A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
Edition of August 18, 2026, continued — page 3 of 3. Back to page 1 · page 2
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-70768 | 6.1 | 15.1 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70961 | 6.1 | 15.1 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-71019 | 6.1 | 15.1 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-73898 | 6.1 | 15.1 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-70759 | 5.4 | 15.1 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70766 | 5.4 | 15.1 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-71123 | 5.4 | 15.1 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-32547 | 7.1 | 14.9 | wordplus | BP Better Messages | CWE-79 | WordPress BP Better Messages plugin <= 2.15.22 - Cross Site Scripting (XSS) v… |
| CVE-2026-66621 | 7.1 | 14.9 | Ultimate Dashboad | Ultimate Dashboard | CWE-79 | WordPress Ultimate Dashboard plugin <= 3.11.2 - Cross Site Scripting (XSS) vu… |
| CVE-2026-66629 | 7.1 | 14.9 | Themeum | Kirki | CWE-79 | WordPress Kirki plugin <= 6.2.3 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-68567 | 7.1 | 14.9 | WP Grids | Convert Pro | CWE-79 | WordPress Convert Pro plugin <= 1.0.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-73338 | 7.1 | 14.9 | Autopay | Autopay | CWE-79 | WordPress Autopay plugin <= 5.0.0 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-73342 | 7.1 | 14.9 | Magazine3 | WP Multilang | CWE-79 | WordPress WP Multilang plugin <= 2.4.31 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-73358 | 7.1 | 14.9 | wp.insider | Affiliates Manager | CWE-79 | WordPress Affiliates Manager plugin <= 2.9.53 - Cross Site Scripting (XSS) vu… |
| CVE-2026-73360 | 7.1 | 14.9 | Premio | Chaty Pro | CWE-79 | WordPress Chaty Pro plugin <= 3.5.8 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-73362 | 7.1 | 14.9 | KaizenCoders | URL Shortify | CWE-79 | WordPress URL Shortify plugin <= 2.5.0 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-73378 | 7.1 | 14.9 | supsystic | Contact Form by Supsystic | CWE-79 | WordPress Contact Form by Supsystic plugin < 1.10.0 - Cross Site Scripting (X… |
| CVE-2026-73382 | 7.1 | 14.9 | Gemini Labs | Site Reviews | CWE-79 | WordPress Site Reviews plugin <= 8.2.0 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-73393 | 7.1 | 14.9 | weDevs | Subscribe2 | CWE-79 | WordPress Subscribe2 plugin <= 10.46 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-66780 | 9.9 | 14.8 | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | CWE-284 | Submariner-operator: submariner-operator: flat broker trust model grants ever… |
| CVE-2026-48508 | 8.8 | 14.9 | Netflix | lemur | CWE-863 | Lemur: Authorization bypass in StrictRolePermission / AuthorityCreatorPermission |
| CVE-2026-71096 | 8.2 | 14.8 | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | CWE-284 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-62529 | 3.5 | 14.7 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-28192 | 9.6 | 14.5 | Piotnet | Piotnet Addons For Elementor Pro | CWE-434 | WordPress Piotnet Addons For Elementor Pro plugin <= 7.1.67 - Arbitrary File … |
| CVE-2026-67262 | 8.1 | 14.5 | Dell | PowerStore 500T | CWE-862 | Dell PowerStore contains a Missing Authorization vulnerability. An attacker w… |
| CVE-2026-70858 | 7.1 | 14.6 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-55164 | 4.9 | 14.6 | Netflix | lemur | CWE-256 | Lemur: Plaintext password storage in Lemur user-update path |
| CVE-2026-71307 | 7.7 | 14.5 | Netflix | lemur | CWE-862 | Lemur: Authenticated low-privilege users can read plaintext destination crede… |
| CVE-2026-75844 | 7.1 | 14.4 | ArcadeData | arcadedb | CWE-918 | ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypass |
| CVE-2026-55593 | 6.5 | 14.3 | froxlor | froxlor | CWE-352 | Froxlor: CSRF Vulnerability in Froxlor AJAX Endpoint — Missing Cross-Site Req… |
| CVE-2026-74952 | 8.8 | 14.3 | Mozilla | Firefox | CWE-269 | Privilege escalation in the Application Update component |
| CVE-2026-73891 | 7.3 | 14.2 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73933 | 7.3 | 14.2 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-71155 | 8.5 | 14.1 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-61696 | 6.3 | 14.1 | forem | forem | CWE-74 | Forem: Stored XSS in Admin Abuse Report Rendering |
| CVE-2026-62606 | 3.1 | 14.1 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-71108 | 5.3 | 14.0 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-62520 | 4.8 | 14.0 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2021-43717 | await | 13.9 | n/a | n/a | — | An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identi… |
| CVE-2026-62448 | 8.2 | 13.8 | Oracle Corporation | Oracle Email Center | — | Vulnerability in the Oracle Email Center product of Oracle E-Business Suite (… |
| CVE-2026-62605 | 8.2 | 13.8 | Oracle Corporation | Oracle Partner Management | — | Vulnerability in the Oracle Partner Management product of Oracle E-Business S… |
| CVE-2026-71016 | 8.2 | 13.8 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-62603 | 5.4 | 13.8 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-70843 | 6.8 | 13.7 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70853 | 3.3 | 13.7 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-62459 | 7.2 | 13.6 | Oracle Corporation | Oracle Hyperion Calculation Manager | CWE-284 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-71156 | 5.3 | 13.6 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-62613 | 9.3 | 13.5 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62637 | 9.3 | 13.5 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-75835 | 9.3 | 13.3 | getgrav | grav | CWE-862 | Grav API Plugin before 1.0.14 Missing Authorization |
| CVE-2026-74950 | 8.8 | 13.3 | Mozilla | Firefox | CWE-269 | Privilege escalation in the Downloads API component |
| CVE-2026-74955 | 8.8 | 13.3 | Mozilla | Firefox | CWE-269 | Privilege escalation in the Request Handling component |
| CVE-2026-52606 | 6.1 | 13.3 | n/a | n/a | CWE-79 | A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.… |
| CVE-2026-52609 | 6.1 | 13.3 | n/a | n/a | CWE-79 | A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.… |
| CVE-2026-45120 | 5.4 | 13.2 | mybb | mybb | CWE-639 | MyBB: Insufficient authorization for private calendar events |
| CVE-2026-75839 | 5.3 | 13.2 | ArcadeData | arcadedb | CWE-200 | ArcadeDB before 26.8.1 Information Disclosure via Cluster Endpoints |
| CVE-2026-75832 | 9.3 | 13.0 | getgrav | grav | CWE-862 | Grav API Plugin before 1.0.14 Authorization Bypass |
| CVE-2026-52723 | 9.1 | 12.8 | fbeta-GmbH | ePA3-Service-OpenSource | CWE-295 | ePA 3.x Integration: VAU Server Authentication Bypass via Circular Certificat… |
| CVE-2026-74004 | 5.4 | 12.9 | wpmonks | Gravity Booster – Styles & Layouts for Gravity Forms | CWE-862 | WordPress Gravity Booster – Styles & Layouts for Gravity Forms plug… |
| CVE-2026-71118 | 4.8 | 12.7 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-62576 | 6.5 | 12.6 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-55166 | 9.9 | 12.4 | Netflix | lemur | CWE-285 | Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent P… |
| CVE-2026-62602 | 8.0 | 12.1 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-62545 | 7.5 | 12.2 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70691 | 7.5 | 12.2 | Oracle Corporation | Oracle Agile Engineering Data Management | — | Vulnerability in the Oracle Agile Engineering Data Management product of Orac… |
| CVE-2026-70955 | 7.5 | 12.2 | Oracle Corporation | Oracle Commerce Platform | — | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com… |
| CVE-2026-73973 | 5.5 | 12.2 | Linuxfabrik | monitoring-plugins | CWE-22 | Linuxfabrik Monitoring Plugins: Arbitrary root file disclosure via unconfined… |
| CVE-2026-76037 | 8.4 | 11.8 | Chrome | CWE-59 | Link following in CredentialProvider in Google Chrome on on Windows prior to … | |
| CVE-2026-71303 | 7.7 | 11.7 | Netflix | lemur | CWE-918 | Lemur: Incomplete fix for CVE-2026-55166 -- ACME authority update endpoint al… |
| CVE-2026-66636 | 6.5 | 11.7 | Marcin | Wise Chat | CWE-79 | WordPress Wise Chat plugin <= 3.4 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-66638 | 6.5 | 11.7 | Shabti Kaplan | Frontend Admin by DynamiApps | CWE-79 | WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Cross Site Scripti… |
| CVE-2026-66639 | 6.5 | 11.7 | WPZOOM | WPZOOM Forms – Contact Form Plugin for Gutenberg | CWE-79 | WordPress WPZOOM Forms – Contact Form plugin for Gutenberg plugin <= 2.0.4 - … |
| CVE-2026-66640 | 6.5 | 11.7 | Marcus (aka @msykes) | Login With Ajax | CWE-79 | WordPress Login With Ajax plugin <= 4.5.1 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-66643 | 6.5 | 11.7 | wronganswersonly | Wufoo Shortcode | CWE-79 | WordPress Wufoo Shortcode plugin <= 1.55 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-66645 | 6.5 | 11.7 | WPDeveloper | Table Of Contents Block | CWE-79 | WordPress Table Of Contents Block plugin <= 1.5.0 - Cross Site Scripting (XSS… |
| CVE-2026-66646 | 6.5 | 11.7 | MyThemeShop | WP Tab Widget | CWE-79 | WordPress WP Tab Widget plugin <= 1.2.11 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-73359 | 6.5 | 11.7 | WP Legal Pages | WP Cookie Notice for GDPR, CCPA & ePrivacy Consent | CWE-79 | WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.3.9 … |
| CVE-2026-71147 | 4.2 | 11.6 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-73379 | 6.5 | 11.6 | supsystic | Contact Form by Supsystic | CWE-288 | WordPress Contact Form by Supsystic plugin < 1.10.0 - Bypass Vulnerability vu… |
| CVE-2026-74903 | 5.3 | 11.5 | siyuan-note | siyuan | CWE-400 | SiYuan before v3.7.4 Insufficient Access Control via spinBlockDOM |
| CVE-2026-75845 | 5.3 | 11.4 | ArcadeData | arcadedb | CWE-269 | ArcadeDB 26.4.2 before 26.8.1 Authorization Bypass via set_server_setting |
| CVE-2025-11729 | 4.3 | 11.3 | buildwps | PPWP – Password Protect Pages | CWE-285 | PPWP: Password Protect Pages, Posts & Full or Partial Content <= 1.9.15 - Imp… |
| CVE-2026-24185 | 7.1 | 11.3 | NVIDIA | NVOS | CWE-288 | NVIDIA NVOS for network switches contains a vulnerability in the secure shell… |
| CVE-2026-70682 | 3.7 | 11.3 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-70785 | 3.7 | 11.3 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-15371 | 8.1 | 11.2 | Rapid7 | Velociraptor | CWE-177 | Velociraptor Stored XSS in URL column types |
| CVE-2026-67846 | await | 11.1 | n/a | n/a | — | Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d65119… |
| CVE-2026-71539 | 8.9 | 11.0 | n8n-io | n8n | CWE-367 | n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve R… |
| CVE-2026-70674 | 8.8 | 11.0 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-61139 | 6.3 | 11.0 | Oracle Corporation | Oracle Public Sector Financials (International) | CWE-284 | Vulnerability in the Oracle Public Sector Financials (International) product … |
| CVE-2026-71030 | 7.2 | 10.8 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-73892 | 6.5 | 10.8 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73904 | 6.5 | 10.8 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-12520 | 6.4 | 10.8 | zephyrproject | zephyr | CWE-787 | Stack buffer overflow and off-by-one writes in Zephyr HL7800 modem AT respons… |
| CVE-2026-63640 | 4.3 | 10.8 | MagicMirrorOrg | MagicMirror | CWE-200 | MagicMirror socket payload secret placeholder expansion can disclose SECRET_*… |
| CVE-2026-61296 | 7.6 | 10.7 | Oracle Corporation | Oracle Enterprise Asset Management | — | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-B… |
| CVE-2026-70678 | 7.6 | 10.7 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-71020 | 7.6 | 10.7 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71021 | 7.6 | 10.7 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71022 | 7.6 | 10.7 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-62522 | 7.1 | 10.7 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-75088 | 2.1 | 10.8 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System viewbilling.php sql injection |
| CVE-2026-52737 | 5.3 | 10.6 | ZcashFoundation | zebra | CWE-345 | ZEBRA: Sync restart poisoning from single unauthenticated peer via above-look… |
| CVE-2026-71071 | 4.6 | 10.6 | Oracle Corporation | Oracle Agile PLM MCAD Connector | — | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply… |
| CVE-2021-43716 | await | 10.6 | n/a | n/a | — | Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Net… |
| CVE-2026-75625 | 9.1 | 10.2 | uber | kraken | CWE-354 | Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification B… |
| CVE-2026-75086 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System viewroom.php sql injection |
| CVE-2026-75087 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System viewdepartment.php sql injection |
| CVE-2026-23933 | 7.7 | 10.1 | Zabbix | Zabbix | CWE-259 | Hardcoded session key in Zabbix 7.4 |
| CVE-2026-74943 | await | 10.1 | Mozilla | Firefox | — | Use-after-free in the Graphics: ImageLib component |
| CVE-2026-74945 | await | 10.1 | Mozilla | Firefox | — | Information disclosure in the Graphics: Text component |
| CVE-2026-73923 | 3.7 | 9.9 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-55426 | 7.8 | 9.9 | Linuxfabrik | monitoring-plugins | CWE-78 | linuxfabrik-lib: Local privilege escalation using embedded command |
| CVE-2026-32467 | 6.0 | 9.8 | apoyl | [Aotuman] Grab WeChat Articles | CWE-918 | WordPress [Aotuman] Grab WeChat Articles plugin <= 2.0.1 - Server Side Reques… |
| CVE-2026-75032 | 6.3 | 9.7 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media… |
| CVE-2026-70963 | 4.2 | 9.7 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-73873 | 4.2 | 9.7 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-62461 | 3.1 | 9.6 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-75833 | 8.6 | 9.5 | getgrav | grav | CWE-601 | Grav API Plugin Open Redirect via Backslash Bypass |
| CVE-2026-75091 | 7.2 | 9.5 | mdmag | Quill Forms | Conversational Multi Step Forms, Surveys & quizzes | CWE-79 | Quill Forms <= 5.7.1 - Unauthenticated Stored Cross-Site Scripting |
| CVE-2026-66651 | 6.5 | 9.5 | MultiVendorX | MultiVendorX | CWE-862 | WordPress MultiVendorX plugin <= 5.0.14 - Broken Access Control vulnerability |
| CVE-2026-73348 | 6.5 | 9.5 | Nexcess | GiveWP | CWE-862 | WordPress GiveWP plugin < 4.16.6 - Broken Access Control vulnerability |
| CVE-2026-17106 | 7.1 | 9.3 | moby | go-archive | CWE-59 | Tar extraction in moby/go-archive can write outside the destination directory… |
| CVE-2026-68923 | 6.5 | 9.3 | MobSF | Mobile-Security-Framework-MobSF | CWE-352 | MobSF: CSRF checks not enforced after Django migration |
| CVE-2026-70789 | 5.9 | 9.4 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70776 | 2.6 | 9.4 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70717 | 7.7 | 9.2 | Oracle Corporation | Oracle Autonomous Health Framework | — | Vulnerability in Oracle Autonomous Health Framework (component: Cluster Healt… |
| CVE-2026-70780 | 6.8 | 9.3 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70923 | 6.1 | 9.3 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-62604 | 3.1 | 9.3 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-53456 | 5.6 | 8.9 | ha-china | blueprint-studio | CWE-522 | Blueprint Studio terminal SSH private key written to disk |
| CVE-2026-15316 | 7.1 | 8.7 | TP-Link Systems Inc. | Tapo C200 v5 | CWE-20 | Denial-of-Service via Oversized Encrypted Credential Input in TP-Link Tapo C200 |
| CVE-2026-52817 | 7.0 | 8.7 | Linuxfabrik | monitoring-plugins | CWE-88 | Linuxfabrik Monitoring Plugins Sudoers: /usr/bin/apt-get arguments allow priv… |
| CVE-2026-74973 | 4.2 | 8.7 | Mozilla | Firefox | CWE-362 | Race condition, use-after-free in the Graphics component |
| CVE-2026-50578 | 7.5 | 8.5 | fbeta-GmbH | ePA3-Service-OpenSource | CWE-295 | ePA 3.x Integration: TLS Certificate Verification Universally Disabled |
| CVE-2026-74006 | 4.3 | 8.4 | WP Table Builder | WP Table Builder | CWE-862 | WordPress WP Table Builder plugin <= 2.2.0 - Broken Access Control vulnerability |
| CVE-2026-74987 | 9.8 | 8.4 | Mozilla | Firefox | CWE-119 | Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 … |
| CVE-2026-71676 | 7.5 | 8.3 | n/a | n/a | CWE-122 | Buffer Overflow vulnerability in Open5GS v.2.7.0 allows a remote attacker to … |
| CVE-2026-53759 | 2.0 | 8.3 | Linuxfabrik | monitoring-plugins | CWE-377 | linuxfabrik-lib: Insecure creation of SQLite databases |
| CVE-2026-73874 | 5.4 | 8.2 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73911 | 5.4 | 8.2 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-60961 | 8.0 | 8.1 | Oracle Corporation | Oracle WebCenter Content | — | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-62578 | 6.5 | 8.1 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-63336 | 5.1 | 8.1 | rabbitmq | rabbitmq-java-client | CWE-295 | RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslPr… |
| CVE-2026-74908 | 5.1 | 8.1 | getgrav | grav | CWE-79 | Grav plugin-api before 1.0.15 Script Injection via SVG |
| CVE-2026-75834 | 5.1 | 8.1 | getgrav | grav | CWE-79 | Grav before 2.0.14 Stored XSS via Invalid UTF-8 Byte |
| CVE-2026-52481 | 7.5 | 8.0 | n/a | n/a | CWE-200 | An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote att… |
| CVE-2026-71675 | 7.5 | 8.0 | n/a | n/a | CWE-401 | An issue in Open5GS v.2.7.0 allows a remote attacker to cause a denial of ser… |
| CVE-2026-71004 | 6.1 | 8.0 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71005 | 6.1 | 8.0 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71006 | 6.1 | 8.0 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71011 | 6.1 | 8.0 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71025 | 6.1 | 8.0 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71031 | 6.1 | 8.0 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-73869 | 6.1 | 8.0 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73870 | 6.1 | 8.0 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-52480 | await | 8.0 | n/a | n/a | — | An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote att… |
| CVE-2026-28568 | 7.1 | 7.8 | Mohamed Magdy | Quill Forms | CWE-79 | WordPress Quill Forms plugin <= 5.7.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-28569 | 7.1 | 7.9 | SSL Zen | SSL Zen | CWE-79 | WordPress SSL Zen plugin <= 4.7.43 - Reflected Cross Site Scripting (XSS) vul… |
| CVE-2026-32333 | 7.1 | 7.9 | TeconceTheme | Mayosis Core | CWE-79 | WordPress Mayosis Core plugin <= 5.4.7 - Reflected Cross Site Scripting (XSS)… |
| CVE-2026-66633 | 7.1 | 7.8 | WPManageNinja | Fluent Forms Pro Add On Pack | CWE-79 | WordPress Fluent Forms Pro Add On Pack plugin < 6.2.12 - Cross Site Scripting… |
| CVE-2026-66667 | 7.1 | 7.9 | WPDeveloper | Templately | CWE-79 | WordPress Templately plugin <= 3.7.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-73190 | 7.1 | 7.9 | Shahjada | WPDM – Premium Packages | CWE-79 | WordPress WPDM – Premium Packages plugin <= 7.0.5 - Cross Site Scripting (XSS… |
| CVE-2026-73351 | 7.1 | 7.8 | miniOrange | WordPress Social Login and Register | CWE-79 | WordPress WordPress Social Login and Register plugin <= 7.8.1 - Cross Site Sc… |
| CVE-2026-73361 | 7.1 | 7.8 | WPZOOM | Recipe Card Blocks for Gutenberg & Elementor | CWE-79 | WordPress Recipe Card Blocks for Gutenberg & Elementor plugin <= 3.4.18 - Cro… |
| CVE-2026-73375 | 7.1 | 7.9 | supsystic | Ultimate Maps by Supsystic | CWE-79 | WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - Cross Site Scripting (X… |
| CVE-2026-71077 | 5.3 | 7.9 | Oracle Corporation | Oracle Agile PLM MCAD Connector | CWE-284 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply… |
| CVE-2026-71308 | 8.1 | 7.7 | Netflix | lemur | CWE-639 | Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack … |
| CVE-2026-71322 | 4.3 | 7.7 | Netflix | lemur | CWE-862 | Lemur: Missing authorization check on POST /certificates/<id>/export for plug… |
| CVE-2026-70709 | 4.8 | 7.6 | Oracle Corporation | Oracle Agile Engineering Data Management | — | Vulnerability in the Oracle Agile Engineering Data Management product of Orac… |
| CVE-2026-73901 | 4.8 | 7.6 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-71075 | 5.9 | 7.5 | Oracle Corporation | Oracle Agile PLM MCAD Connector | CWE-284 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply… |
| CVE-2026-75911 | 8.5 | 7.2 | Hmbown | CodeWhale | CWE-94 | CodeWhale before 0.8.64 Remote Code Execution via allow_shell |
| CVE-2026-23935 | 6.8 | 7.2 | Zabbix | Zabbix | CWE-125 | Use-after-free read in script item/preprocessing HttpRequest body |
| CVE-2026-19670 | 5.3 | 7.2 | CISAgov | Malcolm | CWE-863 | Incorrect Authorization in CISA Malcolm |
| CVE-2026-60884 | 4.4 | 7.1 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | — | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-71145 | 4.4 | 7.1 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-50575 | 7.7 | 6.9 | UNITRONIX | BetterDesk | CWE-294 | BetterDesk has a replay behavior vulnerability when devices are deleted |
| CVE-2026-74975 | 5.4 | 6.9 | Mozilla | Firefox | CWE-451 | Spoofing issue in the Downloads component in Firefox for Android |
| CVE-2026-23930 | 5.3 | 6.9 | Zabbix | Zabbix | CWE-405 | Frontend DoS via the popup.testtriggerexpr action |
| CVE-2026-74983 | 8.1 | 6.9 | Mozilla | Firefox | CWE-693 | Mitigation bypass in the Data Loss Prevention component |
| CVE-2026-60993 | 7.5 | 6.9 | Oracle Corporation | Oracle Identity Manager Connector | — | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-54552 | 7.9 | 6.8 | amoffat | sh | CWE-273 | sh _uid does not drop supplementary groups (incomplete privilege drop) |
| CVE-2026-74951 | 6.5 | 6.8 | Mozilla | Firefox | CWE-1021 | Clickjacking issue in Firefox for Android |
| CVE-2026-74970 | 5.4 | 6.6 | Mozilla | Firefox | CWE-346 | Site isolation issue in the Graphics component |
| CVE-2026-23934 | 5.1 | 6.6 | Zabbix | Zabbix | CWE-405 | Frontend DoS via the validate.api.exists action |
| CVE-2026-75107 | 5.1 | 6.6 | getgrav | grav | CWE-79 | Grav Form Plugin before 9.1.19 Stored XSS via Field Properties |
| CVE-2026-63632 | 3.3 | 6.3 | onnx | onnx | CWE-125 | ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersi… |
| CVE-2026-68939 | 2.0 | 6.3 | pyenv | pyenv | CWE-78 | Pyenv: Glob/wildcard metacharacters bypass is_version_safe(), causing silent … |
| CVE-2026-70666 | 7.4 | 6.2 | Netflix | lemur | CWE-918 | Lemur: Server-Side Request Forgery via the ACME client following server-contr… |
| CVE-2026-55162 | 6.3 | 6.2 | Netflix | lemur | CWE-918 | Lemur: Post-authentication SSRF via certificate verification - attacker-contr… |
| CVE-2026-55163 | 6.3 | 6.2 | Netflix | lemur | CWE-863 | Lemur: Privilege escalation via PUT /api/1/roles/<id> — non-admin role member… |
| CVE-2026-70793 | 4.2 | 6.3 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-66635 | 7.4 | 6.1 | 10Web | Slider by 10Web | CWE-352 | WordPress Slider by 10Web plugin <= 1.2.62 - CSRF to Arbitrary File Deletion … |
| CVE-2026-74957 | await | 6.1 | Mozilla | Firefox | — | Mitigation bypass in the Safe Browsing component |
| CVE-2026-74959 | await | 6.1 | Mozilla | Firefox | — | Mitigation bypass in the Storage: Cache API component |
| CVE-2026-74976 | 6.5 | 6.0 | Mozilla | Firefox | CWE-843 | JIT miscompilation in the JavaScript Engine: JIT component |
| CVE-2026-62454 | 7.8 | 5.9 | Oracle Corporation | Siebel CRM Cloud Applications | — | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-71551 | 7.8 | 5.9 | super-productivity | super-productivity | CWE-78 | Super Productivity: Arbitrary OS Command Execution via IPC EXEC Handler with … |
| CVE-2026-70894 | 7.7 | 5.9 | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-61295 | 7.1 | 5.9 | Oracle Corporation | Oracle WebCenter Content | — | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-19447 | 5.4 | 5.9 | Fileorbis Informatics Services Trade Inc. | FileOrbis | CWE-79 | Stored XSS in Fileorbis Informatics's FileOrbis |
| CVE-2026-62291 | 5.3 | 5.9 | strukturag | libheif | CWE-125 | libheif: Heap out of bounds write in libheif uncompressed encoder when writin… |
| CVE-2026-66591 | 6.5 | 5.8 | David Lingren | Media LIbrary Assistant | CWE-79 | WordPress Media LIbrary Assistant plugin <= 3.39 - Cross Site Scripting (XSS)… |
| CVE-2026-66603 | 6.5 | 5.8 | David Artiss | Draft List | CWE-79 | WordPress Draft List plugin <= 2.6.4 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-66637 | 6.5 | 5.8 | Alex | Featured Video Plus | CWE-79 | WordPress Featured Video Plus plugin <= 2.3.3 - Cross Site Scripting (XSS) vu… |
| CVE-2026-66641 | 6.5 | 5.8 | Deepen Bajracharya | Video Conferencing with Zoom | CWE-79 | WordPress Video Conferencing with Zoom plugin <= 4.6.8 - Cross Site Scripting… |
| CVE-2026-66644 | 6.5 | 5.8 | 93digital | Typing Effect | CWE-79 | WordPress Typing Effect plugin <= 1.3.7 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-68565 | 6.5 | 5.8 | Paolo | GeoDirectory | CWE-79 | WordPress GeoDirectory plugin <= 2.8.172 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-74969 | 8.8 | 5.7 | Mozilla | Firefox | CWE-416 | Use-after-free in the Layout: Text and Fonts component |
| CVE-2026-70840 | 8.4 | 5.7 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70842 | 8.4 | 5.7 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70719 | 4.0 | 5.7 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-70917 | 4.0 | 5.7 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-75850 | 2.3 | 5.7 | ArcadeData | arcadedb | CWE-862 | ArcadeDB before 26.8.1 Per-Type ACL Bypass via Batch Handlers |
| CVE-2026-74934 | await | 5.7 | Mozilla | Firefox | — | Site isolation issue in the Graphics: CanvasWebGL component |
| CVE-2026-74940 | await | 5.7 | Mozilla | Firefox | — | Use-after-free in the Graphics: Text component |
| CVE-2026-74948 | await | 5.7 | Mozilla | Firefox | — | Information disclosure in the Graphics component |
| CVE-2026-75924 | 8.7 | 5.6 | Red Hat | Multicluster Engine for Kubernetes | CWE-269 | Managed-serviceaccount: managed-serviceaccount: hub addon-manager clusterrole… |
| CVE-2026-71131 | 8.6 | 5.6 | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-60392 | 7.8 | 5.6 | Oracle Corporation | Oracle Outside In Technology | CWE-502 | Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Mi… |
| CVE-2026-60412 | 7.8 | 5.6 | Oracle Corporation | Oracle Outside In Technology | — | Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Mi… |
| CVE-2026-60413 | 7.8 | 5.6 | Oracle Corporation | Oracle Outside In Technology | — | Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Mi… |
| CVE-2026-60414 | 7.8 | 5.6 | Oracle Corporation | Oracle Outside In Technology | — | Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Mi… |
| CVE-2026-71010 | 7.8 | 5.6 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-70698 | 6.7 | 5.4 | Oracle Corporation | Oracle Agile Engineering Data Management | — | Vulnerability in the Oracle Agile Engineering Data Management product of Orac… |
| CVE-2026-71109 | 6.7 | 5.4 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-74964 | 9.8 | 5.3 | Mozilla | Firefox | CWE-190 | Integer overflow in the Graphics component |
| CVE-2026-74962 | 8.1 | 5.3 | Mozilla | Firefox | CWE-346 | Site isolation issue in the Networking: Cookies component |
| CVE-2026-71084 | 6.8 | 5.3 | Oracle Corporation | MySQL Connectors | CWE-284 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Con… |
| CVE-2026-74936 | await | 5.3 | Mozilla | Firefox | — | Use-after-free in the JavaScript: WebAssembly component |
| CVE-2026-74944 | await | 5.3 | Mozilla | Firefox | — | Use-after-free in the DOM: Core & HTML component |
| CVE-2026-74960 | await | 5.3 | Mozilla | Firefox | — | Site isolation issue in the WebExtensions component |
| CVE-2025-9210 | 8.1 | 5.2 | Otalio | Ship Property Management System | CWE-347 | Missing JSON Web Token signature validation in Otalio Ship Property Managemen… |
| CVE-2026-70991 | 6.3 | 5.2 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-70726 | 6.0 | 5.2 | Oracle Corporation | Oracle Cash Management | — | Vulnerability in the Oracle Cash Management product of Oracle E-Business Suit… |
| CVE-2026-71114 | 6.0 | 5.2 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-71115 | 6.0 | 5.2 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-75151 | 5.3 | 5.2 | SourceCodester | Onlne Examination & Learning Management System | CWE-352 | SourceCodester Onlne Examination & Learning Management System cross-site requ… |
| CVE-2026-73880 | 4.4 | 5.2 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-74988 | await | 5.1 | Mozilla | Firefox | — | Internally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154 |
| CVE-2026-52876 | 8.8 | 5.0 | truelockmc | streambert | CWE-20 | Streambert: Arbitrary File Execution via VLC/mpv Launcher Fallback |
| CVE-2026-61313 | 6.7 | 4.9 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-71080 | 3.7 | 4.9 | Oracle Corporation | Oracle Agile PLM MCAD Connector | CWE-284 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply… |
| CVE-2026-70941 | 8.8 | 4.8 | Oracle Corporation | Oracle Payroll | — | Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (compo… |
| CVE-2026-71051 | 8.8 | 4.8 | Oracle Corporation | Oracle Product Lifecycle Analytics | — | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Sup… |
| CVE-2026-60753 | 7.8 | 4.8 | Oracle Corporation | Siebel CRM Deployment | — | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-60822 | 7.8 | 4.8 | Oracle Corporation | Oracle Enterprise Manager for Systems Infrastructure | — | Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure pro… |
| CVE-2026-60991 | 7.8 | 4.8 | Oracle Corporation | Oracle Identity Manager Connector | — | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-61291 | 7.8 | 4.8 | Oracle Corporation | Oracle WebCenter Content | — | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-70750 | 7.8 | 4.8 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70866 | 7.8 | 4.8 | Oracle Corporation | Oracle Application Testing Suite | — | Vulnerability in Oracle Application Testing Suite. The supported version that… |
| CVE-2026-71028 | 7.8 | 4.8 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71097 | 7.8 | 4.8 | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | CWE-284 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-71111 | 7.8 | 4.8 | Oracle Corporation | Oracle Identity Manager | — | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-63328 | 6.8 | 4.8 | aquasecurity | trivy | CWE-22 | Trivy: Path Traversal in Trivy Plugin Manager Allows Arbitrary File Write |
| CVE-2026-62572 | 6.5 | 4.8 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70847 | 6.5 | 4.8 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70895 | 6.5 | 4.8 | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-74974 | 5.4 | 4.8 | Mozilla | Firefox | CWE-346 | Same-origin policy bypass in the Graphics: ImageLib component |
| CVE-2026-74981 | await | 4.7 | Mozilla | Firefox | — | Site isolation issue in the Audio/Video: Web Codecs component |
| CVE-2026-74982 | await | 4.7 | Mozilla | Firefox | — | Denial-of-service in the Widget component |
| CVE-2026-74984 | await | 4.7 | Mozilla | Firefox | — | Race condition in the JavaScript Engine component |
| CVE-2026-74985 | await | 4.7 | Mozilla | Firefox | — | Privilege escalation in the Enterprise Policies component |
| CVE-2026-74986 | await | 4.7 | Mozilla | Firefox | — | Site isolation issue in the CSS Parsing and Computation component |
| CVE-2026-74989 | await | 4.7 | Mozilla | Firefox | — | Internally found bugs fixed in Thunderbird 154 |
| CVE-2026-60928 | 8.4 | 4.6 | Oracle Corporation | Oracle WebCenter Content | — | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-70734 | 7.4 | 4.7 | Oracle Corporation | Oracle Autonomous Health Framework | — | Vulnerability in Oracle Autonomous Health Framework (component: Trace File An… |
| CVE-2026-62537 | 7.1 | 4.6 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70936 | 7.1 | 4.6 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70967 | 7.1 | 4.6 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | CWE-284 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-73073 | 7.1 | 4.6 | vim | vim | CWE-94 | Vim: Arbitrary Ex Command Execution in C Omni-Completion |
| CVE-2026-71141 | 7.7 | 4.5 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-12631 | 6.5 | 4.6 | zephyrproject | zephyr | CWE-862 | Broken access-control denial in k_thread_join/k_thread_abort syscall validati… |
| CVE-2026-70838 | 6.1 | 4.5 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-74902 | 9.3 | 4.5 | siyuan-note | siyuan | CWE-79 | SiYuan before v3.7.4 XSS-to-RCE via malicious filename upload |
| CVE-2026-71089 | 3.3 | 4.4 | Oracle Corporation | Oracle Agile PLM MCAD Connector | — | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply… |
| CVE-2026-66602 | 8.8 | 4.4 | DevItems | HashBar – WordPress Notification Bar | CWE-352 | WordPress HashBar – WordPress Notification Bar plugin <= 2.0.0 - Cross Site R… |
| CVE-2026-70800 | 7.3 | 4.4 | Oracle Corporation | Oracle SDP Number Portability | CWE-284 | Vulnerability in the Oracle SDP Number Portability product of Oracle E-Busine… |
| CVE-2026-71136 | 7.3 | 4.3 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-71138 | 7.3 | 4.3 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-5224 | 5.7 | 4.4 | Kriptok Crypto and Information Technologies Industry Trade Inc. | Cryptosim | CWE-312 | Sensitive Data Exposure in Kriptek Crypto's Cryptosim |
| CVE-2026-75926 | 9.3 | 4.3 | gohugoio | hugo | CWE-1188 | Hugo 0.162.0 to 0.164.x - Node Permission Model Bypass via Default TailwindCS… |
| CVE-2026-70989 | 6.5 | 4.3 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-62553 | 5.5 | 4.3 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62564 | 5.5 | 4.3 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70836 | 5.5 | 4.3 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-52875 | 8.4 | 4.2 | truelockmc | streambert | CWE-22 | Streambert: Arbitrary Directory Creation and File Manipulation via Backup Han… |
| CVE-2026-16732 | 6.1 | 4.2 | fastify | fastify | CWE-348 | fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count |
| CVE-2026-71128 | 6.0 | 4.2 | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-71135 | 6.0 | 4.2 | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-71139 | 4.4 | 4.2 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-62580 | 2.6 | 4.2 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-71134 | 5.7 | 4.1 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-74961 | await | 4.1 | Mozilla | Firefox | — | Side-channel in the Web Audio component |
| CVE-2026-74966 | await | 4.1 | Mozilla | Firefox | — | Information disclosure in the Form Autofill component |
| CVE-2026-52872 | 8.8 | 4.0 | truelockmc | streambert | CWE-22 | Streambert: Local File Exfiltration and Overwrite via Subtitle file: Protocol |
| CVE-2026-71125 | 6.1 | 4.0 | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-71073 | 5.5 | 4.0 | Oracle Corporation | MySQL Connectors | — | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Con… |
| CVE-2026-62569 | 3.4 | 4.0 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | CWE-284 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-47630 | 5.5 | 3.9 | NVIDIA | Triton Inference Server | CWE-36 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-27365 | 5.9 | 3.8 | PublishPress | PublishPress Series | CWE-79 | WordPress PublishPress Series plugin <= 2.17.0 - Cross Site Scripting (XSS) v… |
| CVE-2026-73974 | 5.5 | 3.8 | Linuxfabrik | monitoring-plugins | CWE-22 | linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftes… |
| CVE-2026-74967 | 5.4 | 3.8 | Mozilla | Firefox | CWE-346 | Same-origin policy bypass in the Audio/Video: Playback component |
| CVE-2026-45129 | 4.6 | 3.7 | mybb | mybb | CWE-352 | MyBB: ACP Recovery Codes CSRF |
| CVE-2026-74980 | await | 3.7 | Mozilla | Firefox | — | Clickjacking issue in the Downloads component in Firefox for Android |
| CVE-2026-70806 | 7.1 | 3.7 | Oracle Corporation | Oracle E-Business Tax | — | Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite… |
| CVE-2026-70914 | 7.0 | 3.6 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-66589 | 5.4 | 3.6 | Kings Plugins | B2BKing | CWE-862 | WordPress B2BKing plugin <= 5.2.30 - Broken Access Control vulnerability |
| CVE-2026-70962 | 3.3 | 3.6 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-75485 | 5.5 | 3.5 | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | CWE-532 | Must-gather: must-gather: cluster proxy object dumped raw, bypassing inspect … |
| CVE-2026-70667 | 6.3 | 3.5 | Netflix | lemur | CWE-367 | Lemur: SSRF protection in certificate revocation checking bypassable via HTTP… |
| CVE-2026-66783 | 8.2 | 3.4 | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | CWE-20 | Submariner-operator: submariner-operator: arbitrary image override enables pr… |
| CVE-2026-45126 | 3.5 | 3.2 | mybb | mybb | CWE-352 | MyBB: ACP Questions state CSRF |
| CVE-2026-45127 | 3.5 | 3.2 | mybb | mybb | CWE-352 | MyBB: ACP Mass Mail draft resend CSRF |
| CVE-2026-45128 | 3.5 | 3.2 | mybb | mybb | CWE-352 | MyBB: ACP Users View Manager default CSRF |
| CVE-2026-60902 | 7.0 | 3.1 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | — | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-62449 | 7.0 | 3.1 | Oracle Corporation | Oracle Work in Process | — | Vulnerability in the Oracle Work in Process product of Oracle E-Business Suit… |
| CVE-2026-45119 | 4.6 | 2.9 | mybb | mybb | CWE-352 | MyBB: ACP UTF-8 Conversion CSRF |
| CVE-2026-24183 | 7.8 | 2.8 | NVIDIA | Cumulus Linux GA | CWE-250 | NVIDIA Cumulus Linux contains a vulnerability in the user management componen… |
| CVE-2026-70798 | 7.8 | 2.8 | Oracle Corporation | Oracle Purchasing | — | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co… |
| CVE-2026-71116 | 7.5 | 2.8 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-71117 | 7.5 | 2.8 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70705 | 7.1 | 2.8 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-70712 | 6.4 | 2.8 | Oracle Corporation | Oracle Agile Engineering Data Management | — | Vulnerability in the Oracle Agile Engineering Data Management product of Orac… |
| CVE-2026-71119 | 6.4 | 2.8 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-32657 | 7.3 | 2.7 | Dell | AppSync | CWE-61 | Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Ve… |
| CVE-2026-55165 | 4.8 | 2.7 | Netflix | lemur | CWE-347 | Lemur : JWT verifier trusts attacker-supplied alg from token header — defense… |
| CVE-2026-62584 | 4.0 | 2.7 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70916 | 4.0 | 2.7 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70932 | 7.2 | 2.7 | Oracle Corporation | Oracle Order Management | — | Vulnerability in the Oracle Order Management product of Oracle E-Business Sui… |
| CVE-2026-70902 | 7.1 | 2.6 | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-62558 | 6.3 | 2.6 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-71132 | 5.3 | 2.7 | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-70685 | 7.9 | 2.6 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-74963 | 5.4 | 2.5 | Mozilla | Firefox | CWE-346 | Same-origin policy bypass in the Networking: Cookies component |
| CVE-2026-50126 | 4.0 | 2.6 | KNMI | adaguc-server | CWE-125 | adaguc-server GeoJSON coordinate parser (CConvertGeoJSON.cpp) vulnerable to o… |
| CVE-2026-70711 | 3.6 | 2.5 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-70919 | 2.5 | 2.5 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-71129 | 8.2 | 2.5 | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-62570 | 3.0 | 2.5 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | CWE-284 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62583 | 3.0 | 2.5 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | CWE-284 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70879 | 7.8 | 2.3 | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-71126 | 7.8 | 2.3 | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-70992 | 7.0 | 2.3 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71041 | 7.0 | 2.3 | Oracle Corporation | Oracle Agile PLM | CWE-284 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-70841 | 5.6 | 2.4 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-75857 | 7.3 | 2.3 | Hmbown | CodeWhale | CWE-269 | CodeWhale before 0.8.64 Privilege Escalation via exec_shell_interact |
| CVE-2026-60873 | 7.2 | 2.2 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | CWE-284 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-71013 | 6.0 | 2.3 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-60808 | 7.5 | 2.2 | Oracle Corporation | Siebel Apps - Marketing | — | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co… |
| CVE-2026-70758 | 5.3 | 2.1 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70784 | 5.3 | 2.1 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-75904 | 4.8 | 2.1 | Konstanty Bialkowski | libmodplug | CWE-125 | libmodplug <= 0.8.9.1 - Out-of-Bounds Read in pat_smplooped via Crafted MIDI … |
| CVE-2026-70714 | 4.1 | 2.0 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-71144 | 3.0 | 2.1 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-71081 | 1.9 | 2.1 | Oracle Corporation | Oracle Agile PLM MCAD Connector | CWE-284 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply… |
| CVE-2026-71046 | 8.8 | 2.0 | Oracle Corporation | Oracle Agile PLM | CWE-284 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-61300 | 7.8 | 2.0 | Oracle Corporation | Oracle Enterprise Manager Base Platform | — | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-62581 | 7.8 | 2.0 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-71101 | 7.8 | 2.0 | Oracle Corporation | Oracle HRMS (US) | CWE-284 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (com… |
| CVE-2026-62573 | 5.5 | 2.0 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-71146 | 1.9 | 2.0 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-61298 | 5.6 | 2.0 | Oracle Corporation | Oracle Enterprise Manager Base Platform | — | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-71151 | 5.6 | 2.0 | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-70912 | 5.3 | 1.9 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-61339 | 7.3 | 1.8 | Oracle Corporation | Siebel CRM Cloud Applications | — | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-62536 | 7.1 | 1.9 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-71066 | 4.5 | 1.9 | Oracle Corporation | Oracle Agile PLM MCAD Connector | CWE-284 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply… |
| CVE-2026-71083 | 1.8 | 1.9 | Oracle Corporation | Oracle Agile PLM MCAD Connector | CWE-284 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply… |
| CVE-2026-57826 | 9.8 | 1.8 | n/a | n/a | CWE-295 | An issue was discovered in openHiTLS 0.2.0 through 0.3.2. In the X.509 certif… |
| CVE-2026-71094 | 7.3 | 1.7 | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | CWE-284 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-71127 | 6.0 | 1.6 | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-71137 | 6.0 | 1.6 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-71033 | 5.5 | 1.7 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-74968 | 5.4 | 1.7 | Mozilla | Firefox | CWE-346 | Site isolation issue in the Graphics: WebRender component |
| CVE-2026-71082 | 2.5 | 1.7 | Oracle Corporation | Oracle Agile PLM MCAD Connector | CWE-284 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply… |
| CVE-2026-59781 | 5.4 | 1.6 | Zabbix | Zabbix | CWE-427 | Improper validation of custom installation directories on Windows could allow… |
| CVE-2026-71140 | 3.4 | 1.6 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-71154 | 6.1 | 1.5 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-18751 | 5.2 | 1.5 | Citrix | WorkSpace App | CWE-73 | Citrix Workspace App for Mac Security Bulletin for CVE-2026-18751 |
| CVE-2026-70731 | 8.4 | 1.4 | Oracle Corporation | Oracle Autonomous Health Framework | — | Vulnerability in Oracle Autonomous Health Framework (component: Trace File An… |
| CVE-2026-70693 | 6.3 | 1.4 | Oracle Corporation | Oracle Agile Engineering Data Management | — | Vulnerability in the Oracle Agile Engineering Data Management product of Orac… |
| CVE-2026-62577 | 3.3 | 1.4 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-60975 | 7.5 | 1.3 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | — | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-61407 | 8.8 | 1.2 | Dell | Watchdog Timer Driver | CWE-698 | Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL… |
| CVE-2026-70796 | 7.2 | 1.1 | Oracle Corporation | Oracle General Ledger | — | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite… |
| CVE-2026-71078 | 4.2 | 1.1 | Oracle Corporation | Oracle Agile PLM MCAD Connector | CWE-284 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply… |
| CVE-2026-71149 | 4.2 | 1.1 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-71072 | 3.3 | 1.1 | Oracle Corporation | Oracle Agile PLM MCAD Connector | CWE-284 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply… |
| CVE-2026-71477 | 6.7 | 1.1 | jdx | mise | CWE-278 | mise: Incorrect file ownership, when installed by the root user using `instal… |
| CVE-2026-70850 | 3.0 | 1.0 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70697 | 7.0 | 1.0 | Oracle Corporation | Oracle Agile Engineering Data Management | — | Vulnerability in the Oracle Agile Engineering Data Management product of Orac… |
| CVE-2026-71098 | 7.0 | 1.0 | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | CWE-284 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-62575 | 4.7 | 1.0 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-71092 | 7.5 | 0.9 | Oracle Corporation | PeopleSoft Enterprise FIN Lease Administration | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Lease Administration product o… |
| CVE-2026-59915 | 7.3 | 0.9 | Dell | Alienware Command Center (AWCC) | CWE-272 | Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a … |
| CVE-2026-62511 | 3.0 | 0.9 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-60994 | 7.2 | 0.7 | Oracle Corporation | Oracle Identity Manager Connector | — | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-70794 | 4.7 | 0.7 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-71105 | 4.7 | 0.6 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-66782 | 7.8 | 0.3 | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | CWE-312 | Submariner-operator: submariner-operator: broker api bearer token stored clea… |
| CVE-2026-71417 | 7.3 | 0.3 | Netflix | lemur | CWE-639 | Lemur: Any user can revoke arbitrary certificates at the CA by uploading a du… |
| CVE-2026-66781 | 6.5 | 0.2 | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | CWE-312 | Submariner-operator: submariner-operator: ipsec psk stored cleartext in subma… |
| CVE-2026-71317 | 6.5 | 0.2 | Netflix | lemur | CWE-862 | Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent autho… |
| CVE-2026-49500 | 6.0 | 0.2 | Dell | Alienware Command Center (AWCC | CWE-272 | Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an… |
| CVE-2026-73834 | 5.5 | 0.2 | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | CWE-312 | Must-gather: must-gather: embedded secret data in acm wrapper crs collected w… |