grav before 2.0.15 Path Traversal via plugin-asset-map.php |
| CVE-2026-32481 | 7.5 | 25.7 | ezoic | Ezoic | CWE-288 | WordPress Ezoic plugin <= 2.22.11 - Broken Authentication vulnerability |
| CVE-2026-74989 | 9.8 | 25.5 | Mozilla | Firefox | CWE-119 | Internally found bugs fixed in Firefox 154 |
| CVE-2026-60860 | 8.7 | 25.5 | Oracle Corporation | Service Delivery Platform | CWE-284 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-74977 | 7.5 | 25.5 | Mozilla | Firefox | CWE-190 | Integer overflow in the Graphics component |
| CVE-2026-74982 | 7.5 | 25.5 | Mozilla | Firefox | CWE-400 | Denial-of-service in the Widget component |
| CVE-2026-61272 | 9.8 | 25.4 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-70953 | 9.8 | 25.4 | Oracle Corporation | Oracle Commerce Platform | CWE-306 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com… |
| CVE-2026-70954 | 9.8 | 25.4 | Oracle Corporation | Oracle Commerce Platform | CWE-306 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com… |
| CVE-2026-70995 | 9.8 | 25.4 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-70994 | 9.1 | 25.4 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-70997 | 9.1 | 25.4 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-49226 | 8.3 | 25.4 | givanz | Vvveb | CWE-639 | Vvveb post authorization bypass allows Authors to view, duplicate, or delete … |
| CVE-2026-75082 | 2.1 | 25.5 | Webkul | Bagisto | CWE-74 | Webkul Bagisto Customer-Registration Notification Email register cross site s… |
| CVE-2026-60990 | 9.9 | 25.3 | Oracle Corporation | Oracle Identity Manager Connector | CWE-284 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-73939 | 8.6 | 25.3 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-75913 | 8.5 | 25.4 | Hmbown | CodeWhale | CWE-73 | CodeWhale before 0.8.64 Argument Injection via git_show |
| CVE-2026-73903 | 7.5 | 25.3 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-70856 | 7.5 | 25.2 | Oracle Corporation | Siebel CRM Deployment | CWE-284 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-15571 | 7.3 | 25.2 | Red Hat | Red Hat build of Keycloak 26.6 | CWE-341 | Keycloak-services: keycloak-services: predictable account-linking hash enable… |
| CVE-2026-73920 | 9.4 | 25.1 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-50191 | 8.8 | 25.1 | RARgames | 4gaBoards | CWE-287 | 4gaBoards: Pre-Account Takeover via SSO Email Linkage |
| CVE-2026-70707 | 8.8 | 25.2 | Oracle Corporation | Oracle Sales for Handhelds | — | Vulnerability in the Oracle Sales for Handhelds product of Oracle E-Business … |
| CVE-2026-70787 | 8.8 | 25.2 | Oracle Corporation | Oracle Hyperion Financial Reporting | CWE-284 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70792 | 8.8 | 25.2 | Oracle Corporation | Oracle Yard Management | CWE-284 | Vulnerability in the Oracle Yard Management product of Oracle E-Business Suit… |
| CVE-2026-70819 | 8.8 | 25.2 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70874 | 8.8 | 25.2 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-74946 | 8.8 | 25.2 | Mozilla | Firefox | CWE-119 | Privilege escalation due to incorrect boundary conditions in the Graphics: Ca… |
| CVE-2026-74983 | 8.1 | 25.1 | Mozilla | Firefox | CWE-693 | Mitigation bypass in the Data Loss Prevention component |
| CVE-2026-75778 | 5.5 | 25.2 | code-projects | Task Management System | CWE-74 | code-projects Task Management System Login Form index.php select_with_multipl… |
| CVE-2026-46482 | 5.3 | 25.1 | mybb | mybb | CWE-636 | MyBB: Security Question insufficient validation |
| CVE-2026-74985 | 9.8 | 25.0 | Mozilla | Firefox | CWE-269 | Privilege escalation in the Enterprise Policies component |
| CVE-2026-61321 | 8.1 | 24.9 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-284 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-70929 | 8.1 | 24.9 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70957 | 8.1 | 24.9 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | CWE-284 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70999 | 8.1 | 24.9 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-60983 | 7.7 | 24.9 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-70988 | 7.7 | 24.9 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71056 | 7.7 | 24.9 | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | CWE-284 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-19671 | 7.1 | 24.9 | CISAgov | Malcolm | CWE-409 | Improper handling of highly compressed data (data amplification) in CISA Malcolm |
| CVE-2026-60830 | 6.5 | 24.9 | Oracle Corporation | Oracle Workflow | CWE-284 | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (comp… |
| CVE-2026-70938 | 6.5 | 24.9 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70968 | 6.5 | 24.9 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | CWE-284 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-73189 | 6.5 | 24.9 | Themeum | WP Crowdfunding | CWE-639 | WordPress WP Crowdfunding plugin < 2.2.1 - Insecure Direct Object References … |
| CVE-2026-73404 | 6.5 | 24.9 | Stylemix | MasterStudy LMS | CWE-862 | WordPress MasterStudy LMS plugin <= 3.7.41 - Broken Access Control vulnerability |
| CVE-2026-70862 | 9.1 | 24.7 | Oracle Corporation | Oracle Application Testing Suite | CWE-284 | Vulnerability in Oracle Application Testing Suite. The supported version that… |
| CVE-2026-70872 | 9.1 | 24.7 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-70883 | 9.1 | 24.7 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-17106 | 7.1 | 24.8 | moby | go-archive | CWE-59 | Tar extraction in moby/go-archive can write outside the destination directory… |
| CVE-2026-62377 | 4.3 | 24.8 | strukturag | libheif | CWE-617 | libheif: Reachable assertion in HeifContext::get_track() aborts on a valid-bu… |
| CVE-2026-60955 | 8.2 | 24.6 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-73882 | 7.5 | 24.7 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-74941 | 8.8 | 24.5 | Mozilla | Firefox | CWE-269 | Privilege escalation in the Graphics: CanvasWebGL component |
| CVE-2026-70778 | 8.7 | 24.6 | Oracle Corporation | Oracle Customer Care | CWE-284 | Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite … |
| CVE-2026-70882 | 8.7 | 24.6 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-60765 | 7.5 | 24.5 | Oracle Corporation | Siebel Apps - Marketing | CWE-306 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co… |
| CVE-2026-73377 | 7.5 | 24.5 | supsystic | Ultimate Maps by Supsystic | CWE-862 | WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - Broken Access Control v… |
| CVE-2026-73994 | 7.5 | 24.5 | Syed Balkhi | Charitable | CWE-862 | WordPress Charitable plugin <= 1.8.11.3 - Broken Access Control vulnerability |
| CVE-2026-76042 | 3.1 | 24.6 | Chrome | CWE-908 | Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169… | |
| CVE-2026-74938 | 9.1 | 24.5 | Mozilla | Firefox | CWE-693 | Mitigation bypass in the JavaScript: GC component |
| CVE-2026-75836 | 8.7 | 24.4 | getgrav | grav | CWE-862 | Grav API Plugin before 1.0.14 Missing Authorization |
| CVE-2026-75912 | 8.3 | 24.4 | Hmbown | CodeWhale | CWE-88 | CodeWhale before 0.8.64 Argument Injection via git_blame |
| CVE-2026-61124 | 7.1 | 24.5 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-62631 | 8.8 | 24.3 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-70897 | 8.2 | 24.3 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-71572 | 4.8 | 24.3 | Joomla! Project | Joomla! CMS | CWE-93 | Joomla! Core - [20260801] - Response header injection in download views in Jo… |
| CVE-2026-74976 | 6.5 | 24.2 | Mozilla | Firefox | CWE-843 | JIT miscompilation in the JavaScript Engine: JIT component |
| CVE-2026-74969 | 8.8 | 24.1 | Mozilla | Firefox | CWE-416 | Use-after-free in the Layout: Text and Fonts component |
| CVE-2026-62485 | 8.2 | 24.0 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-72531 | 5.1 | 24.1 | Joomla! Project | Joomla! CMS | CWE-284 | Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice … |
| CVE-2026-72532 | 5.1 | 24.1 | Joomla! Project | Joomla! CMS | CWE-284 | Joomla! Core - [20260805] - Improper ACL checks for category webservice endpo… |
| CVE-2026-70672 | 7.4 | 24.0 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-70837 | 7.1 | 23.9 | Oracle Corporation | Oracle Financials for Asia/Pacific | CWE-284 | Vulnerability in the Oracle Financials for Asia/Pacific product of Oracle E-B… |
| CVE-2026-70990 | 6.8 | 24.0 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-200 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71121 | 6.5 | 24.0 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-73395 | 6.5 | 24.0 | wpdevart | Booking calendar, Appointment Booking System | CWE-639 | WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Ins… |
| CVE-2026-47721 | 6.3 | 24.0 | frangoteam | FUXA | CWE-862 | FUXA: Scheduler API missing admin check enables operator-to-admin escalation … |
| CVE-2026-63337 | 7.5 | 23.8 | rabbitmq | rabbitmq-java-client | CWE-470 | RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescript… |
| CVE-2026-60856 | 7.4 | 23.9 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | CWE-284 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-74905 | 6.9 | 23.9 | siyuan-note | siyuan | CWE-918 | SiYuan before v3.7.4 SSRF via IPv6 Transition Address Bypass |
| CVE-2026-70657 | 4.3 | 23.9 | 9001 | copyparty | CWE-863 | Copyparty: file/dirkey confusion |
| CVE-2026-71124 | 4.3 | 23.9 | Oracle Corporation | Oracle Access Manager | CWE-284 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-75851 | 9.4 | 23.8 | ArcadeData | arcadedb | CWE-269 | ArcadeDB before 26.8.1 Authentication Bypass via Async Command |
| CVE-2026-70807 | 8.5 | 23.8 | Oracle Corporation | Oracle Call Center Technology | CWE-284 | Vulnerability in the Oracle Call Center Technology product of Oracle E-Busine… |
| CVE-2026-62552 | 7.5 | 23.8 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70777 | 7.5 | 23.8 | Oracle Corporation | Oracle iSupplier Portal | CWE-284 | Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Sui… |
| CVE-2026-71104 | 7.2 | 23.8 | Oracle Corporation | Oracle HRMS (Netherlands) | CWE-284 | Vulnerability in the Oracle HRMS (Netherlands) product of Oracle E-Business S… |
| CVE-2026-70816 | 7.1 | 23.8 | Oracle Corporation | Oracle Financials for EMEA | CWE-284 | Vulnerability in the Oracle Financials for EMEA product of Oracle E-Business … |
| CVE-2026-70833 | 7.1 | 23.8 | Oracle Corporation | Oracle Landed Cost Management | CWE-284 | Vulnerability in the Oracle Landed Cost Management product of Oracle E-Busine… |
| CVE-2026-70839 | 7.1 | 23.8 | Oracle Corporation | Oracle Financials for EMEA | — | Vulnerability in the Oracle Financials for EMEA product of Oracle E-Business … |
| CVE-2026-74046 | 6.9 | 23.8 | Wazuh | wazuh-manager | CWE-409 | Wazuh 4.4.0 < 4.14.7 DoS via fdecompress_files() Zip Bomb |
| CVE-2026-62509 | 5.3 | 23.8 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62510 | 5.3 | 23.7 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62566 | 5.3 | 23.7 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62579 | 5.3 | 23.7 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70727 | 5.3 | 23.8 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-70754 | 5.3 | 23.7 | Oracle Corporation | Oracle Hyperion Financial Reporting | CWE-284 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70911 | 5.3 | 23.7 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-200 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-73336 | 5.1 | 23.8 | Joomla! Project | Joomla! CMS | CWE-79 | Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.… |
| CVE-2026-60981 | 8.7 | 23.6 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-61215 | 8.7 | 23.6 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-61219 | 8.7 | 23.6 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-75840 | 8.7 | 23.6 | ArcadeData | arcadedb | CWE-1025 | ArcadeDB before 26.8.1 Arbitrary File Read via Unescaped Regex |
| CVE-2026-70803 | 7.6 | 23.5 | Oracle Corporation | Oracle General Ledger | CWE-284 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite… |
| CVE-2026-50577 | 7.4 | 23.6 | fbeta-GmbH | ePA3-Service-OpenSource | CWE-323 | ePA 3.x Integration: AES-GCM Nonce Reuse via Frozen VAU Request Counter |
| CVE-2026-73922 | 9.1 | 23.5 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73924 | 9.1 | 23.5 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-74949 | 8.8 | 23.3 | Mozilla | Firefox | CWE-416 | Use-after-free in the Graphics: Canvas2D component |
| CVE-2026-73902 | 7.5 | 23.3 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73915 | 7.5 | 23.3 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73934 | 7.5 | 23.3 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73935 | 7.5 | 23.3 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-71017 | 6.5 | 23.3 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-18504 | 5.4 | 23.4 | fastify | fastify | CWE-20 | fastify vulnerable to schema validation bypass via root primitive coercion mi… |
| CVE-2026-65959 | 5.3 | 23.4 | vitessio | vitess | CWE-862 | Vitess: Missing authorization on vttablet /debug/vrlog exposes live VReplicat… |
| CVE-2026-62590 | 8.5 | 23.3 | Oracle Corporation | Siebel CRM Integration | CWE-284 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-70859 | 8.5 | 23.3 | Oracle Corporation | Siebel CRM Integration | CWE-284 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-52877 | 8.3 | 23.2 | truelockmc | streambert | CWE-20 | Streambert : Insecure Protocol Execution in open-external IPC Handler |
| CVE-2026-52793 | 8.1 | 23.2 | froxlor | froxlor | CWE-287 | Froxlor: API Authentication bypasses 2FA Authentication |
| CVE-2026-60679 | 7.5 | 23.3 | Oracle Corporation | Oracle WebLogic Server | CWE-287 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-18534 | 7.4 | 23.2 | The Browser Company of New York | ArcSearch | CWE-1021 | Address bar spoofing risk in affected iOS versions of Arc Search |
| CVE-2026-74935 | 8.8 | 23.1 | Mozilla | Firefox | CWE-269 | Privilege escalation in the DOM: Networking component |
| CVE-2026-70725 | 7.6 | 23.1 | Oracle Corporation | Oracle Advanced Inbound Telephony | CWE-284 | Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Bu… |
| CVE-2026-70764 | 7.6 | 23.1 | Oracle Corporation | Oracle General Ledger | CWE-284 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite… |
| CVE-2026-70724 | 7.5 | 23.1 | Oracle Corporation | MySQL Cluster | — | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluste… |
| CVE-2026-61308 | 6.8 | 23.1 | Oracle Corporation | Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition | CWE-284 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM E… |
| CVE-2026-61021 | 9.9 | 22.9 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-57826 | 9.8 | 22.9 | n/a | n/a | CWE-295 | An issue was discovered in openHiTLS 0.2.0 through 0.3.2. In the X.509 certif… |
| CVE-2026-61042 | 8.8 | 22.8 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-60995 | 9.9 | 22.7 | Oracle Corporation | Oracle Identity Manager Connector | CWE-284 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-73373 | 8.9 | 22.8 | Joomla! Project | Joomla! CMS | CWE-434 | Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0… |
| CVE-2026-73929 | 8.3 | 22.8 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-60748 | 7.6 | 22.8 | Oracle Corporation | Oracle General Ledger | CWE-284 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite… |
| CVE-2026-61208 | 7.6 | 22.8 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-73908 | 7.5 | 22.8 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-74979 | 9.8 | 22.6 | Mozilla | Firefox | CWE-284 | Mitigation bypass in the Add-ons Manager component |
| CVE-2026-71167 | 9.4 | 22.7 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-28191 | 8.8 | 22.7 | Theme-One Inc. | The Grid | CWE-266 | WordPress The Grid plugin <= 2.7.9.1 - Privilege Escalation vulnerability |
| CVE-2026-71024 | 8.2 | 22.7 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71100 | 5.3 | 22.6 | Oracle Corporation | Oracle Database Server | CWE-284 | Vulnerability in the RDBMS component of Oracle Database Server. Supported ver… |
| CVE-2026-71148 | 5.3 | 22.6 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-73895 | 5.3 | 22.6 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73899 | 5.3 | 22.6 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73906 | 5.3 | 22.6 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-67442 | 2.0 | 22.6 | frangoteam | FUXA | CWE-284 | FUXA Business Logic Flaw: Role Deletion Without User Assignment Cleanup |
| CVE-2026-74939 | 8.8 | 22.4 | Mozilla | Firefox | CWE-269 | Privilege escalation in the DOM: Navigation component |
| CVE-2026-74942 | 8.8 | 22.4 | Mozilla | Firefox | CWE-269 | Privilege escalation in the Remote Settings Client component |
| CVE-2026-45733 | 8.3 | 22.4 | TriliumNext | Trilium | CWE-79 | Trilium: Stored XSS in note icon rendering leads to Remote Code Execution in … |
| CVE-2026-70694 | 7.7 | 22.5 | Oracle Corporation | Oracle Payments | — | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (comp… |
| CVE-2026-70695 | 7.7 | 22.5 | Oracle Corporation | Oracle Payments | — | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (comp… |
| CVE-2026-75843 | 9.4 | 22.4 | ArcadeData | arcadedb | CWE-269 | ArcadeDB before 26.8.1 Privilege Escalation via gRPC Transaction |
| CVE-2026-62610 | 9.1 | 22.3 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-70668 | 9.1 | 22.3 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62535 | 8.6 | 22.3 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62620 | 8.6 | 22.3 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-70728 | 8.5 | 22.3 | Oracle Corporation | Oracle Autonomous Health Framework | — | Vulnerability in Oracle Autonomous Health Framework (component: Trace File An… |
| CVE-2026-32468 | 7.5 | 22.3 | rayhanduitku | Duitku Payment Gateway | CWE-497 | WordPress Duitku Payment Gateway plugin <= 2.11.14 - Sensitive Data Exposure … |
| CVE-2026-70696 | 7.5 | 22.3 | Oracle Corporation | Oracle Payments | — | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (comp… |
| CVE-2026-62601 | 7.1 | 22.3 | Oracle Corporation | Oracle Sales | — | Vulnerability in the Oracle Sales product of Oracle E-Business Suite (compone… |
| CVE-2026-70736 | 7.1 | 22.3 | Oracle Corporation | Oracle Hyperion Profitability and Cost Management | — | Vulnerability in the Oracle Hyperion Profitability and Cost Management produc… |
| CVE-2026-70808 | 7.1 | 22.3 | Oracle Corporation | Oracle Scripting | CWE-284 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (com… |
| CVE-2026-70844 | 7.1 | 22.3 | Oracle Corporation | Oracle Loans | CWE-284 | Vulnerability in the Oracle Loans product of Oracle E-Business Suite (compone… |
| CVE-2026-71060 | 4.4 | 22.4 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-45116 | 8.7 | 22.2 | mybb | mybb | CWE-79 | MyBB: Profile field type confusion XSS |
| CVE-2026-55839 | 8.7 | 22.2 | kestra-io | kestra | CWE-79 | Kestra: Stored XSS via custom Markdown [[link]] attribute injection |
| CVE-2026-60944 | 8.2 | 22.2 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-61222 | 8.2 | 22.2 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-70790 | 7.4 | 22.2 | Oracle Corporation | Oracle Telecommunications Billing Integrator | CWE-284 | Vulnerability in the Oracle Telecommunications Billing Integrator product of … |
| CVE-2026-61288 | 7.1 | 22.2 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-50576 | 6.8 | 22.2 | fbeta-GmbH | ePA3-Service-OpenSource | CWE-113 | ePA 3.x Integration: HTTP Header Injection in VAU Inner Requests |
| CVE-2026-45125 | 5.3 | 22.2 | mybb | mybb | CWE-93 | MyBB: Email User CRLF injection |
| CVE-2026-62289 | 4.3 | 22.2 | strukturag | libheif | CWE-191 | libheif: Integer underflow in Fraction constructor via double clap transform … |
| CVE-2026-60903 | 8.7 | 22.1 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60934 | 8.7 | 22.1 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60935 | 8.7 | 22.1 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60954 | 8.7 | 22.1 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60980 | 8.7 | 22.1 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-61212 | 8.5 | 22.1 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-60769 | 7.5 | 22.1 | Oracle Corporation | Oracle General Ledger | CWE-306 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite… |
| CVE-2026-70930 | 7.5 | 22.1 | Oracle Corporation | Oracle Order Management | CWE-306 | Vulnerability in the Oracle Order Management product of Oracle E-Business Sui… |
| CVE-2026-70937 | 7.5 | 22.1 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70973 | 7.5 | 22.1 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | CWE-306 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-71160 | 7.5 | 22.1 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-60759 | 7.4 | 22.1 | Oracle Corporation | Oracle Internet Procurement Connector | CWE-284 | Vulnerability in the Oracle Internet Procurement Connector product of Oracle … |
| CVE-2026-60766 | 7.4 | 22.1 | Oracle Corporation | Siebel CRM Integration | CWE-284 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-60792 | 7.4 | 22.1 | Oracle Corporation | Siebel CRM Deployment | CWE-284 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-60797 | 7.4 | 22.2 | Oracle Corporation | Siebel CRM Integration | CWE-284 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-60803 | 7.4 | 22.1 | Oracle Corporation | Siebel Apps - Marketing | CWE-284 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co… |
| CVE-2026-60915 | 7.4 | 22.1 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-60933 | 7.4 | 22.1 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-71009 | 7.4 | 22.1 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71143 | 7.4 | 22.1 | Oracle Corporation | Oracle Communications Unified Inventory Management | CWE-284 | Vulnerability in the Oracle Communications Unified Inventory Management produ… |
| CVE-2026-70982 | 6.8 | 22.1 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-70983 | 6.8 | 22.1 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-70976 | 9.1 | 22.0 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-70979 | 9.1 | 22.0 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-306 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-62596 | 8.5 | 22.0 | Oracle Corporation | Siebel CRM Integration | CWE-284 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-61340 | 8.2 | 22.0 | Oracle Corporation | Oracle MES for Process Manufacturing | CWE-284 | Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E… |
| CVE-2026-11801 | 7.5 | 22.0 | gwin | WPAdverts – Classifieds Plugin | CWE-862 | WPAdverts <= 2.3.2 - Missing Authorization to Unauthenticated Sensitive Infor… |
| CVE-2026-73890 | 7.5 | 22.0 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-62587 | 7.1 | 22.0 | Oracle Corporation | Siebel CRM Administration | CWE-284 | Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (… |
| CVE-2026-75838 | 5.1 | 22.0 | cure53 | DOMPurify | CWE-79 | DOMPurify before 3.4.13 Cross-Site Scripting via IN_PLACE hook |
| CVE-2026-61230 | 8.6 | 21.9 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-70890 | 7.5 | 21.9 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-71076 | 5.3 | 21.9 | Oracle Corporation | Oracle Agile PLM MCAD Connector | CWE-284 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply… |
| CVE-2026-71157 | 5.3 | 21.9 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73877 | 5.3 | 21.9 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73888 | 5.3 | 21.9 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73889 | 5.3 | 21.9 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-61634 | 0.0 | 21.9 | rabbitmq | rabbitmq-java-client | CWE-20 | RabbitMQ Java client accepts broker frames larger than the negotiated AMQP fr… |
| CVE-2021-43716 | 9.8 | 21.8 | n/a | n/a | CWE-347 | Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Net… |
| CVE-2026-62582 | 9.6 | 21.8 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-74906 | 8.7 | 21.8 | siyuan-note | siyuan | CWE-863 | SiYuan before v3.7.4 Incorrect Authorization via Publish Access |
| CVE-2026-70782 | 8.1 | 21.8 | Oracle Corporation | Oracle Labor Distribution | — | Vulnerability in the Oracle Labor Distribution product of Oracle E-Business S… |
| CVE-2026-70830 | 8.1 | 21.8 | Oracle Corporation | Oracle Process Manufacturing Systems | CWE-284 | Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E… |
| CVE-2026-49222 | 7.6 | 21.8 | givanz | Vvveb | CWE-639 | Vvveb product question authorization bypass allows Vendors to read, approve, … |
| CVE-2026-49223 | 7.6 | 21.8 | givanz | Vvveb | CWE-639 | Vvveb product review authorization bypass allows Vendors to read, approve, ed… |
| CVE-2026-49227 | 7.6 | 21.8 | givanz | Vvveb | CWE-639 | Vvveb comment authorization bypass allows Authors to read, approve, edit, or … |
| CVE-2026-73529 | 6.9 | 21.8 | alextselegidis | plainpad | CWE-307 | Plainpad Missing Rate Limiting via POST /v1/sessions |
| CVE-2026-41921 | 5.1 | 21.8 | Koha Community | Koha | CWE-79 | Koha Stored XSS via Purchase Suggestion Handler |
| CVE-2026-23938 | 2.1 | 21.9 | Zabbix | Zabbix | CWE-248 | Server DoS via JavaScript preprocessing or script items |
| CVE-2026-74953 | 8.8 | 21.7 | Mozilla | Firefox | CWE-269 | Privilege escalation in the Networking: Cookies component |
| CVE-2026-74965 | 8.8 | 21.7 | Mozilla | Firefox | CWE-269 | Privilege escalation in the Shell Integration component |
| CVE-2026-75898 | 8.4 | 21.7 | infiniflow | ragflow | CWE-918 | RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component |
| CVE-2026-60392 | 7.8 | 21.7 | Oracle Corporation | Oracle Outside In Technology | CWE-502 | Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Mi… |
| CVE-2026-60412 | 7.8 | 21.7 | Oracle Corporation | Oracle Outside In Technology | CWE-502 | Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Mi… |
| CVE-2026-71048 | 7.6 | 21.7 | Oracle Corporation | Oracle Product Lifecycle Analytics | CWE-284 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Sup… |
| CVE-2026-70679 | 5.3 | 21.7 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-23929 | 8.5 | 21.6 | Zabbix | Zabbix | CWE-1321 | Prototype pollution leading to stored XSS |
| CVE-2026-74039 | 7.1 | 21.5 | Wazuh | wazuh-manager | CWE-770 | Wazuh 4.0.0 < 4.14.7 API DoS via Deeply Nested JSON auth_context |
| CVE-2026-69160 | 6.5 | 21.4 | OpenListTeam | OpenList | CWE-639 | OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API |
| CVE-2026-73398 | 6.5 | 21.5 | Papaki (Enartia S.A.) | Piraeus Bank WooCommerce Payment Gateway | CWE-288 | WordPress Piraeus Bank WooCommerce Payment Gateway plugin 3.2.0 - Broken Auth… |
| CVE-2026-62460 | 5.0 | 21.4 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-62471 | 8.1 | 21.3 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70795 | 8.1 | 21.3 | Oracle Corporation | Oracle Applications Platform Engineering | CWE-284 | Vulnerability in the Oracle Applications Platform Engineering product of Orac… |
| CVE-2026-73894 | 7.3 | 21.4 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73918 | 7.3 | 21.4 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-71091 | 6.5 | 21.3 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-73371 | 5.1 | 21.3 | Joomla! Project | Joomla! CMS | CWE-284 | Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joo… |
| CVE-2026-73372 | 5.1 | 21.3 | Joomla! Project | Joomla! CMS | CWE-284 | Joomla! Core - [20260809] - Improper ACL checks when injection schema.org con… |
| CVE-2026-63335 | 6.3 | 21.3 | rabbitmq | rabbitmq-java-client | CWE-20 | RabbitMQ Java client malformed body frame triggers raw command assembler exce… |
| CVE-2026-48796 | 5.3 | 21.2 | cefsharp | CefSharp | CWE-22 | CefSharp: `FolderSchemeHandlerFactory` path boundary check can expose files o… |
| CVE-2026-74937 | 8.8 | 21.1 | Mozilla | Firefox | CWE-416 | Use-after-free in the JavaScript: GC component |
| CVE-2026-45115 | 8.7 | 21.1 | mybb | mybb | CWE-79 | MyBB: Buddy/ignore list username XSS |
| CVE-2026-62598 | 8.2 | 21.2 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-70703 | 8.2 | 21.2 | Oracle Corporation | Oracle Agile Engineering Data Management | — | Vulnerability in the Oracle Agile Engineering Data Management product of Orac… |
| CVE-2026-24184 | 7.5 | 21.2 | NVIDIA | Cumulus Linux GA | CWE-120 | NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Pro… |
| CVE-2026-52735 | 9.3 | 21.1 | ZcashFoundation | zebra | CWE-684 | ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-o… |
| CVE-2026-74015 | 9.3 | 21.1 | merkulove | Readabler | CWE-89 | WordPress Readabler plugin < 2.0.18 - SQL Injection vulnerability |
| CVE-2026-61293 | 8.1 | 21.1 | Oracle Corporation | Oracle Hyperion Calculation Manager | CWE-284 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-60781 | 7.1 | 20.9 | Oracle Corporation | Oracle Payments | CWE-306 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (comp… |
| CVE-2026-47699 | 6.4 | 20.9 | confidential-containers | guest-components | CWE-22 | Confidential Containers Guest Components image-rs: zip-slip-class arbitrary f… |
| CVE-2026-75829 | 8.6 | 20.8 | getgrav | grav | CWE-1336 | grav-plugin-api before 1.0.15 Twig SSTI via translate endpoint |
| CVE-2026-69189 | 7.6 | 20.8 | hoppscotch | hoppscotch | CWE-200 | Hoppscotch: Cross-user private data exposure and UserHistory IDOR via team Gr… |
| CVE-2026-62481 | 7.5 | 20.9 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | CWE-284 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62555 | 6.5 | 20.9 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-73932 | 5.3 | 20.8 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-70903 | 8.7 | 20.8 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-71000 | 8.7 | 20.8 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71014 | 9.1 | 20.6 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71036 | 9.1 | 20.6 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-73865 | 9.1 | 20.6 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-61228 | 8.6 | 20.6 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-70996 | 8.6 | 20.6 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-28567 | 7.5 | 20.6 | Fahad Mahmood | WP Sort Order | CWE-862 | WordPress WP Sort Order plugin <= 1.3.5 - Broken Access Control vulnerability |
| CVE-2026-28571 | 7.5 | 20.6 | WPPOOL | FormyChat | CWE-862 | WordPress FormyChat plugin <= 2.15.7 - Broken Access Control vulnerability |
| CVE-2026-70947 | 7.5 | 20.6 | Oracle Corporation | Oracle Purchasing | CWE-284 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co… |
| CVE-2026-70985 | 7.5 | 20.6 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71038 | 7.5 | 20.6 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71043 | 7.5 | 20.6 | Oracle Corporation | Oracle Agile PLM | CWE-284 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-71061 | 7.5 | 20.6 | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | CWE-284 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-73887 | 7.5 | 20.6 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-71059 | 9.9 | 20.6 | Oracle Corporation | Oracle BI Publisher | CWE-284 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-60967 | 8.8 | 20.5 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | CWE-284 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-61213 | 8.8 | 20.5 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-61273 | 8.8 | 20.5 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-70899 | 8.8 | 20.5 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-70951 | 8.8 | 20.5 | Oracle Corporation | Siebel CRM End User | CWE-284 | Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (compon… |
| CVE-2026-70956 | 8.8 | 20.5 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | CWE-306 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70965 | 8.8 | 20.5 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | CWE-284 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-71044 | 8.8 | 20.5 | Oracle Corporation | Oracle Agile PLM | CWE-284 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-71052 | 8.8 | 20.5 | Oracle Corporation | Oracle Agile Engineering Data Management | CWE-284 | Vulnerability in the Oracle Agile Engineering Data Management product of Orac… |
| CVE-2026-71058 | 8.8 | 20.6 | Oracle Corporation | Oracle BI Publisher | CWE-284 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-71150 | 8.8 | 20.5 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-62589 | 8.7 | 20.5 | Oracle Corporation | Siebel CRM Integration | CWE-284 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-71018 | 8.2 | 20.4 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-70974 | 5.3 | 20.3 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-200 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-74956 | 9.1 | 20.2 | Mozilla | Firefox | CWE-843 | Same-origin policy bypass in the DOM: Service Workers component |
| CVE-2026-70769 | 6.5 | 20.2 | Oracle Corporation | Oracle Hyperion Financial Reporting | CWE-284 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-76033 | 4.2 | 20.2 | Chrome | CWE-20 | Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169… | |
| CVE-2026-23922 | 2.1 | 20.2 | Zabbix | Zabbix | CWE-522 | Email media OAuth secret leak to Super Admin |
| CVE-2026-70692 | 7.7 | 20.1 | Oracle Corporation | Oracle Marketing Encyclopedia System | — | Vulnerability in the Oracle Marketing Encyclopedia System product of Oracle E… |
| CVE-2026-70824 | 6.5 | 20.1 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70825 | 6.5 | 20.1 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-74009 | 5.3 | 20.1 | Razorpay | Razorpay for WooCommerce | CWE-639 | WordPress Razorpay for WooCommerce plugin <= 4.8.7 - Insecure Direct Object R… |
| CVE-2026-62442 | 8.1 | 20.0 | Oracle Corporation | Siebel CRM Cloud Applications | — | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-61306 | 7.1 | 20.1 | Oracle Corporation | Oracle Complex Maintenance, Repair and Overhaul | CWE-284 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product … |
| CVE-2026-70751 | 6.8 | 20.1 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70788 | 6.5 | 20.0 | Oracle Corporation | Oracle Hyperion Financial Reporting | CWE-284 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70716 | 5.9 | 20.0 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-71120 | 5.3 | 20.0 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-61045 | 8.6 | 19.9 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-32465 | 8.8 | 19.8 | g5theme | Essential Real Estate | CWE-502 | WordPress Essential Real Estate plugin <= 5.3.3 - PHP Object Injection vulner… |
| CVE-2026-19869 | 7.6 | 19.8 | neo4j | graphql | CWE-639 | Privilege Escalation via Dropped Field-Level @authentication |
| CVE-2026-75830 | 7.1 | 19.8 | getgrav | grav | CWE-73 | grav-plugin-api before 1.0.15 Path Traversal via batchCopy |
| CVE-2026-23937 | 6.0 | 19.8 | Zabbix | Zabbix | CWE-203 | Host PSK extraction in Zabbix API |
| CVE-2026-23931 | 5.3 | 19.8 | Zabbix | Zabbix | CWE-203 | Frontend plaintext macro value enumeration via the validatate.api.exists action |
| CVE-2026-63641 | 2.3 | 19.8 | MagicMirrorOrg | MagicMirror | CWE-284 | MagicMirror Socket.IO module namespaces bypass configured IP whitelist and al… |
| CVE-2026-32466 | 8.5 | 19.6 | WPExperts | Gravity Forms Bookings premium | CWE-89 | WordPress Gravity Forms Bookings premium plugin <= 2.1 - SQL Injection vulner… |
| CVE-2026-60758 | 8.5 | 19.6 | Oracle Corporation | Siebel Artificial Intelligence | CWE-284 | Vulnerability in the Siebel Artificial Intelligence product of Oracle Siebel … |
| CVE-2026-60798 | 8.5 | 19.6 | Oracle Corporation | Siebel CRM Deployment | CWE-284 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-61326 | 8.5 | 19.6 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-284 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-71049 | 8.5 | 19.6 | Oracle Corporation | Oracle Product Lifecycle Analytics | CWE-284 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Sup… |
| CVE-2026-60998 | 8.0 | 19.7 | Oracle Corporation | Oracle Identity Manager Connector | CWE-284 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-53958 | 7.6 | 19.7 | RARgames | 4gaBoards | CWE-287 | 4gaBoards: SSO Pre-Account Takeover / Hijacking via Mass Assignment |
| CVE-2026-70971 | 7.1 | 19.6 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | CWE-284 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-52873 | 6.9 | 19.8 | truelockmc | streambert | CWE-79 | Streambert: Global CSP Removal in Wyzie Redeem Window Enables Unconstrained X… |
| CVE-2026-48744 | 6.5 | 19.6 | saleor | saleor | CWE-285 | Saleor: Anonymous users can modify channel settings via `channelUpdate` due t… |
| CVE-2026-70907 | 5.3 | 19.7 | Oracle Corporation | Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition | CWE-284 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM E… |
| CVE-2026-76032 | 5.3 | 19.6 | pydio | cells | CWE-862 | Pydio Cells 5.0.0 to 5.0.2 - Missing Authorization on the Share Link REST Han… |
| CVE-2026-12564 | 9.6 | 19.4 | Red Hat | Red Hat Ansible Automation Platform 2 | CWE-918 | Automation-controller: automation-controller: kubernetes service account toke… |
| CVE-2026-61286 | 8.6 | 19.5 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-75130 | 6.4 | 19.4 | Uptash | Context7 | CWE-1427 | Context7 2.1.2 Prompt Injection via Custom AI Instructions |
| CVE-2026-60996 | 8.7 | 19.3 | Oracle Corporation | Oracle Identity Manager Connector | CWE-284 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-28570 | 8.1 | 19.2 | SpabRice | Vavo Core | CWE-98 | WordPress Vavo Core plugin <= 2.3.0 - Local File Inclusion vulnerability |
| CVE-2026-32464 | 8.1 | 19.2 | Vladimir Prelovac | Theme Test Drive | CWE-98 | WordPress Theme Test Drive plugin <= 2.9.1 - Local File Inclusion vulnerability |
| CVE-2026-73345 | 7.1 | 19.2 | Saad Iqbal | License Manager for WooCommerce | CWE-89 | WordPress License Manager for WooCommerce plugin <= 3.0.18 - SQL Injection vu… |
| CVE-2026-71008 | 6.8 | 19.3 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-70887 | 8.2 | 19.2 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-74966 | 7.5 | 19.1 | Mozilla | Firefox | CWE-359 | Information disclosure in the Form Autofill component |
| CVE-2026-49452 | 6.5 | 19.2 | Kozea | WeasyPrint | CWE-74 | WeasyPrint: CSS Injection via Presentational Hints |
| CVE-2026-62623 | 8.8 | 19.0 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-70715 | 8.8 | 19.0 | Oracle Corporation | Oracle Autonomous Health Framework | — | Vulnerability in Oracle Autonomous Health Framework (component: Trace File An… |
| CVE-2026-75841 | 5.3 | 19.0 | ArcadeData | arcadedb | CWE-770 | ArcadeDB before 26.8.1 Denial of Service via range() |
| CVE-2026-75828 | 9.3 | 18.8 | getgrav | grav | CWE-79 | Grav before 2.0.15 Stored XSS via detectXss() Quote Bypass |
| CVE-2026-61229 | 8.1 | 19.0 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-62594 | 7.7 | 18.8 | Oracle Corporation | Siebel CRM Integration | CWE-284 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-62615 | 8.5 | 18.6 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-70885 | 8.5 | 18.6 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-61331 | 7.7 | 18.7 | Oracle Corporation | Oracle Financials Common Modules | CWE-284 | Vulnerability in the Oracle Financials Common Modules product of Oracle E-Bus… |
| CVE-2026-70875 | 7.5 | 18.6 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-61290 | 7.1 | 18.7 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60895 | 6.8 | 18.6 | Oracle Corporation | Oracle Unified Directory | CWE-284 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2025-9211 | 6.7 | 18.7 | Otalio | Ship Property Management System | CWE-79 | Cross-site scripting in Otalio Ship Property Management System |
| CVE-2026-70732 | 6.5 | 18.7 | Oracle Corporation | Oracle Mobile Application Server | — | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Bus… |
| CVE-2026-70975 | 6.5 | 18.7 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-200 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-73885 | 7.2 | 18.6 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73886 | 7.2 | 18.6 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-60693 | 7.1 | 18.6 | Oracle Corporation | Oracle General Ledger | CWE-284 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite… |
| CVE-2026-70809 | 7.1 | 18.6 | Oracle Corporation | Oracle Scripting | CWE-284 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (com… |
| CVE-2026-73867 | 6.5 | 18.6 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-45123 | 4.3 | 18.6 | mybb | mybb | CWE-918 | MyBB: IPv6 SSRF |
| CVE-2026-47245 | 4.3 | 18.5 | mybb | mybb | CWE-252 | MyBB: Buddy list corruption |
| CVE-2026-60853 | 3.7 | 18.6 | Oracle Corporation | Helidon | CWE-200 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-70786 | 7.6 | 18.4 | Oracle Corporation | Oracle Service Fulfillment Manager | CWE-284 | Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-B… |
| CVE-2026-70864 | 7.6 | 18.4 | Oracle Corporation | Oracle Application Testing Suite | CWE-284 | Vulnerability in Oracle Application Testing Suite. The supported version that… |
| CVE-2026-62523 | 6.5 | 18.4 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-73914 | 6.5 | 18.4 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-70753 | 6.3 | 18.4 | Oracle Corporation | Oracle Hyperion Financial Reporting | CWE-284 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-75858 | 8.5 | 18.4 | Hmbown | CodeWhale | CWE-94 | CodeWhale rlm_eval before 0.8.64 Remote Code Execution |
| CVE-2026-70676 | 7.0 | 18.4 | Oracle Corporation | Oracle Hyperion Calculation Manager | CWE-284 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-32463 | 9.9 | 18.3 | Kamlesh Parmar | Sync Post With Other Site | CWE-434 | WordPress Sync Post With Other Site plugin <= 1.9.3 - Arbitrary File Upload v… |
| CVE-2026-71045 | 8.8 | 18.1 | Oracle Corporation | Oracle Agile PLM | CWE-284 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-61268 | 8.1 | 18.0 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-61270 | 8.1 | 18.0 | Oracle Corporation | JD Edwards EnterpriseOne Orchestrator | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle … |
| CVE-2026-70904 | 8.1 | 18.1 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-61305 | 8.3 | 18.0 | Oracle Corporation | Oracle BI Publisher | CWE-284 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-70935 | 7.1 | 17.9 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-71003 | 7.1 | 17.9 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71012 | 7.1 | 17.9 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-60589 | 3.7 | 18.0 | Oracle Corporation | Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition | CWE-200 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM E… |
| CVE-2026-70804 | 7.7 | 17.8 | Oracle Corporation | Oracle Public Sector Human Resources | — | Vulnerability in the Oracle Public Sector Human Resources product of Oracle E… |
| CVE-2026-74958 | 7.5 | 17.8 | Mozilla | Firefox | CWE-1021 | Information disclosure in the WebRTC component |
| CVE-2026-62616 | 7.2 | 17.7 | Oracle Corporation | Oracle Reports Developer | CWE-284 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62458 | 7.1 | 17.8 | Oracle Corporation | Oracle Work in Process | — | Vulnerability in the Oracle Work in Process product of Oracle E-Business Suit… |
| CVE-2026-75089 | 5.5 | 17.7 | PHPGurukul | Complaint Management System | CWE-74 | PHPGurukul Complaint Management System check_availability.php sql injection |
| CVE-2026-70683 | 4.3 | 17.7 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-70791 | 7.6 | 17.6 | Oracle Corporation | Oracle Transportation Execution | CWE-284 | Vulnerability in the Oracle Transportation Execution product of Oracle E-Busi… |
| CVE-2026-68927 | 3.0 | 17.6 | MobSF | Mobile-Security-Framework-MobSF | CWE-918 | MobSF: SSRF port restriction bypass in assetlinks_check |
| CVE-2026-70893 | 8.2 | 17.4 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-70964 | 8.2 | 17.4 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | CWE-284 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70993 | 8.2 | 17.5 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-60969 | 7.7 | 17.5 | Oracle Corporation | Oracle Unified Directory | CWE-200 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60909 | 7.6 | 17.4 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-61227 | 7.6 | 17.4 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-73928 | 7.2 | 17.4 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-70972 | 6.8 | 17.4 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | CWE-284 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-60682 | 6.5 | 17.4 | Oracle Corporation | Oracle Hyperion Financial Reporting | CWE-306 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-60866 | 6.5 | 17.4 | Oracle Corporation | Service Delivery Platform | CWE-284 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-73893 | 6.5 | 17.4 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73897 | 6.5 | 17.4 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-30250 | 6.1 | 17.4 | n/a | n/a | CWE-79 | Cross-site scripting vulnerability in the user documentation field in Beta Sy… |
| CVE-2026-73909 | 5.9 | 17.4 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-74971 | 4.3 | 17.4 | Mozilla | Firefox | CWE-200 | Information disclosure in the DOM: UI Events & Focus Handling component |
| CVE-2026-74972 | 4.3 | 17.4 | Mozilla | Firefox | CWE-200 | Information disclosure in the DOM: Push Subscriptions component |
| CVE-2026-75626 | 9.3 | 17.4 | smicallef | spiderfoot | CWE-79 | SpiderFoot Stored Cross-Site Scripting via Correlation Titles |
| CVE-2026-71122 | 8.0 | 17.3 | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | CWE-284 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-70888 | 6.6 | 17.3 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-71002 | 8.5 | 17.2 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71574 | 8.5 | 17.2 | Joomla! Project | Joomla! CMS | CWE-284 | Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice e… |
| CVE-2026-66634 | 4.3 | 17.2 | Pantherius | Modal Survey | CWE-639 | WordPress Modal Survey plugin <= 2.0.2.2.3 - Insecure Direct Object Reference… |
| CVE-2026-62618 | 9.3 | 17.1 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-70852 | 8.2 | 17.1 | Oracle Corporation | Oracle Demand Planning | CWE-284 | Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (c… |
| CVE-2026-62533 | 3.7 | 17.1 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-70848 | 3.7 | 17.1 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70670 | 9.6 | 17.0 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-70699 | 7.4 | 17.0 | Oracle Corporation | Oracle Payments | — | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (comp… |
| CVE-2026-71162 | 6.5 | 17.0 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-62532 | 3.8 | 17.0 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-74954 | 7.5 | 16.9 | Mozilla | Firefox | CWE-203 | Information disclosure due to side-channel in the Storage: Cache API component |
| CVE-2026-32473 | 7.2 | 16.7 | DeKnows | PDF Smart Viewer for Elementor | CWE-918 | WordPress PDF Smart Viewer for Elementor plugin <= 1.0.4 - Server Side Reques… |
| CVE-2026-71032 | 7.2 | 16.7 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-73875 | 7.2 | 16.7 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73876 | 7.2 | 16.7 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-61198 | 6.5 | 16.7 | Oracle Corporation | Oracle Learning Management | CWE-284 | Vulnerability in the Oracle Learning Management product of Oracle E-Business … |
| CVE-2026-73868 | 6.5 | 16.7 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73356 | 8.2 | 16.5 | Cloudways | Breeze | CWE-862 | WordPress Breeze plugin <= 2.5.12 - Arbitrary Content Deletion vulnerability |
| CVE-2026-61281 | 8.1 | 16.6 | Oracle Corporation | Oracle Hyperion Calculation Manager | CWE-284 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-62499 | 6.1 | 16.4 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62526 | 3.3 | 16.5 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | CWE-284 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70851 | 3.1 | 16.4 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-74961 | 9.1 | 16.3 | Mozilla | Firefox | CWE-203 | Side-channel in the Web Audio component |
| CVE-2026-67262 | 8.1 | 16.4 | Dell | PowerStore 500T | CWE-862 | Dell PowerStore contains a Missing Authorization vulnerability. An attacker w… |
| CVE-2026-55106 | 5.3 | 16.3 | goauthentik | authentik | CWE-862 | authentik: Unauthenticated LDAP directory data disclosure |
| CVE-2026-75831 | 5.1 | 16.4 | getgrav | grav | CWE-79 | Grav before 2.0.15 Stored XSS via audio/video source URL |
| CVE-2026-62441 | 5.4 | 16.2 | Oracle Corporation | Oracle Hyperion Calculation Manager | CWE-284 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-62446 | 5.3 | 16.2 | Oracle Corporation | Oracle Hyperion Calculation Manager | CWE-284 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-71088 | 4.8 | 16.2 | Oracle Corporation | Oracle Agile PLM MCAD Connector | CWE-284 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply… |
| CVE-2026-45121 | 4.3 | 16.2 | mybb | mybb | CWE-863 | MyBB: Insufficient permission check for calendar select |
| CVE-2026-70867 | 7.1 | 16.1 | Oracle Corporation | Oracle Application Testing Suite | CWE-284 | Vulnerability in Oracle Application Testing Suite. The supported version that… |
| CVE-2026-71103 | 6.3 | 16.1 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-19608 | 5.3 | 16.1 | Red Hat | Red Hat Build of Keycloak | CWE-285 | Keycloak-services: keycloak-services: name-only group claims let same-name gr… |
| CVE-2026-75876 | 2.1 | 16.1 | xianrendzw | EasyReport | CWE-74 | xianrendzw EasyReport Move Operations ModuleController.java sql injection |
| CVE-2026-60733 | 7.7 | 16.0 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-75846 | 7.1 | 16.0 | ArcadeData | arcadedb | CWE-862 | ArcadeDB before 26.8.1 Unauthorized Function Deletion via DELETE FUNCTION |
| CVE-2026-68568 | 6.3 | 16.0 | Stylemix | MasterStudy LMS | CWE-266 | WordPress MasterStudy LMS plugin <= 3.7.41 - Privilege Escalation vulnerability |
| CVE-2026-70775 | 6.3 | 16.0 | Oracle Corporation | Oracle Installed Base | CWE-284 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite… |
| CVE-2026-71062 | 8.5 | 15.8 | Oracle Corporation | Oracle Database Server | CWE-284 | Vulnerability in the RDBMS component of Oracle Database Server. Supported ver… |
| CVE-2026-61177 | 8.1 | 15.8 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-61199 | 7.7 | 15.8 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-70945 | 7.7 | 15.8 | Oracle Corporation | Oracle Payroll | CWE-284 | Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (compo… |
| CVE-2026-32553 | 7.2 | 15.8 | Brainstorm Force | OttoKit | CWE-918 | WordPress OttoKit plugin <= 1.1.35 - Server Side Request Forgery (SSRF) vulne… |
| CVE-2026-73367 | 7.2 | 15.9 | supsystic | Easy Google Maps | CWE-829 | WordPress Easy Google Maps plugin < 1.14.2 - Remote File Inclusion vulnerability |
| CVE-2026-12632 | 6.5 | 15.8 | zephyrproject | zephyr | CWE-125 | Out-of-bounds read in Zephyr PTP message parsing from unvalidated message type |
| CVE-2026-70969 | 6.5 | 15.8 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-71001 | 6.5 | 15.8 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-73352 | 6.5 | 15.8 | Nexcess | GiveWP | CWE-862 | WordPress GiveWP plugin <= 4.16.5.1 - Broken Access Control vulnerability |
| CVE-2026-66622 | 7.5 | 15.8 | averta | Depicter Slider | CWE-89 | WordPress Depicter Slider plugin <= 4.8.0 - SQL Injection vulnerability |
| CVE-2026-70960 | 7.6 | 15.6 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-71027 | 7.6 | 15.6 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71023 | 7.5 | 15.6 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-54570 | 6.9 | 15.7 | AngleSharp | AngleSharp | CWE-80 | AngleSharp: HTML5 Spec Compliance: mXSS via annotation-xml HTML Integration P… |
| CVE-2026-50139 | 5.9 | 15.6 | patrickhener | goshs | CWE-362 | goshs: Share-link ?token=… redemption races past download limit |
| CVE-2026-45122 | 4.3 | 15.7 | mybb | mybb | CWE-863 | MyBB: Insufficient permission check for calendar event move |
| CVE-2026-45124 | 4.3 | 15.7 | mybb | mybb | CWE-862 | MyBB: Mod CP report resolution missing authorization |
| CVE-2026-73426 | 4.6 | 15.5 | basecamp | trix | CWE-79 | Trix: Stored XSS vulnerability through serialized attributes |
| CVE-2024-14045 | 2.1 | 15.4 | n/a | OpenBoxes | CWE-266 | OpenBoxes Product Supplier Edit Controller RoleInterceptor.groovy improper au… |
| CVE-2024-14046 | 2.1 | 15.4 | n/a | OpenBoxes | CWE-284 | OpenBoxes Document Upload Controller DocumentController.groovy DocumentContro… |
| CVE-2026-70998 | 9.3 | 15.3 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71065 | 9.3 | 15.3 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-74947 | 8.8 | 15.4 | Mozilla | Firefox | CWE-763 | Privilege escalation due to invalid pointer in the Graphics component |
| CVE-2026-71130 | 8.2 | 15.4 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-71159 | 8.2 | 15.3 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-74978 | 8.1 | 15.3 | Mozilla | Firefox | CWE-1021 | Clickjacking issue in the Widget component |
| CVE-2026-61193 | 8.7 | 15.2 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-70900 | 8.7 | 15.2 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-70898 | 7.4 | 15.2 | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-284 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-71029 | 6.8 | 15.2 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-16309 | 5.3 | 15.2 | Netiket Information Technologies | EdoWEB | CWE-639 | IDOR in Netiket Information Technologies' EdoWEB |
| CVE-2026-74003 | 4.3 | 15.3 | rometheme | RomethemeForm For Elementor | CWE-862 | WordPress RomethemeForm For Elementor plugin <= 1.2.6 - Broken Access Control… |
| CVE-2026-70681 | 7.5 | 15.1 | Oracle Corporation | Oracle Applications DBA | — | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Sui… |
| CVE-2026-62627 | 7.1 | 15.1 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-70760 | 7.1 | 15.1 | Oracle Corporation | Oracle Order Management | — | Vulnerability in the Oracle Order Management product of Oracle E-Business Sui… |
| CVE-2026-15315 | 8.7 | 15.0 | TP-Link Systems Inc. | Tapo C200 v5 | CWE-287 | Unauthenticated Administrative Authentication Bypass via device_confirm Repla… |