boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, August 18, 2026 · all times UTC← 2026-08-17 · archive

Edition of August 18, 2026, continued — page 3 of 3. Back to page 1 · page 2

Results (continued, ranked) — ranks 1001–1407 of 1407
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-707686.115.1Oracle CorporationOracle Hyperion Financial ReportingVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-709616.115.1Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-710196.115.1Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-738986.115.1Oracle CorporationHelidonVulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-707595.415.1Oracle CorporationOracle Hyperion Financial ReportingVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-707665.415.1Oracle CorporationOracle Hyperion Financial ReportingVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-711235.415.1Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-325477.114.9wordplusBP Better MessagesCWE-79WordPress BP Better Messages plugin <= 2.15.22 - Cross Site Scripting (XSS) v…
CVE-2026-666217.114.9Ultimate DashboadUltimate DashboardCWE-79WordPress Ultimate Dashboard plugin <= 3.11.2 - Cross Site Scripting (XSS) vu…
CVE-2026-666297.114.9ThemeumKirkiCWE-79WordPress Kirki plugin <= 6.2.3 - Cross Site Scripting (XSS) vulnerability
CVE-2026-685677.114.9WP GridsConvert ProCWE-79WordPress Convert Pro plugin <= 1.0.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-733387.114.9AutopayAutopayCWE-79WordPress Autopay plugin <= 5.0.0 - Cross Site Scripting (XSS) vulnerability
CVE-2026-733427.114.9Magazine3WP MultilangCWE-79WordPress WP Multilang plugin <= 2.4.31 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-733587.114.9wp.insiderAffiliates ManagerCWE-79WordPress Affiliates Manager plugin <= 2.9.53 - Cross Site Scripting (XSS) vu…
CVE-2026-733607.114.9PremioChaty ProCWE-79WordPress Chaty Pro plugin <= 3.5.8 - Cross Site Scripting (XSS) vulnerability
CVE-2026-733627.114.9KaizenCodersURL ShortifyCWE-79WordPress URL Shortify plugin <= 2.5.0 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-733787.114.9supsysticContact Form by SupsysticCWE-79WordPress Contact Form by Supsystic plugin < 1.10.0 - Cross Site Scripting (X…
CVE-2026-733827.114.9Gemini LabsSite ReviewsCWE-79WordPress Site Reviews plugin <= 8.2.0 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-733937.114.9weDevsSubscribe2CWE-79WordPress Subscribe2 plugin <= 10.46 - Cross Site Scripting (XSS) vulnerability
CVE-2026-667809.914.8Red HatRed Hat Advanced Cluster Management for Kubernetes 2CWE-284Submariner-operator: submariner-operator: flat broker trust model grants ever…
CVE-2026-485088.814.9NetflixlemurCWE-863Lemur: Authorization bypass in StrictRolePermission / AuthorityCreatorPermission
CVE-2026-710968.214.8Oracle CorporationOracle Business Intelligence Enterprise EditionCWE-284Vulnerability in the Oracle Business Intelligence Enterprise Edition product …
CVE-2026-625293.514.7Oracle CorporationOracle Hyperion Calculation ManagerVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-281929.614.5PiotnetPiotnet Addons For Elementor ProCWE-434WordPress Piotnet Addons For Elementor Pro plugin <= 7.1.67 - Arbitrary File …
CVE-2026-672628.114.5DellPowerStore 500TCWE-862Dell PowerStore contains a Missing Authorization vulnerability. An attacker w…
CVE-2026-708587.114.6Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-551644.914.6NetflixlemurCWE-256Lemur: Plaintext password storage in Lemur user-update path
CVE-2026-713077.714.5NetflixlemurCWE-862Lemur: Authenticated low-privilege users can read plaintext destination crede…
CVE-2026-758447.114.4ArcadeDataarcadedbCWE-918ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypass
CVE-2026-555936.514.3froxlorfroxlorCWE-352Froxlor: CSRF Vulnerability in Froxlor AJAX Endpoint — Missing Cross-Site Req…
CVE-2026-749528.814.3MozillaFirefoxCWE-269Privilege escalation in the Application Update component
CVE-2026-738917.314.2Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-739337.314.2Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-711558.514.1Oracle CorporationHelidonVulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-616966.314.1foremforemCWE-74Forem: Stored XSS in Admin Abuse Report Rendering
CVE-2026-626063.114.1Oracle CorporationOracle Hyperion Calculation ManagerVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-711085.314.0Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-625204.814.0Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2021-43717await13.9n/an/aAn issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identi…
CVE-2026-624488.213.8Oracle CorporationOracle Email CenterVulnerability in the Oracle Email Center product of Oracle E-Business Suite (…
CVE-2026-626058.213.8Oracle CorporationOracle Partner ManagementVulnerability in the Oracle Partner Management product of Oracle E-Business S…
CVE-2026-710168.213.8Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-626035.413.8Oracle CorporationOracle Hyperion Calculation ManagerVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-708436.813.7Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-708533.313.7Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-624597.213.6Oracle CorporationOracle Hyperion Calculation ManagerCWE-284Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-711565.313.6Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-626139.313.5Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626379.313.5Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-758359.313.3getgravgravCWE-862Grav API Plugin before 1.0.14 Missing Authorization
CVE-2026-749508.813.3MozillaFirefoxCWE-269Privilege escalation in the Downloads API component
CVE-2026-749558.813.3MozillaFirefoxCWE-269Privilege escalation in the Request Handling component
CVE-2026-526066.113.3n/an/aCWE-79A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.…
CVE-2026-526096.113.3n/an/aCWE-79A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.…
CVE-2026-451205.413.2mybbmybbCWE-639MyBB: Insufficient authorization for private calendar events
CVE-2026-758395.313.2ArcadeDataarcadedbCWE-200ArcadeDB before 26.8.1 Information Disclosure via Cluster Endpoints
CVE-2026-758329.313.0getgravgravCWE-862Grav API Plugin before 1.0.14 Authorization Bypass
CVE-2026-527239.112.8fbeta-GmbHePA3-Service-OpenSourceCWE-295ePA 3.x Integration: VAU Server Authentication Bypass via Circular Certificat…
CVE-2026-740045.412.9wpmonksGravity Booster &#8211; Styles &amp; Layouts for Gravity FormsCWE-862WordPress Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms plug…
CVE-2026-711184.812.7Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-625766.512.6Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-551669.912.4NetflixlemurCWE-285Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent P…
CVE-2026-626028.012.1Oracle CorporationOracle Hyperion Calculation ManagerVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-625457.512.2Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-706917.512.2Oracle CorporationOracle Agile Engineering Data ManagementVulnerability in the Oracle Agile Engineering Data Management product of Orac…
CVE-2026-709557.512.2Oracle CorporationOracle Commerce PlatformVulnerability in the Oracle Commerce Platform product of Oracle Commerce (com…
CVE-2026-739735.512.2Linuxfabrikmonitoring-pluginsCWE-22Linuxfabrik Monitoring Plugins: Arbitrary root file disclosure via unconfined…
CVE-2026-760378.411.8GoogleChromeCWE-59Link following in CredentialProvider in Google Chrome on on Windows prior to …
CVE-2026-713037.711.7NetflixlemurCWE-918Lemur: Incomplete fix for CVE-2026-55166 -- ACME authority update endpoint al…
CVE-2026-666366.511.7MarcinWise ChatCWE-79WordPress Wise Chat plugin <= 3.4 - Cross Site Scripting (XSS) vulnerability
CVE-2026-666386.511.7Shabti KaplanFrontend Admin by DynamiAppsCWE-79WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Cross Site Scripti…
CVE-2026-666396.511.7WPZOOMWPZOOM Forms – Contact Form Plugin for GutenbergCWE-79WordPress WPZOOM Forms – Contact Form plugin for Gutenberg plugin <= 2.0.4 - …
CVE-2026-666406.511.7Marcus (aka @msykes)Login With AjaxCWE-79WordPress Login With Ajax plugin <= 4.5.1 - Cross Site Scripting (XSS) vulner…
CVE-2026-666436.511.7wronganswersonlyWufoo ShortcodeCWE-79WordPress Wufoo Shortcode plugin <= 1.55 - Cross Site Scripting (XSS) vulnera…
CVE-2026-666456.511.7WPDeveloperTable Of Contents BlockCWE-79WordPress Table Of Contents Block plugin <= 1.5.0 - Cross Site Scripting (XSS…
CVE-2026-666466.511.7MyThemeShopWP Tab WidgetCWE-79WordPress WP Tab Widget plugin <= 1.2.11 - Cross Site Scripting (XSS) vulnera…
CVE-2026-733596.511.7WP Legal PagesWP Cookie Notice for GDPR, CCPA & ePrivacy ConsentCWE-79WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.3.9 …
CVE-2026-711474.211.6Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-733796.511.6supsysticContact Form by SupsysticCWE-288WordPress Contact Form by Supsystic plugin < 1.10.0 - Bypass Vulnerability vu…
CVE-2026-749035.311.5siyuan-notesiyuanCWE-400SiYuan before v3.7.4 Insufficient Access Control via spinBlockDOM
CVE-2026-758455.311.4ArcadeDataarcadedbCWE-269ArcadeDB 26.4.2 before 26.8.1 Authorization Bypass via set_server_setting
CVE-2025-117294.311.3buildwpsPPWP – Password Protect PagesCWE-285PPWP: Password Protect Pages, Posts & Full or Partial Content <= 1.9.15 - Imp…
CVE-2026-241857.111.3NVIDIANVOSCWE-288NVIDIA NVOS for network switches contains a vulnerability in the secure shell…
CVE-2026-706823.711.3Oracle CorporationOracle Hyperion Calculation ManagerVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-707853.711.3Oracle CorporationOracle Hyperion Financial ReportingVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-153718.111.2Rapid7VelociraptorCWE-177Velociraptor Stored XSS in URL column types
CVE-2026-67846await11.1n/an/aBerkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d65119…
CVE-2026-715398.911.0n8n-ion8nCWE-367n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve R…
CVE-2026-706748.811.0Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-611396.311.0Oracle CorporationOracle Public Sector Financials (International)CWE-284Vulnerability in the Oracle Public Sector Financials (International) product …
CVE-2026-710307.210.8Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-738926.510.8Oracle CorporationHelidonVulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-739046.510.8Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-125206.410.8zephyrprojectzephyrCWE-787Stack buffer overflow and off-by-one writes in Zephyr HL7800 modem AT respons…
CVE-2026-636404.310.8MagicMirrorOrgMagicMirrorCWE-200MagicMirror socket payload secret placeholder expansion can disclose SECRET_*…
CVE-2026-612967.610.7Oracle CorporationOracle Enterprise Asset ManagementVulnerability in the Oracle Enterprise Asset Management product of Oracle E-B…
CVE-2026-706787.610.7Oracle CorporationOracle Hyperion Calculation ManagerVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-710207.610.7Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-710217.610.7Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-710227.610.7Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-625227.110.7Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-750882.110.8itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System viewbilling.php sql injection
CVE-2026-527375.310.6ZcashFoundationzebraCWE-345ZEBRA: Sync restart poisoning from single unauthenticated peer via above-look…
CVE-2026-710714.610.6Oracle CorporationOracle Agile PLM MCAD ConnectorVulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply…
CVE-2021-43716await10.6n/an/aVerification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Net…
CVE-2026-756259.110.2uberkrakenCWE-354Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification B…
CVE-2026-750862.110.2itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System viewroom.php sql injection
CVE-2026-750872.110.2itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System viewdepartment.php sql injection
CVE-2026-239337.710.1ZabbixZabbixCWE-259Hardcoded session key in Zabbix 7.4
CVE-2026-74943await10.1MozillaFirefoxUse-after-free in the Graphics: ImageLib component
CVE-2026-74945await10.1MozillaFirefoxInformation disclosure in the Graphics: Text component
CVE-2026-739233.79.9Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-554267.89.9Linuxfabrikmonitoring-pluginsCWE-78linuxfabrik-lib: Local privilege escalation using embedded command
CVE-2026-324676.09.8apoyl[Aotuman] Grab WeChat ArticlesCWE-918WordPress [Aotuman] Grab WeChat Articles plugin <= 2.0.1 - Server Side Reques…
CVE-2026-750326.39.7Red HatRed Hat Enterprise Linux 10CWE-125Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media…
CVE-2026-709634.29.7Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-738734.29.7Oracle CorporationHelidonVulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-624613.19.6Oracle CorporationOracle Hyperion Calculation ManagerVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-758338.69.5getgravgravCWE-601Grav API Plugin Open Redirect via Backslash Bypass
CVE-2026-750917.29.5mdmagQuill Forms | Conversational Multi Step Forms, Surveys & quizzesCWE-79Quill Forms <= 5.7.1 - Unauthenticated Stored Cross-Site Scripting
CVE-2026-666516.59.5MultiVendorXMultiVendorXCWE-862WordPress MultiVendorX plugin <= 5.0.14 - Broken Access Control vulnerability
CVE-2026-733486.59.5NexcessGiveWPCWE-862WordPress GiveWP plugin < 4.16.6 - Broken Access Control vulnerability
CVE-2026-171067.19.3mobygo-archiveCWE-59Tar extraction in moby/go-archive can write outside the destination directory…
CVE-2026-689236.59.3MobSFMobile-Security-Framework-MobSFCWE-352MobSF: CSRF checks not enforced after Django migration
CVE-2026-707895.99.4Oracle CorporationOracle Hyperion Financial ReportingVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-707762.69.4Oracle CorporationOracle Hyperion Financial ReportingVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-707177.79.2Oracle CorporationOracle Autonomous Health FrameworkVulnerability in Oracle Autonomous Health Framework (component: Cluster Healt…
CVE-2026-707806.89.3Oracle CorporationOracle Hyperion Financial ReportingVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-709236.19.3Oracle CorporationHelidonVulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-626043.19.3Oracle CorporationOracle Hyperion Calculation ManagerVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-534565.68.9ha-chinablueprint-studioCWE-522Blueprint Studio terminal SSH private key written to disk
CVE-2026-153167.18.7TP-Link Systems Inc.Tapo C200 v5CWE-20Denial-of-Service via Oversized Encrypted Credential Input in TP-Link Tapo C200
CVE-2026-528177.08.7Linuxfabrikmonitoring-pluginsCWE-88Linuxfabrik Monitoring Plugins Sudoers: /usr/bin/apt-get arguments allow priv…
CVE-2026-749734.28.7MozillaFirefoxCWE-362Race condition, use-after-free in the Graphics component
CVE-2026-505787.58.5fbeta-GmbHePA3-Service-OpenSourceCWE-295ePA 3.x Integration: TLS Certificate Verification Universally Disabled
CVE-2026-740064.38.4WP Table BuilderWP Table BuilderCWE-862WordPress WP Table Builder plugin <= 2.2.0 - Broken Access Control vulnerability
CVE-2026-749879.88.4MozillaFirefoxCWE-119Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 …
CVE-2026-716767.58.3n/an/aCWE-122Buffer Overflow vulnerability in Open5GS v.2.7.0 allows a remote attacker to …
CVE-2026-537592.08.3Linuxfabrikmonitoring-pluginsCWE-377linuxfabrik-lib: Insecure creation of SQLite databases
CVE-2026-738745.48.2Oracle CorporationHelidonVulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-739115.48.2Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-609618.08.1Oracle CorporationOracle WebCenter ContentVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-625786.58.1Oracle CorporationOracle Hyperion Calculation ManagerVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-633365.18.1rabbitmqrabbitmq-java-clientCWE-295RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslPr…
CVE-2026-749085.18.1getgravgravCWE-79Grav plugin-api before 1.0.15 Script Injection via SVG
CVE-2026-758345.18.1getgravgravCWE-79Grav before 2.0.14 Stored XSS via Invalid UTF-8 Byte
CVE-2026-524817.58.0n/an/aCWE-200An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote att…
CVE-2026-716757.58.0n/an/aCWE-401An issue in Open5GS v.2.7.0 allows a remote attacker to cause a denial of ser…
CVE-2026-710046.18.0Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-710056.18.0Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-710066.18.0Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-710116.18.0Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-710256.18.0Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-710316.18.0Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-738696.18.0Oracle CorporationHelidonVulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-738706.18.0Oracle CorporationHelidonVulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-52480await8.0n/an/aAn issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote att…
CVE-2026-285687.17.8Mohamed MagdyQuill FormsCWE-79WordPress Quill Forms plugin <= 5.7.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-285697.17.9SSL ZenSSL ZenCWE-79WordPress SSL Zen plugin <= 4.7.43 - Reflected Cross Site Scripting (XSS) vul…
CVE-2026-323337.17.9TeconceThemeMayosis CoreCWE-79WordPress Mayosis Core plugin <= 5.4.7 - Reflected Cross Site Scripting (XSS)…
CVE-2026-666337.17.8WPManageNinjaFluent Forms Pro Add On PackCWE-79WordPress Fluent Forms Pro Add On Pack plugin < 6.2.12 - Cross Site Scripting…
CVE-2026-666677.17.9WPDeveloperTemplatelyCWE-79WordPress Templately plugin <= 3.7.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-731907.17.9ShahjadaWPDM – Premium PackagesCWE-79WordPress WPDM – Premium Packages plugin <= 7.0.5 - Cross Site Scripting (XSS…
CVE-2026-733517.17.8miniOrangeWordPress Social Login and RegisterCWE-79WordPress WordPress Social Login and Register plugin <= 7.8.1 - Cross Site Sc…
CVE-2026-733617.17.8WPZOOMRecipe Card Blocks for Gutenberg & ElementorCWE-79WordPress Recipe Card Blocks for Gutenberg & Elementor plugin <= 3.4.18 - Cro…
CVE-2026-733757.17.9supsysticUltimate Maps by SupsysticCWE-79WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - Cross Site Scripting (X…
CVE-2026-710775.37.9Oracle CorporationOracle Agile PLM MCAD ConnectorCWE-284Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply…
CVE-2026-713088.17.7NetflixlemurCWE-639Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack …
CVE-2026-713224.37.7NetflixlemurCWE-862Lemur: Missing authorization check on POST /certificates/<id>/export for plug…
CVE-2026-707094.87.6Oracle CorporationOracle Agile Engineering Data ManagementVulnerability in the Oracle Agile Engineering Data Management product of Orac…
CVE-2026-739014.87.6Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-710755.97.5Oracle CorporationOracle Agile PLM MCAD ConnectorCWE-284Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply…
CVE-2026-759118.57.2HmbownCodeWhaleCWE-94CodeWhale before 0.8.64 Remote Code Execution via allow_shell
CVE-2026-239356.87.2ZabbixZabbixCWE-125Use-after-free read in script item/preprocessing HttpRequest body
CVE-2026-196705.37.2CISAgovMalcolmCWE-863Incorrect Authorization in CISA Malcolm
CVE-2026-608844.47.1Oracle CorporationPeopleSoft Enterprise PeopleToolsVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop…
CVE-2026-711454.47.1Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-505757.76.9UNITRONIXBetterDeskCWE-294BetterDesk has a replay behavior vulnerability when devices are deleted
CVE-2026-749755.46.9MozillaFirefoxCWE-451Spoofing issue in the Downloads component in Firefox for Android
CVE-2026-239305.36.9ZabbixZabbixCWE-405Frontend DoS via the popup.testtriggerexpr action
CVE-2026-749838.16.9MozillaFirefoxCWE-693Mitigation bypass in the Data Loss Prevention component
CVE-2026-609937.56.9Oracle CorporationOracle Identity Manager ConnectorVulnerability in the Oracle Identity Manager Connector product of Oracle Fusi…
CVE-2026-545527.96.8amoffatshCWE-273sh _uid does not drop supplementary groups (incomplete privilege drop)
CVE-2026-749516.56.8MozillaFirefoxCWE-1021Clickjacking issue in Firefox for Android
CVE-2026-749705.46.6MozillaFirefoxCWE-346Site isolation issue in the Graphics component
CVE-2026-239345.16.6ZabbixZabbixCWE-405Frontend DoS via the validate.api.exists action
CVE-2026-751075.16.6getgravgravCWE-79Grav Form Plugin before 9.1.19 Stored XSS via Field Properties
CVE-2026-636323.36.3onnxonnxCWE-125ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersi…
CVE-2026-689392.06.3pyenvpyenvCWE-78Pyenv: Glob/wildcard metacharacters bypass is_version_safe(), causing silent …
CVE-2026-706667.46.2NetflixlemurCWE-918Lemur: Server-Side Request Forgery via the ACME client following server-contr…
CVE-2026-551626.36.2NetflixlemurCWE-918Lemur: Post-authentication SSRF via certificate verification - attacker-contr…
CVE-2026-551636.36.2NetflixlemurCWE-863Lemur: Privilege escalation via PUT /api/1/roles/<id> — non-admin role member…
CVE-2026-707934.26.3Oracle CorporationOracle Hyperion Financial ReportingVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-666357.46.110WebSlider by 10WebCWE-352WordPress Slider by 10Web plugin <= 1.2.62 - CSRF to Arbitrary File Deletion …
CVE-2026-74957await6.1MozillaFirefoxMitigation bypass in the Safe Browsing component
CVE-2026-74959await6.1MozillaFirefoxMitigation bypass in the Storage: Cache API component
CVE-2026-749766.56.0MozillaFirefoxCWE-843JIT miscompilation in the JavaScript Engine: JIT component
CVE-2026-624547.85.9Oracle CorporationSiebel CRM Cloud ApplicationsVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-715517.85.9super-productivitysuper-productivityCWE-78Super Productivity: Arbitrary OS Command Execution via IPC EXEC Handler with …
CVE-2026-708947.75.9Oracle CorporationOracle Hyperion Data Relationship ManagementVulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-612957.15.9Oracle CorporationOracle WebCenter ContentVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-194475.45.9Fileorbis Informatics Services Trade Inc.FileOrbisCWE-79Stored XSS in Fileorbis Informatics's FileOrbis
CVE-2026-622915.35.9strukturaglibheifCWE-125libheif: Heap out of bounds write in libheif uncompressed encoder when writin…
CVE-2026-665916.55.8David LingrenMedia LIbrary AssistantCWE-79WordPress Media LIbrary Assistant plugin <= 3.39 - Cross Site Scripting (XSS)…
CVE-2026-666036.55.8David ArtissDraft ListCWE-79WordPress Draft List plugin <= 2.6.4 - Cross Site Scripting (XSS) vulnerability
CVE-2026-666376.55.8AlexFeatured Video PlusCWE-79WordPress Featured Video Plus plugin <= 2.3.3 - Cross Site Scripting (XSS) vu…
CVE-2026-666416.55.8Deepen BajracharyaVideo Conferencing with ZoomCWE-79WordPress Video Conferencing with Zoom plugin <= 4.6.8 - Cross Site Scripting…
CVE-2026-666446.55.893digitalTyping EffectCWE-79WordPress Typing Effect plugin <= 1.3.7 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-685656.55.8PaoloGeoDirectoryCWE-79WordPress GeoDirectory plugin <= 2.8.172 - Cross Site Scripting (XSS) vulnera…
CVE-2026-749698.85.7MozillaFirefoxCWE-416Use-after-free in the Layout: Text and Fonts component
CVE-2026-708408.45.7Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-708428.45.7Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-707194.05.7Oracle CorporationOracle Hyperion Calculation ManagerVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-709174.05.7Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-758502.35.7ArcadeDataarcadedbCWE-862ArcadeDB before 26.8.1 Per-Type ACL Bypass via Batch Handlers
CVE-2026-74934await5.7MozillaFirefoxSite isolation issue in the Graphics: CanvasWebGL component
CVE-2026-74940await5.7MozillaFirefoxUse-after-free in the Graphics: Text component
CVE-2026-74948await5.7MozillaFirefoxInformation disclosure in the Graphics component
CVE-2026-759248.75.6Red HatMulticluster Engine for KubernetesCWE-269Managed-serviceaccount: managed-serviceaccount: hub addon-manager clusterrole…
CVE-2026-711318.65.6Oracle CorporationOracle VM VirtualBoxVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-603927.85.6Oracle CorporationOracle Outside In TechnologyCWE-502Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Mi…
CVE-2026-604127.85.6Oracle CorporationOracle Outside In TechnologyVulnerability in the Oracle Outside In Technology product of Oracle Fusion Mi…
CVE-2026-604137.85.6Oracle CorporationOracle Outside In TechnologyVulnerability in the Oracle Outside In Technology product of Oracle Fusion Mi…
CVE-2026-604147.85.6Oracle CorporationOracle Outside In TechnologyVulnerability in the Oracle Outside In Technology product of Oracle Fusion Mi…
CVE-2026-710107.85.6Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-706986.75.4Oracle CorporationOracle Agile Engineering Data ManagementVulnerability in the Oracle Agile Engineering Data Management product of Orac…
CVE-2026-711096.75.4Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-749649.85.3MozillaFirefoxCWE-190Integer overflow in the Graphics component
CVE-2026-749628.15.3MozillaFirefoxCWE-346Site isolation issue in the Networking: Cookies component
CVE-2026-710846.85.3Oracle CorporationMySQL ConnectorsCWE-284Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Con…
CVE-2026-74936await5.3MozillaFirefoxUse-after-free in the JavaScript: WebAssembly component
CVE-2026-74944await5.3MozillaFirefoxUse-after-free in the DOM: Core & HTML component
CVE-2026-74960await5.3MozillaFirefoxSite isolation issue in the WebExtensions component
CVE-2025-92108.15.2OtalioShip Property Management SystemCWE-347Missing JSON Web Token signature validation in Otalio Ship Property Managemen…
CVE-2026-709916.35.2Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-707266.05.2Oracle CorporationOracle Cash ManagementVulnerability in the Oracle Cash Management product of Oracle E-Business Suit…
CVE-2026-711146.05.2Oracle CorporationOracle VM VirtualBoxCWE-284Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-711156.05.2Oracle CorporationOracle VM VirtualBoxCWE-284Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-751515.35.2SourceCodesterOnlne Examination & Learning Management SystemCWE-352SourceCodester Onlne Examination & Learning Management System cross-site requ…
CVE-2026-738804.45.2Oracle CorporationHelidonVulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-74988await5.1MozillaFirefoxInternally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154
CVE-2026-528768.85.0truelockmcstreambertCWE-20Streambert: Arbitrary File Execution via VLC/mpv Launcher Fallback
CVE-2026-613136.74.9Oracle CorporationOracle Hyperion Calculation ManagerVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-710803.74.9Oracle CorporationOracle Agile PLM MCAD ConnectorCWE-284Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply…
CVE-2026-709418.84.8Oracle CorporationOracle PayrollVulnerability in the Oracle Payroll product of Oracle E-Business Suite (compo…
CVE-2026-710518.84.8Oracle CorporationOracle Product Lifecycle AnalyticsVulnerability in the Oracle Product Lifecycle Analytics product of Oracle Sup…
CVE-2026-607537.84.8Oracle CorporationSiebel CRM DeploymentVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp…
CVE-2026-608227.84.8Oracle CorporationOracle Enterprise Manager for Systems InfrastructureVulnerability in the Oracle Enterprise Manager for Systems Infrastructure pro…
CVE-2026-609917.84.8Oracle CorporationOracle Identity Manager ConnectorVulnerability in the Oracle Identity Manager Connector product of Oracle Fusi…
CVE-2026-612917.84.8Oracle CorporationOracle WebCenter ContentVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-707507.84.8Oracle CorporationOracle Hyperion Financial ReportingVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-708667.84.8Oracle CorporationOracle Application Testing SuiteVulnerability in Oracle Application Testing Suite. The supported version that…
CVE-2026-710287.84.8Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-710977.84.8Oracle CorporationOracle Business Intelligence Enterprise EditionCWE-284Vulnerability in the Oracle Business Intelligence Enterprise Edition product …
CVE-2026-711117.84.8Oracle CorporationOracle Identity ManagerVulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-633286.84.8aquasecuritytrivyCWE-22Trivy: Path Traversal in Trivy Plugin Manager Allows Arbitrary File Write
CVE-2026-625726.54.8Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-708476.54.8Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-708956.54.8Oracle CorporationOracle Hyperion Data Relationship ManagementVulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-749745.44.8MozillaFirefoxCWE-346Same-origin policy bypass in the Graphics: ImageLib component
CVE-2026-74981await4.7MozillaFirefoxSite isolation issue in the Audio/Video: Web Codecs component
CVE-2026-74982await4.7MozillaFirefoxDenial-of-service in the Widget component
CVE-2026-74984await4.7MozillaFirefoxRace condition in the JavaScript Engine component
CVE-2026-74985await4.7MozillaFirefoxPrivilege escalation in the Enterprise Policies component
CVE-2026-74986await4.7MozillaFirefoxSite isolation issue in the CSS Parsing and Computation component
CVE-2026-74989await4.7MozillaFirefoxInternally found bugs fixed in Thunderbird 154
CVE-2026-609288.44.6Oracle CorporationOracle WebCenter ContentVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-707347.44.7Oracle CorporationOracle Autonomous Health FrameworkVulnerability in Oracle Autonomous Health Framework (component: Trace File An…
CVE-2026-625377.14.6Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-709367.14.6Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-709677.14.6Oracle CorporationOracle Hyperion Infrastructure TechnologyCWE-284Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-730737.14.6vimvimCWE-94Vim: Arbitrary Ex Command Execution in C Omni-Completion
CVE-2026-711417.74.5Oracle CorporationOracle VM VirtualBoxCWE-284Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-126316.54.6zephyrprojectzephyrCWE-862Broken access-control denial in k_thread_join/k_thread_abort syscall validati…
CVE-2026-708386.14.5Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-749029.34.5siyuan-notesiyuanCWE-79SiYuan before v3.7.4 XSS-to-RCE via malicious filename upload
CVE-2026-710893.34.4Oracle CorporationOracle Agile PLM MCAD ConnectorVulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply…
CVE-2026-666028.84.4DevItemsHashBar – WordPress Notification BarCWE-352WordPress HashBar – WordPress Notification Bar plugin <= 2.0.0 - Cross Site R…
CVE-2026-708007.34.4Oracle CorporationOracle SDP Number PortabilityCWE-284Vulnerability in the Oracle SDP Number Portability product of Oracle E-Busine…
CVE-2026-711367.34.3Oracle CorporationOracle VM VirtualBoxCWE-284Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-711387.34.3Oracle CorporationOracle VM VirtualBoxCWE-284Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-52245.74.4Kriptok Crypto and Information Technologies Industry Trade Inc.CryptosimCWE-312Sensitive Data Exposure in Kriptek Crypto's Cryptosim
CVE-2026-759269.34.3gohugoiohugoCWE-1188Hugo 0.162.0 to 0.164.x - Node Permission Model Bypass via Default TailwindCS…
CVE-2026-709896.54.3Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-625535.54.3Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-625645.54.3Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-708365.54.3Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-528758.44.2truelockmcstreambertCWE-22Streambert: Arbitrary Directory Creation and File Manipulation via Backup Han…
CVE-2026-167326.14.2fastifyfastifyCWE-348fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count
CVE-2026-711286.04.2Oracle CorporationOracle VM VirtualBoxVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-711356.04.2Oracle CorporationOracle VM VirtualBoxVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-711394.44.2Oracle CorporationOracle VM VirtualBoxCWE-284Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-625802.64.2Oracle CorporationOracle Hyperion Calculation ManagerVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-711345.74.1Oracle CorporationOracle VM VirtualBoxCWE-284Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-74961await4.1MozillaFirefoxSide-channel in the Web Audio component
CVE-2026-74966await4.1MozillaFirefoxInformation disclosure in the Form Autofill component
CVE-2026-528728.84.0truelockmcstreambertCWE-22Streambert: Local File Exfiltration and Overwrite via Subtitle file: Protocol
CVE-2026-711256.14.0Oracle CorporationOracle VM VirtualBoxVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-710735.54.0Oracle CorporationMySQL ConnectorsVulnerability in the MySQL Connectors product of Oracle MySQL (component: Con…
CVE-2026-625693.44.0Oracle CorporationOracle Hyperion Infrastructure TechnologyCWE-284Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-476305.53.9NVIDIATriton Inference ServerCWE-36NVIDIA Triton Inference Server for Linux contains a vulnerability where an at…
CVE-2026-273655.93.8PublishPressPublishPress SeriesCWE-79WordPress PublishPress Series plugin <= 2.17.0 - Cross Site Scripting (XSS) v…
CVE-2026-739745.53.8Linuxfabrikmonitoring-pluginsCWE-22linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftes…
CVE-2026-749675.43.8MozillaFirefoxCWE-346Same-origin policy bypass in the Audio/Video: Playback component
CVE-2026-451294.63.7mybbmybbCWE-352MyBB: ACP Recovery Codes CSRF
CVE-2026-74980await3.7MozillaFirefoxClickjacking issue in the Downloads component in Firefox for Android
CVE-2026-708067.13.7Oracle CorporationOracle E-Business TaxVulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite…
CVE-2026-709147.03.6Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-665895.43.6Kings PluginsB2BKingCWE-862WordPress B2BKing plugin <= 5.2.30 - Broken Access Control vulnerability
CVE-2026-709623.33.6Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-754855.53.5Red HatRed Hat Advanced Cluster Management for Kubernetes 2CWE-532Must-gather: must-gather: cluster proxy object dumped raw, bypassing inspect …
CVE-2026-706676.33.5NetflixlemurCWE-367Lemur: SSRF protection in certificate revocation checking bypassable via HTTP…
CVE-2026-667838.23.4Red HatRed Hat Advanced Cluster Management for Kubernetes 2CWE-20Submariner-operator: submariner-operator: arbitrary image override enables pr…
CVE-2026-451263.53.2mybbmybbCWE-352MyBB: ACP Questions state CSRF
CVE-2026-451273.53.2mybbmybbCWE-352MyBB: ACP Mass Mail draft resend CSRF
CVE-2026-451283.53.2mybbmybbCWE-352MyBB: ACP Users View Manager default CSRF
CVE-2026-609027.03.1Oracle CorporationPeopleSoft Enterprise PeopleToolsVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop…
CVE-2026-624497.03.1Oracle CorporationOracle Work in ProcessVulnerability in the Oracle Work in Process product of Oracle E-Business Suit…
CVE-2026-451194.62.9mybbmybbCWE-352MyBB: ACP UTF-8 Conversion CSRF
CVE-2026-241837.82.8NVIDIACumulus Linux GACWE-250NVIDIA Cumulus Linux contains a vulnerability in the user management componen…
CVE-2026-707987.82.8Oracle CorporationOracle PurchasingVulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co…
CVE-2026-711167.52.8Oracle CorporationOracle VM VirtualBoxCWE-284Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-711177.52.8Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-707057.12.8Oracle CorporationOracle Hyperion Calculation ManagerVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-707126.42.8Oracle CorporationOracle Agile Engineering Data ManagementVulnerability in the Oracle Agile Engineering Data Management product of Orac…
CVE-2026-711196.42.8Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-326577.32.7DellAppSyncCWE-61Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Ve…
CVE-2026-551654.82.7NetflixlemurCWE-347Lemur : JWT verifier trusts attacker-supplied alg from token header — defense…
CVE-2026-625844.02.7Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-709164.02.7Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-709327.22.7Oracle CorporationOracle Order ManagementVulnerability in the Oracle Order Management product of Oracle E-Business Sui…
CVE-2026-709027.12.6Oracle CorporationOracle Hyperion Data Relationship ManagementVulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-625586.32.6Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-711325.32.7Oracle CorporationOracle VM VirtualBoxVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-706857.92.6Oracle CorporationOracle Hyperion Calculation ManagerVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-749635.42.5MozillaFirefoxCWE-346Same-origin policy bypass in the Networking: Cookies component
CVE-2026-501264.02.6KNMIadaguc-serverCWE-125adaguc-server GeoJSON coordinate parser (CConvertGeoJSON.cpp) vulnerable to o…
CVE-2026-707113.62.5Oracle CorporationOracle Hyperion Calculation ManagerVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-709192.52.5Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-711298.22.5Oracle CorporationOracle VM VirtualBoxVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-625703.02.5Oracle CorporationOracle Hyperion Infrastructure TechnologyCWE-284Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-625833.02.5Oracle CorporationOracle Hyperion Infrastructure TechnologyCWE-284Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-708797.82.3Oracle CorporationOracle Hyperion Data Relationship ManagementVulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-711267.82.3Oracle CorporationOracle VM VirtualBoxVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-709927.02.3Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-710417.02.3Oracle CorporationOracle Agile PLMCWE-284Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone…
CVE-2026-708415.62.4Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-758577.32.3HmbownCodeWhaleCWE-269CodeWhale before 0.8.64 Privilege Escalation via exec_shell_interact
CVE-2026-608737.22.2Oracle CorporationPeopleSoft Enterprise PeopleToolsCWE-284Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop…
CVE-2026-710136.02.3Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-608087.52.2Oracle CorporationSiebel Apps - MarketingVulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co…
CVE-2026-707585.32.1Oracle CorporationOracle Hyperion Financial ReportingVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-707845.32.1Oracle CorporationOracle Hyperion Financial ReportingVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-759044.82.1Konstanty BialkowskilibmodplugCWE-125libmodplug <= 0.8.9.1 - Out-of-Bounds Read in pat_smplooped via Crafted MIDI …
CVE-2026-707144.12.0Oracle CorporationOracle Hyperion Calculation ManagerVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-711443.02.1Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-710811.92.1Oracle CorporationOracle Agile PLM MCAD ConnectorCWE-284Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply…
CVE-2026-710468.82.0Oracle CorporationOracle Agile PLMCWE-284Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone…
CVE-2026-613007.82.0Oracle CorporationOracle Enterprise Manager Base PlatformVulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-625817.82.0Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-711017.82.0Oracle CorporationOracle HRMS (US)CWE-284Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (com…
CVE-2026-625735.52.0Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-711461.92.0Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-612985.62.0Oracle CorporationOracle Enterprise Manager Base PlatformVulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-711515.62.0Oracle CorporationOracle VM VirtualBoxVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-709125.31.9Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-613397.31.8Oracle CorporationSiebel CRM Cloud ApplicationsVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-625367.11.9Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-710664.51.9Oracle CorporationOracle Agile PLM MCAD ConnectorCWE-284Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply…
CVE-2026-710831.81.9Oracle CorporationOracle Agile PLM MCAD ConnectorCWE-284Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply…
CVE-2026-578269.81.8n/an/aCWE-295An issue was discovered in openHiTLS 0.2.0 through 0.3.2. In the X.509 certif…
CVE-2026-710947.31.7Oracle CorporationOracle Business Intelligence Enterprise EditionCWE-284Vulnerability in the Oracle Business Intelligence Enterprise Edition product …
CVE-2026-711276.01.6Oracle CorporationOracle VM VirtualBoxVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-711376.01.6Oracle CorporationOracle VM VirtualBoxCWE-284Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-710335.51.7Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-749685.41.7MozillaFirefoxCWE-346Site isolation issue in the Graphics: WebRender component
CVE-2026-710822.51.7Oracle CorporationOracle Agile PLM MCAD ConnectorCWE-284Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply…
CVE-2026-597815.41.6ZabbixZabbixCWE-427Improper validation of custom installation directories on Windows could allow…
CVE-2026-711403.41.6Oracle CorporationOracle VM VirtualBoxCWE-284Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-711546.11.5Oracle CorporationHelidonVulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-187515.21.5CitrixWorkSpace AppCWE-73Citrix Workspace App for Mac Security Bulletin for CVE-2026-18751
CVE-2026-707318.41.4Oracle CorporationOracle Autonomous Health FrameworkVulnerability in Oracle Autonomous Health Framework (component: Trace File An…
CVE-2026-706936.31.4Oracle CorporationOracle Agile Engineering Data ManagementVulnerability in the Oracle Agile Engineering Data Management product of Orac…
CVE-2026-625773.31.4Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-609757.51.3Oracle CorporationPeopleSoft Enterprise PeopleToolsVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop…
CVE-2026-614078.81.2DellWatchdog Timer DriverCWE-698Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL…
CVE-2026-707967.21.1Oracle CorporationOracle General LedgerVulnerability in the Oracle General Ledger product of Oracle E-Business Suite…
CVE-2026-710784.21.1Oracle CorporationOracle Agile PLM MCAD ConnectorCWE-284Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply…
CVE-2026-711494.21.1Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-710723.31.1Oracle CorporationOracle Agile PLM MCAD ConnectorCWE-284Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply…
CVE-2026-714776.71.1jdxmiseCWE-278mise: Incorrect file ownership, when installed by the root user using `instal…
CVE-2026-708503.01.0Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-706977.01.0Oracle CorporationOracle Agile Engineering Data ManagementVulnerability in the Oracle Agile Engineering Data Management product of Orac…
CVE-2026-710987.01.0Oracle CorporationOracle Business Intelligence Enterprise EditionCWE-284Vulnerability in the Oracle Business Intelligence Enterprise Edition product …
CVE-2026-625754.71.0Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-710927.50.9Oracle CorporationPeopleSoft Enterprise FIN Lease AdministrationCWE-284Vulnerability in the PeopleSoft Enterprise FIN Lease Administration product o…
CVE-2026-599157.30.9DellAlienware Command Center (AWCC)CWE-272Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a …
CVE-2026-625113.00.9Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-609947.20.7Oracle CorporationOracle Identity Manager ConnectorVulnerability in the Oracle Identity Manager Connector product of Oracle Fusi…
CVE-2026-707944.70.7Oracle CorporationOracle Hyperion Financial ReportingVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-711054.70.6Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-667827.80.3Red HatRed Hat Advanced Cluster Management for Kubernetes 2CWE-312Submariner-operator: submariner-operator: broker api bearer token stored clea…
CVE-2026-714177.30.3NetflixlemurCWE-639Lemur: Any user can revoke arbitrary certificates at the CA by uploading a du…
CVE-2026-667816.50.2Red HatRed Hat Advanced Cluster Management for Kubernetes 2CWE-312Submariner-operator: submariner-operator: ipsec psk stored cleartext in subma…
CVE-2026-713176.50.2NetflixlemurCWE-862Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent autho…
CVE-2026-495006.00.2DellAlienware Command Center (AWCCCWE-272Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an…
CVE-2026-738345.50.2Red HatRed Hat Advanced Cluster Management for Kubernetes 2CWE-312Must-gather: must-gather: embedded secret data in acm wrapper crs collected w…