Security Box Score — September 15, 2026 — page 2
Edition of September 15, 2026, continued — page 2 of 3. Back to page 1 · page 3
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-92062 | 8.8 | — | Mozilla | Firefox | CWE-269 | Privilege escalation in the Session Restore component |
| CVE-2026-92073 | 8.8 | — | Mozilla | Firefox | CWE-269 | Privilege escalation in the Enterprise Policies component |
| CVE-2026-18110 | 8.7 | — | Concrete CMS | Concrete CMS | CWE-862 | Concrete CMS 9.0.0 through 9.5.2 is vulnerable to missing authorization in th… |
| CVE-2026-54251 | 8.7 | — | netty | netty-incubator-codec-ohttp | CWE-664 | netty-incubator-codec-ohttp: [OHttpServerCodec] Native Direct-Memory Leak on … |
| CVE-2026-55887 | 8.7 | — | docker | mcp-gateway | CWE-88 | MCP Gateway: Argument injection via OCI image label YAML in Docker MCP Gateway |
| CVE-2026-58201 | 8.7 | — | merill | lokka | CWE-918 | Lokka: Azure Resource Manager URL path validation issue |
| CVE-2026-68070 | 8.7 | — | Digital Watchdog | VMAX A1 G4 DVR | CWE-306 | Missing Authentication for Critical Function in Digital Watchdog VMAX DVR and… |
| CVE-2026-68950 | 8.7 | — | Digital Watchdog | VMAX A1 G4 DVR | CWE-798 | Use of Hard-coded Credentials in Digital Watchdog VMAX DVR and NVR Product Li… |
| CVE-2026-69205 | 8.7 | — | http4s | http4s | CWE-444 | Http4s: Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling) |
| CVE-2026-69217 | 8.7 | — | http4s | http4s | CWE-444 | Http4s: Ember Server accepts duplicate Content-Length headers |
| CVE-2026-73926 | 8.7 | — | Oracle Corporation | Oracle Access Manager | — | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-76852 | 8.7 | — | Netcore | NR268 | CWE-354 | Netcore NR268 1.7.121109 Forgeable Firmware Authenticity Check in mtd_write |
| CVE-2026-76860 | 8.7 | — | Netcore | NR255-V | CWE-121 | Netcore NR255-V 1.5.130703 Stack-Based Buffer Overflow in wake_up_set.cgi via… |
| CVE-2026-76861 | 8.7 | — | Netcore | NR255-V | CWE-121 | Netcore NR255-V 1.5.130703 Stack-Based Buffer Overflow in ntools_tcpdump_star… |
| CVE-2026-76862 | 8.7 | — | Netcore | NR255-V | CWE-88 | Netcore NR255-V 1.5.130703 OS Command Argument Injection in Nettools tcpdump … |
| CVE-2026-79994 | 8.7 | — | Docker | Docker Sandboxes | CWE-367 | Docker Sandboxes UDS forwarder can reach arbitrary host Unix sockets through … |
| CVE-2026-81567 | 8.7 | — | j2commerce.com | J2Store extension for Joomla | CWE-89 | Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in th… |
| CVE-2026-81568 | 8.7 | — | j2commerce.com | J2Store extension for Joomla | CWE-22 | Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` i… |
| CVE-2026-82189 | 8.7 | — | j2commerce.com | J2Store extension for Joomla | CWE-472 | Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone … |
| CVE-2026-83025 | 8.7 | — | Oracle Corporation | Oracle Identity Manager Connector | — | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-83135 | 8.7 | — | Oracle Corporation | Oracle iStore | — | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (compon… |
| CVE-2026-83144 | 8.7 | — | Oracle Corporation | Siebel Apps - Customer Order Management | — | Vulnerability in the Siebel Apps - Customer Order Management product of Oracl… |
| CVE-2026-83145 | 8.7 | — | Oracle Corporation | Siebel Apps - Customer Order Management | — | Vulnerability in the Siebel Apps - Customer Order Management product of Oracl… |
| CVE-2026-83310 | 8.7 | — | Oracle Corporation | Oracle BI Publisher | — | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-87171 | 8.7 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87178 | 8.7 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87791 | 8.7 | — | Developers Italia | design-scuole-wordpress-theme | CWE-22 | Path traversal vulnerability in WordPress theme design-scuole-wordpress-theme |
| CVE-2026-87792 | 8.7 | — | Developers Italia | design-scuole-wordpress-theme | CWE-200 | Multiple authorization bypass in WordPress theme design-scuole-wordpress-theme |
| CVE-2026-89025 | 8.7 | — | Belden | Hirschmann HiOS Switch Platform | CWE-755 | Hirschmann HiOS Switch Platform DoS via Malformed HTTP Request |
| CVE-2026-91925 | 8.7 | — | polyaxon | polyaxon | CWE-1336 | Polyaxon through 2.16.4 Server-Side Template Injection via Unsandboxed Jinja2… |
| CVE-2026-91934 | 8.7 | — | FlowiseAI | Flowise | CWE-22 | Flowise before 3.1.4 Remote Code Execution via SQL Database Chain |
| CVE-2026-91935 | 8.7 | — | FlowiseAI | Flowise | CWE-918 | Flowise before 3.1.4 SSRF and API Key Exfiltration via Chat Model Nodes |
| CVE-2026-91937 | 8.7 | — | FlowiseAI | Flowise | CWE-943 | Flowise before 3.1.4 NoSQL Injection via sessionId |
| CVE-2026-91940 | 8.7 | — | unclecode | crawl4ai | CWE-22 | crawl4ai before 0.9.3 Arbitrary File Write via PDFContentScrapingStrategy |
| CVE-2026-91941 | 8.7 | — | unclecode | crawl4ai | CWE-400 | Crawl4AI before 0.9.3 Denial of Service via PDFContentScrapingStrategy |
| CVE-2026-91964 | 8.7 | — | FreeRDP | FreeRDP | CWE-122 | FreeRDP 2.0.0 through 3.30.0 Heap Buffer Overflow via RoutingToken |
| CVE-2026-91965 | 8.7 | — | WWBN | AVideo | CWE-200 | WWBN AVideo through 29.0 Broken Access Control via Live Endpoints |
| CVE-2026-91972 | 8.7 | — | go-vikunja | vikunja | CWE-307 | Vikunja before 2.6.0 Authentication Bypass via Unthrottled API |
| CVE-2026-91973 | 8.7 | — | go-vikunja | vikunja | CWE-307 | Vikunja before 2.6.0 Authentication Bypass via CalDAV BasicAuth |
| CVE-2026-91985 | 8.7 | — | go-vikunja | vikunja | CWE-200 | Vikunja before 2.6.0 Privilege Escalation via Link Share Hash |
| CVE-2026-91989 | 8.7 | — | dep0we | atomic-agents-stack | CWE-22 | atomic-agents-stack before 1.1.0 Path Traversal via dashboard serve.py |
| CVE-2026-91990 | 8.7 | — | tornadoweb | tornado | CWE-770 | Tornado before 6.5.8 Memory Amplification DoS via multipart |
| CVE-2026-91996 | 8.7 | — | dromara | lamp-cloud | CWE-306 | lamp-cloud through 5.10.0 Missing Authentication for JVM Properties Endpoint |
| CVE-2026-92000 | 8.7 | — | cthackers | adm-zip | CWE-409 | adm-zip 0.5.14 through 0.6.0 Denial of Service via Zero Declared Uncompressed… |
| CVE-2026-55691 | 8.6 | — | StarCitizenWiki | mediawiki-extensions-EmbedVideo | CWE-79 | EmbedVideo Extension : Stored XSS via unsanitized class passed to template |
| CVE-2026-57586 | 8.6 | — | naranor | agent-coderag | CWE-78 | CodeRAG: Gradle Wrapper Execution During Dependency Discovery Enables Arbitra… |
| CVE-2026-73941 | 8.6 | — | Oracle Corporation | Oracle Access Manager | — | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-76679 | 8.6 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | — | Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConne… |
| CVE-2026-76866 | 8.6 | — | Netcore | NR255-V | CWE-88 | Netcore NR255-V 1.5.130703 OS Command Argument Injection via Unquoted DDNS Pa… |
| CVE-2026-76869 | 8.6 | — | Netcore | NR255-V | CWE-121 | Netcore NR255-V 1.5.130703 Stack-Based Buffer Overflow in reboot_timer_set.cgi |
| CVE-2026-81236 | 8.6 | — | Dell | Wyse Management Suite | CWE-434 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrest… |
| CVE-2026-81239 | 8.6 | — | Dell | Wyse Management Suite | CWE-434 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrest… |
| CVE-2026-81240 | 8.6 | — | Dell | Wyse Management Suite | CWE-434 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrest… |
| CVE-2026-83023 | 8.6 | — | Oracle Corporation | Oracle Identity Manager Connector | — | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-83074 | 8.6 | — | Oracle Corporation | Siebel CRM Cloud Applications | — | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-83093 | 8.6 | — | Oracle Corporation | Oracle Forms | — | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (compon… |
| CVE-2026-83203 | 8.6 | — | Oracle Corporation | Siebel CRM End User | — | Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (compon… |
| CVE-2026-83284 | 8.6 | — | Oracle Corporation | Oracle BI Publisher | — | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-83305 | 8.6 | — | Oracle Corporation | Oracle BI Publisher | — | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-87273 | 8.6 | — | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-11729 | 8.5 | — | IBM | MQ | CWE-502 | IBM MQ Java messaging is vulnerable to remote code execution |
| CVE-2026-18111 | 8.5 | — | Concrete CMS | Concrete CMS | CWE-306 | Concrete CMS below 9.5.4 allows privilege escalation because adding users and… |
| CVE-2026-59973 | 8.5 | — | agentfront | frontmcp | CWE-918 | mcp-from-openapi: Bypass of OpenAPI external $ref SSRF fix in latest FrontMCP… |
| CVE-2026-76680 | 8.5 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | — | Authenticated Server-Side Request Forgery Vulnerabilities Leading to Informat… |
| CVE-2026-76681 | 8.5 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | — | Authenticated Information Disclosure Vulnerability in HPE Networking EdgeConn… |
| CVE-2026-81894 | 8.5 | — | Concrete CMS | Concrete CMS | CWE-89 | Concrete CMS 9.5.2 and below is vulnerable to Stored DOM-based Cross-site Scr… |
| CVE-2026-81895 | 8.5 | — | Concrete CMS | Concrete CMS | CWE-89 | Concrete CMS 9.5.2 and below is vulnerable to Stored SQL Injection in Concret… |
| CVE-2026-82993 | 8.5 | — | Oracle Corporation | PeopleSoft Enterprise PeopleTools | — | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-83002 | 8.5 | — | Oracle Corporation | Oracle Access Manager | — | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-83003 | 8.5 | — | Oracle Corporation | Oracle WebCenter Enterprise Capture | — | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-83007 | 8.5 | — | Oracle Corporation | Oracle WebCenter Enterprise Capture | — | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-83045 | 8.5 | — | Oracle Corporation | Oracle WebCenter Portal | — | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-83049 | 8.5 | — | Oracle Corporation | Oracle WebCenter Portal | — | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-83083 | 8.5 | — | Oracle Corporation | Oracle Marketing | — | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (com… |
| CVE-2026-83172 | 8.5 | — | Oracle Corporation | Oracle Sales Online | — | Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (… |
| CVE-2026-83267 | 8.5 | — | Oracle Corporation | Oracle BI Publisher | — | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-83272 | 8.5 | — | Oracle Corporation | Oracle Database Server | — | Vulnerability in the Oracle Text component of Oracle Database Server. Support… |
| CVE-2026-83302 | 8.5 | — | Oracle Corporation | Oracle BI Publisher | — | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-83303 | 8.5 | — | Oracle Corporation | Oracle BI Publisher | — | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-83309 | 8.5 | — | Oracle Corporation | Oracle BI Publisher | — | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-83311 | 8.5 | — | Oracle Corporation | Oracle BI Publisher | — | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-83321 | 8.5 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83425 | 8.5 | — | Oracle Corporation | Oracle Complex Maintenance, Repair and Overhaul | — | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product … |
| CVE-2026-83449 | 8.5 | — | Oracle Corporation | Oracle Bills of Material | — | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Su… |
| CVE-2026-83451 | 8.5 | — | Oracle Corporation | Oracle Product Workbench | — | Vulnerability in the Oracle Product Workbench product of Oracle E-Business Su… |
| CVE-2026-83490 | 8.5 | — | Oracle Corporation | Oracle iRecruitment | — | Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (… |
| CVE-2026-87161 | 8.5 | — | Oracle Corporation | Oracle HRMS (India) | — | Vulnerability in the Oracle HRMS (India) product of Oracle E-Business Suite (… |
| CVE-2026-87177 | 8.5 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-88765 | 8.5 | — | GitLab | GitLab | CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injec… |
| CVE-2026-57441 | 8.4 | — | bitbonsai | mcpvault | CWE-41 | MCPVault: PathFilter restricted-directory deny-list bypass via case and trail… |
| CVE-2026-81896 | 8.4 | — | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS below version 9.5.3 is vulnerable to Stored XSS in Concrete CMS … |
| CVE-2026-83264 | 8.4 | — | Oracle Corporation | Oracle Product Lifecycle Analytics | — | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Sup… |
| CVE-2026-87219 | 8.4 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87259 | 8.4 | — | Oracle Corporation | Oracle Agile Engineering Data Management | — | Vulnerability in the Oracle Agile Engineering Data Management product of Orac… |
| CVE-2026-91924 | 8.4 | — | sosedoff | pgweb | CWE-862 | pgweb through 0.17.0 Missing Authorization on Direct Connect Endpoint |
| CVE-2026-1758 | 8.3 | — | Secomea | GateManager | CWE-384 | Session Fixation |
| CVE-2026-54549 | 8.3 | — | pipeboard-co | meta-ads-mcp | CWE-918 | Meta Ads MCP: Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unr… |
| CVE-2026-63443 | 8.3 | — | coder | coder | CWE-863 | Coder: Workspace agent API insecure redirect handling allowed cross-agent fil… |
| CVE-2026-83026 | 8.3 | — | Oracle Corporation | Oracle Identity Manager Connector | — | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-83030 | 8.3 | — | Oracle Corporation | Oracle Managed File Transfer | — | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Mi… |
| CVE-2026-83285 | 8.3 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83307 | 8.3 | — | Oracle Corporation | Oracle BI Publisher | — | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-87125 | 8.3 | — | Oracle Corporation | Oracle Financials for Asia/Pacific | — | Vulnerability in the Oracle Financials for Asia/Pacific product of Oracle E-B… |
| CVE-2026-87210 | 8.3 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-91712 | 8.3 | — | Chrome | CWE-367 | Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.4… | |
| CVE-2026-91724 | 8.3 | — | Chrome | CWE-416 | Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a rem… | |
| CVE-2026-91733 | 8.3 | — | Chrome | CWE-754 | Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 all… | |
| CVE-2026-91735 | 8.3 | — | Chrome | CWE-863 | Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allo… | |
| CVE-2026-91743 | 8.3 | — | Chrome | CWE-367 | Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remo… | |
| CVE-2026-91748 | 8.3 | — | Chrome | CWE-367 | Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.4… | |
| CVE-2026-91923 | 8.3 | — | kubesphere | kubesphere | CWE-918 | KubeSphere through 4.1.3 SSRF via git credential verification endpoint |
| CVE-2026-91936 | 8.3 | — | FlowiseAI | Flowise | CWE-78 | Flowise before 3.1.4 Script Injection via Docker Workflows |
| CVE-2026-91943 | 8.3 | — | unclecode | crawl4ai | CWE-918 | Crawl4AI before 0.9.3 SSRF via PDFContentScrapingStrategy |
| CVE-2026-54167 | 8.2 | — | tektoncd | pipelines-as-code | CWE-345 | Pipelines-as-Code GitHub App token request can be redirected via untrusted En… |
| CVE-2026-61544 | 8.2 | — | libp2p | rust-libp2p | CWE-248 | libp2p-quic: Remote panic via certificate expiry race during QUIC handshake |
| CVE-2026-76682 | 8.2 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | — | Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConne… |
| CVE-2026-83047 | 8.2 | — | Oracle Corporation | Oracle WebCenter Portal | — | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-83078 | 8.2 | — | Oracle Corporation | Siebel CRM Cloud Applications | — | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-83085 | 8.2 | — | Oracle Corporation | Siebel CRM Cloud Applications | — | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-83087 | 8.2 | — | Oracle Corporation | Siebel CRM Cloud Applications | — | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-83181 | 8.2 | — | Oracle Corporation | Siebel CRM Development | — | Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (com… |
| CVE-2026-83215 | 8.2 | — | Oracle Corporation | Siebel CRM Deployment | — | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-83234 | 8.2 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83236 | 8.2 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83248 | 8.2 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83265 | 8.2 | — | Oracle Corporation | Oracle Web Services Manager | — | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Mid… |
| CVE-2026-83266 | 8.2 | — | Oracle Corporation | Oracle JDeveloper | — | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (c… |
| CVE-2026-83343 | 8.2 | — | Oracle Corporation | Oracle Utilities Network Management System | — | Vulnerability in the Oracle Utilities Network Management System product of Or… |
| CVE-2026-83418 | 8.2 | — | Oracle Corporation | Oracle Communications Cloud Native Core Security Edge Protection Proxy | — | Vulnerability in the Oracle Communications Cloud Native Core Security Edge Pr… |
| CVE-2026-83435 | 8.2 | — | Oracle Corporation | Oracle Bills of Material | — | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Su… |
| CVE-2026-83438 | 8.2 | — | Oracle Corporation | Oracle Engineering | — | Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (c… |
| CVE-2026-83461 | 8.2 | — | Oracle Corporation | Oracle Mobile Application Server | — | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Bus… |
| CVE-2026-83465 | 8.2 | — | Oracle Corporation | Oracle Mobile Application Server | — | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Bus… |
| CVE-2026-87174 | 8.2 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87196 | 8.2 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87197 | 8.2 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87200 | 8.2 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87228 | 8.2 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87229 | 8.2 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87266 | 8.2 | — | Oracle Corporation | Oracle Agile PLM | — | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-91955 | 8.2 | — | FreeRDP | FreeRDP | CWE-369 | FreeRDP before 3.31.0 Denial of Service via Desktop Dimensions |
| CVE-2026-91992 | 8.2 | — | tornadoweb | tornado | CWE-200 | Tornado before 6.5.7 Credential Leak via Handle Reuse |
| CVE-2026-11728 | 8.1 | — | IBM | MQ | CWE-787 | IBM MQ .NET client is vulnerable to remote code execution |
| CVE-2026-12355 | 8.1 | — | IBM | MQ | CWE-74 | IBM MQ Resource Adapter IVT servlet is vulnerable to unauthenticated remote c… |
| CVE-2026-12666 | 8.1 | — | IBM | MQ | CWE-611 | IBM MQ Java messaging is vulnerable to XML external entity injection |
| CVE-2026-16141 | 8.1 | — | OpenBMC | phosphor-net-ipmid | CWE-457 | OpenBMC IPMI Authentication Bypass via Default userKey and Stale Challenge Value |
| CVE-2026-54076 | 8.1 | — | ArcadeData | arcadedb | CWE-862 | ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2… |
| CVE-2026-56825 | 8.1 | — | shopperlabs | shopper | CWE-862 | Shopper: Missing authorization on product removal actions in CollectionProduc… |
| CVE-2026-56827 | 8.1 | — | shopperlabs | shopper | CWE-862 | Shopper: Authorization bypass in Filament bulk actions allows browse-only sta… |
| CVE-2026-56829 | 8.1 | — | shopperlabs | shopper | CWE-862 | Shopper: Unauthorized inventory stock manipulation via unlocked variant prope… |
| CVE-2026-61668 | 8.1 | — | DIRACGrid | DIRAC | CWE-295 | DIRAC: Pilot code downloaded over unverified HTTPS connection |
| CVE-2026-73951 | 8.1 | — | Oracle Corporation | Oracle WebCenter Portal | — | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-73954 | 8.1 | — | Oracle Corporation | PeopleSoft Enterprise PeopleTools | — | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-73958 | 8.1 | — | Oracle Corporation | Oracle Access Manager | — | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-76683 | 8.1 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | — | Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution… |
| CVE-2026-76684 | 8.1 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | — | Authentication Bypass Vulnerabilities in HPE Networking EdgeConnect SD-WAN Or… |
| CVE-2026-76685 | 8.1 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | — | Unauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution … |
| CVE-2026-79410 | 8.1 | — | n/a | n/a | CWE-20 | Improper validation of the quantity parameter in the add-to-cart path of Webk… |
| CVE-2026-79425 | 8.1 | — | n/a | n/a | CWE-918 | An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/onl… |
| CVE-2026-83010 | 8.1 | — | Oracle Corporation | Oracle WebCenter Enterprise Capture | — | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-83011 | 8.1 | — | Oracle Corporation | Oracle Platform Security for Java | — | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi… |
| CVE-2026-83014 | 8.1 | — | Oracle Corporation | PeopleSoft Enterprise PeopleTools | — | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-83019 | 8.1 | — | Oracle Corporation | PeopleSoft Enterprise PeopleTools | — | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-83067 | 8.1 | — | Oracle Corporation | Oracle JDeveloper | — | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (c… |
| CVE-2026-83072 | 8.1 | — | Oracle Corporation | Oracle Applications Framework | — | Vulnerability in the Oracle Applications Framework product of Oracle E-Busine… |
| CVE-2026-83073 | 8.1 | — | Oracle Corporation | Siebel CRM Cloud Applications | — | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-83089 | 8.1 | — | Oracle Corporation | Oracle Alert | — | Vulnerability in the Oracle Alert product of Oracle E-Business Suite (compone… |
| CVE-2026-83101 | 8.1 | — | Oracle Corporation | Oracle Forms | — | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (compon… |
| CVE-2026-83132 | 8.1 | — | Oracle Corporation | Oracle iStore | — | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (compon… |
| CVE-2026-83143 | 8.1 | — | Oracle Corporation | Siebel Apps - Life Sciences | — | Vulnerability in the Siebel Apps - Life Sciences product of Oracle Siebel CRM… |
| CVE-2026-83152 | 8.1 | — | Oracle Corporation | Oracle Project Intelligence | — | Vulnerability in the Oracle Project Intelligence product of Oracle E-Business… |
| CVE-2026-83169 | 8.1 | — | Oracle Corporation | Oracle One-to-One Fulfillment | — | Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Busine… |
| CVE-2026-83174 | 8.1 | — | Oracle Corporation | Oracle CRM Technical Foundation | — | Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Busi… |
| CVE-2026-83177 | 8.1 | — | Oracle Corporation | Oracle One-to-One Fulfillment | — | Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Busine… |
| CVE-2026-83191 | 8.1 | — | Oracle Corporation | Siebel CRM Deployment | — | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-83192 | 8.1 | — | Oracle Corporation | Siebel CRM End User | — | Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (compon… |
| CVE-2026-83220 | 8.1 | — | Oracle Corporation | Siebel CRM Integration | — | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-83245 | 8.1 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83246 | 8.1 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83254 | 8.1 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83255 | 8.1 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83256 | 8.1 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83258 | 8.1 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83286 | 8.1 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83297 | 8.1 | — | Oracle Corporation | Oracle BI Publisher | — | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-83299 | 8.1 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83308 | 8.1 | — | Oracle Corporation | Oracle BI Publisher | — | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-83314 | 8.1 | — | Oracle Corporation | Oracle BI Publisher | — | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-83351 | 8.1 | — | Oracle Corporation | Oracle Database Server | — | Vulnerability in the RDBMS component of Oracle Database Server. Supported ver… |
| CVE-2026-83357 | 8.1 | — | Oracle Corporation | Oracle GraalVM for JDK, Oracle GraalVM | — | Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle… |
| CVE-2026-83408 | 8.1 | — | Oracle Corporation | Oracle GraalVM for JDK, Oracle GraalVM | — | Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle… |
| CVE-2026-83412 | 8.1 | — | Oracle Corporation | Oracle Coherence | — | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-83422 | 8.1 | — | Oracle Corporation | Oracle Identity Manager | — | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-83428 | 8.1 | — | Oracle Corporation | Oracle Demand Signal Repository | — | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Busi… |
| CVE-2026-83429 | 8.1 | — | Oracle Corporation | Oracle Demand Signal Repository | — | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Busi… |
| CVE-2026-83430 | 8.1 | — | Oracle Corporation | Oracle Product Workbench | — | Vulnerability in the Oracle Product Workbench product of Oracle E-Business Su… |
| CVE-2026-83432 | 8.1 | — | Oracle Corporation | Oracle Depot Repair | — | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (… |
| CVE-2026-83434 | 8.1 | — | Oracle Corporation | Oracle Product Workbench | — | Vulnerability in the Oracle Product Workbench product of Oracle E-Business Su… |
| CVE-2026-83439 | 8.1 | — | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-83446 | 8.1 | — | Oracle Corporation | Oracle Financials Common Modules | — | Vulnerability in the Oracle Financials Common Modules product of Oracle E-Bus… |
| CVE-2026-83447 | 8.1 | — | Oracle Corporation | Oracle Bills of Material | — | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Su… |
| CVE-2026-83448 | 8.1 | — | Oracle Corporation | Oracle Bills of Material | — | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Su… |
| CVE-2026-83455 | 8.1 | — | Oracle Corporation | Oracle Demand Signal Repository | — | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Busi… |
| CVE-2026-83457 | 8.1 | — | Oracle Corporation | Oracle Demand Signal Repository | — | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Busi… |
| CVE-2026-83464 | 8.1 | — | Oracle Corporation | Oracle Mobile Application Server | — | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Bus… |
| CVE-2026-83477 | 8.1 | — | Oracle Corporation | Oracle Work in Process | — | Vulnerability in the Oracle Work in Process product of Oracle E-Business Suit… |
| CVE-2026-87152 | 8.1 | — | Oracle Corporation | Oracle Installed Base | — | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite… |
| CVE-2026-87153 | 8.1 | — | Oracle Corporation | Oracle Product Hub | — | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c… |
| CVE-2026-87154 | 8.1 | — | Oracle Corporation | Oracle Product Hub | — | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c… |
| CVE-2026-87157 | 8.1 | — | Oracle Corporation | Oracle Order Management | — | Vulnerability in the Oracle Order Management product of Oracle E-Business Sui… |
| CVE-2026-87159 | 8.1 | — | Oracle Corporation | Oracle HRMS (India) | — | Vulnerability in the Oracle HRMS (India) product of Oracle E-Business Suite (… |
| CVE-2026-87166 | 8.1 | — | Oracle Corporation | Oracle Purchasing | — | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co… |
| CVE-2026-87167 | 8.1 | — | Oracle Corporation | Oracle Purchasing | — | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co… |
| CVE-2026-87168 | 8.1 | — | Oracle Corporation | Oracle Purchasing | — | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co… |
| CVE-2026-87218 | 8.1 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87231 | 8.1 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87232 | 8.1 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87234 | 8.1 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87241 | 8.1 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87265 | 8.1 | — | Oracle Corporation | Oracle Purchasing | — | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co… |
| CVE-2026-87286 | 8.1 | — | Oracle Corporation | Oracle GraalVM | — | Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Com… |
| CVE-2026-87287 | 8.1 | — | Oracle Corporation | Oracle GraalVM | — | Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Com… |
| CVE-2026-87288 | 8.1 | — | Oracle Corporation | Oracle GraalVM | — | Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Com… |
| CVE-2026-88619 | 8.1 | — | n/a | n/a | CWE-862 | 1024-lab SmartAdmin v3.30.0 contains a missing authorization vulnerability in… |
| CVE-2026-91727 | 8.1 | — | Chrome | CWE-706 | Incorrect reference resolution in Extensions in Google Chrome on on Mac prior… | |
| CVE-2026-55225 | 8.0 | — | strimzi | strimzi-kafka-operator | CWE-269 | Strimzi: Cross-namespace privilege escalation via `Kafka.spec.entityOperator` |
| CVE-2026-55343 | 8.0 | — | Android | CWE-120 | In decodeAmr of ImsMediaAudioPlayer.cpp, there is a possible out-of-bounds wr… | |
| CVE-2026-56967 | 8.0 | — | Android | CWE-122 | In Cellular Modem, there is a possible out-of-bounds write due to a heap buff… | |
| CVE-2026-58704 | 8.0 | — | Android | CWE-285 | In Cellular Modem, there is a possible permission bypass due to a logic error… | |
| CVE-2026-81235 | 8.0 | — | Dell | Wyse Management Suite | CWE-325 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing… |
| CVE-2026-83081 | 8.0 | — | Oracle Corporation | Oracle Banking Corporate Lending | — | Vulnerability in the Oracle Banking Corporate Lending product of Oracle Finan… |
| CVE-2026-83138 | 8.0 | — | Oracle Corporation | Oracle Spares Management | — | Vulnerability in the Oracle Spares Management product of Oracle E-Business Su… |
| CVE-2026-83157 | 8.0 | — | Oracle Corporation | Oracle Applications Manager | — | Vulnerability in the Oracle Applications Manager product of Oracle E-Business… |
| CVE-2026-83170 | 8.0 | — | Oracle Corporation | Oracle One-to-One Fulfillment | — | Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Busine… |
| CVE-2026-83178 | 8.0 | — | Oracle Corporation | Oracle Application Object Library | — | Vulnerability in the Oracle Application Object Library product of Oracle E-Bu… |
| CVE-2026-83450 | 8.0 | — | Oracle Corporation | Oracle Bills of Material | — | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Su… |
| CVE-2026-83483 | 8.0 | — | Oracle Corporation | Oracle Advanced Benefits | — | Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Su… |
| CVE-2026-87164 | 8.0 | — | Oracle Corporation | Oracle Banking Branch | — | Vulnerability in the Oracle Banking Branch product of Oracle Financial Servic… |
| CVE-2026-87243 | 8.0 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87245 | 8.0 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-83022 | 7.9 | — | Oracle Corporation | Oracle WebCenter Enterprise Capture | — | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-83079 | 7.9 | — | Oracle Corporation | Siebel CRM Cloud Applications | — | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-83096 | 7.9 | — | Oracle Corporation | Oracle Forms | — | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (compon… |
| CVE-2026-0199 | 7.8 | — | Android | CWE-20 | In gf_ta_test_set_config of gf_ta_test.c, there is a possible out-of-bounds w… | |
| CVE-2026-19781 | 7.8 | — | Ashlar-Vellum | Cobalt | CWE-122 | Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code E… |
| CVE-2026-19885 | 7.8 | — | OriginLab | Origin Viewer | CWE-787 | OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Exe… |
| CVE-2026-19886 | 7.8 | — | OriginLab | Origin Viewer | CWE-119 | OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execut… |
| CVE-2026-55323 | 7.8 | — | Android | CWE-122 | In gf_base_update_finger_base of gf_base.c, there is a possible out-of-bounds… | |
| CVE-2026-55351 | 7.8 | — | Android | CWE-190 | In VPU, there is a possible out-of-bounds write due to an integer overflow. T… | |
| CVE-2026-55864 | 7.8 | — | geonetwork | core-geonetwork | CWE-918 | GeoNetwork: Unauthenticaded Server-Side Request Forgery in SLD Tool |
| CVE-2026-56945 | 7.8 | — | Android | CWE-441 | In VPU, there is a possible out-of-bounds write due to a confused deputy. Thi… | |
| CVE-2026-57014 | 7.8 | — | Android | CWE-787 | In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a pos… | |
| CVE-2026-58744 | 7.8 | — | Android | CWE-20 | In multiple locations, there is a possible escalation of privilege due to imp… | |
| CVE-2026-58766 | 7.8 | — | Android | CWE-693 | In multiple functions of arm-smmu-v3.c, there is a possible escalation of pri… | |
| CVE-2026-82992 | 7.8 | — | Oracle Corporation | Siebel CRM Deployment | — | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-82996 | 7.8 | — | Oracle Corporation | Oracle Platform Security for Java | — | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi… |
| CVE-2026-83018 | 7.8 | — | Oracle Corporation | PeopleSoft Enterprise PeopleTools | — | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-83024 | 7.8 | — | Oracle Corporation | Oracle Identity Manager Connector | — | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-83071 | 7.8 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83118 | 7.8 | — | Oracle Corporation | Applications DBA | — | Vulnerability in the Applications DBA product of Oracle E-Business Suite (com… |
| CVE-2026-83147 | 7.8 | — | Oracle Corporation | PeopleSoft Enterprise FIN Inventory Brazil | — | Vulnerability in the PeopleSoft Enterprise FIN Inventory Brazil product of Or… |
| CVE-2026-83159 | 7.8 | — | Oracle Corporation | Applications DBA | — | Vulnerability in the Applications DBA product of Oracle E-Business Suite (com… |
| CVE-2026-83211 | 7.8 | — | Oracle Corporation | Siebel CRM Deployment | — | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-83214 | 7.8 | — | Oracle Corporation | Siebel CRM Deployment | — | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-83216 | 7.8 | — | Oracle Corporation | Siebel CRM Deployment | — | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-83247 | 7.8 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83249 | 7.8 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83253 | 7.8 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83288 | 7.8 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83290 | 7.8 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83291 | 7.8 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83293 | 7.8 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83294 | 7.8 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83317 | 7.8 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83336 | 7.8 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83337 | 7.8 | — | Oracle Corporation | Oracle Middleware Common Libraries and Tools | — | Vulnerability in the Oracle Middleware Common Libraries and Tools product of … |
| CVE-2026-83342 | 7.8 | — | Oracle Corporation | Oracle Utilities Network Management System | — | Vulnerability in the Oracle Utilities Network Management System product of Or… |
| CVE-2026-83353 | 7.8 | — | Oracle Corporation | Oracle WebCenter Content | — | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-83420 | 7.8 | — | Oracle Corporation | PeopleSoft Enterprise FIN Engineering Brazil | — | Vulnerability in the PeopleSoft Enterprise FIN Engineering Brazil product of … |
| CVE-2026-87216 | 7.8 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87268 | 7.8 | — | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-87269 | 7.8 | — | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-87270 | 7.8 | — | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-87271 | 7.8 | — | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-87272 | 7.8 | — | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-92176 | 7.8 | — | pdfforge | PDF Architect | CWE-125 | pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vu… |
| CVE-2026-92177 | 7.8 | — | pdfforge | PDF Architect | CWE-787 | pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execu… |
| CVE-2026-92178 | 7.8 | — | pdfforge | PDF Architect | CWE-119 | pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Executi… |
| CVE-2026-92179 | 7.8 | — | pdfforge | PDF Architect | CWE-787 | pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execu… |
| CVE-2026-92180 | 7.8 | — | pdfforge | PDF Architect | CWE-427 | pdfforge PDF Architect activation-service Update Service Uncontrolled Search … |
| CVE-2026-92248 | 7.8 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-190 | Gimp: integer overflow when generating a thumbnail preview for a psd file |
| CVE-2026-13210 | 7.7 | — | GitLab | GitLab | CWE-863 | Incorrect Authorization in GitLab |
| CVE-2026-19407 | 7.7 | — | Google Cloud | Gemini Enterprise Agent Platform SDK for Python | CWE-330 | GCS Bucket Squatting leading to RCE in Gemini Enterprise Agent Platform Pytho… |
| CVE-2026-53957 | 7.7 | — | contentful | contentful-mcp-server | CWE-918 | Contentful MCP Server: export_space/import_space tools pass LLM-controlled `h… |
| CVE-2026-65831 | 7.7 | — | ArcadeData | arcadedb | CWE-269 | ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scriptin… |
| CVE-2026-76820 | 7.7 | — | OpenCTI-Platform | opencti | CWE-918 | OpenCTI: Synchronizer SSRF: stream fetch has no URL validation |
| CVE-2026-81897 | 7.7 | — | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via Express form… |
| CVE-2026-83012 | 7.7 | — | Oracle Corporation | Oracle WebCenter Enterprise Capture | — | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-83041 | 7.7 | — | Oracle Corporation | Oracle WebCenter Portal | — | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-83048 | 7.7 | — | Oracle Corporation | Oracle WebCenter Portal | — | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-83068 | 7.7 | — | Oracle Corporation | Oracle Enterprise Manager for Oracle Database | — | Vulnerability in the Oracle Enterprise Manager for Oracle Database product of… |
| CVE-2026-83070 | 7.7 | — | Oracle Corporation | PeopleSoft Enterprise PRTL Interaction Hub | — | Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub product of Or… |
| CVE-2026-83084 | 7.7 | — | Oracle Corporation | Oracle Marketing | — | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (com… |
| CVE-2026-83088 | 7.7 | — | Oracle Corporation | Oracle Database Server | — | Vulnerability in the RDBMS component of Oracle Database Server. Supported ver… |
| CVE-2026-83116 | 7.7 | — | Oracle Corporation | Oracle Order Management | — | Vulnerability in the Oracle Order Management product of Oracle E-Business Sui… |
| CVE-2026-83127 | 7.7 | — | Oracle Corporation | Oracle Sales Offline | — | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite … |
| CVE-2026-83129 | 7.7 | — | Oracle Corporation | Oracle Sales | — | Vulnerability in the Oracle Sales product of Oracle E-Business Suite (compone… |
| CVE-2026-83131 | 7.7 | — | Oracle Corporation | Oracle Web Applications Desktop Integrator | — | Vulnerability in the Oracle Web Applications Desktop Integrator product of Or… |
| CVE-2026-83134 | 7.7 | — | Oracle Corporation | Oracle iStore | — | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (compon… |
| CVE-2026-83141 | 7.7 | — | Oracle Corporation | Oracle Field Service | — | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite … |
| CVE-2026-83142 | 7.7 | — | Oracle Corporation | Oracle Proposals | — | Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (com… |
| CVE-2026-83146 | 7.7 | — | Oracle Corporation | Siebel CRM End User | — | Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (compon… |
| CVE-2026-83166 | 7.7 | — | Oracle Corporation | Oracle Customer Interaction History | — | Vulnerability in the Oracle Customer Interaction History product of Oracle E-… |
| CVE-2026-83233 | 7.7 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83243 | 7.7 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83287 | 7.7 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83312 | 7.7 | — | Oracle Corporation | Oracle BI Publisher | — | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-83313 | 7.7 | — | Oracle Corporation | Oracle BI Publisher | — | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-83319 | 7.7 | — | Oracle Corporation | Oracle BI Publisher | — | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-83356 | 7.7 | — | Oracle Corporation | Enterprise Command Center Framework | — | Vulnerability in the Enterprise Command Center Framework product of Oracle E-… |
| CVE-2026-83437 | 7.7 | — | Oracle Corporation | Oracle Engineering | — | Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (c… |
| CVE-2026-83485 | 7.7 | — | Oracle Corporation | Oracle Product Hub | — | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c… |
| CVE-2026-83486 | 7.7 | — | Oracle Corporation | Oracle Product Hub | — | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c… |
| CVE-2026-83487 | 7.7 | — | Oracle Corporation | Oracle Product Hub | — | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c… |
| CVE-2026-87124 | 7.7 | — | Oracle Corporation | Oracle iRecruitment | — | Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (… |
| CVE-2026-87127 | 7.7 | — | Oracle Corporation | Oracle Purchasing | — | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co… |
| CVE-2026-87134 | 7.7 | — | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-87141 | 7.7 | — | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-87147 | 7.7 | — | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-87151 | 7.7 | — | Oracle Corporation | Oracle Bills of Material | — | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Su… |
| CVE-2026-87183 | 7.7 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87256 | 7.7 | — | Oracle Corporation | Oracle Agile PLM | — | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-87257 | 7.7 | — | Oracle Corporation | Oracle Agile PLM | — | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-87264 | 7.7 | — | Oracle Corporation | PeopleSoft Enterprise PeopleTools | — | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-91930 | 7.7 | — | FlowiseAI | Flowise | CWE-266 | Flowise before 3.1.4 Cross-Tenant Organization Admin Takeover |
| CVE-2026-91947 | 7.7 | — | FreeRDP | FreeRDP | CWE-362 | FreeRDP Server before 3.31.0 Use-After-Free via DRDYNVC |
| CVE-2026-91948 | 7.7 | — | FreeRDP | FreeRDP | CWE-191 | FreeRDP before 3.31.0 Out-of-bounds Write via SHOW_PROTOCOL |
| CVE-2026-66372 | 7.6 | — | Digital Watchdog | VMAX A1 G4 DVR | CWE-337 | Predictable Seed in Pseudo-Random Number Generator (PRNG) in Digital Watchdog… |
| CVE-2026-73943 | 7.6 | — | Oracle Corporation | Oracle Identity Manager | — | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-83052 | 7.6 | — | Oracle Corporation | Oracle WebCenter Portal | — | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-83091 | 7.6 | — | Oracle Corporation | Oracle Field Service | — | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite … |
| CVE-2026-83126 | 7.6 | — | Oracle Corporation | Oracle Sales Online | — | Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (… |
| CVE-2026-83207 | 7.6 | — | Oracle Corporation | Siebel CRM Development | — | Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (com… |
| CVE-2026-83320 | 7.6 | — | Oracle Corporation | Oracle BI Publisher | — | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-87131 | 7.6 | — | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-87132 | 7.6 | — | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-87133 | 7.6 | — | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-87137 | 7.6 | — | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-87144 | 7.6 | — | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-87233 | 7.6 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87250 | 7.6 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87258 | 7.6 | — | Oracle Corporation | Oracle Agile PLM | — | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-91929 | 7.6 | — | FlowiseAI | Flowise | CWE-862 | Flowise before 3.1.4 Cross-Tenant Authorization Bypass |
| CVE-2026-91933 | 7.6 | — | FlowiseAI | Flowise | CWE-639 | Flowise before 3.1.4 Authorization Bypass via openai-realtime |
| CVE-2026-91938 | 7.6 | — | FlowiseAI | Flowise | CWE-918 | Flowise before 3.1.4 Server-Side Request Forgery via document loaders |
| CVE-2025-66974 | 7.5 | — | n/a | n/a | CWE-20 | An issue in Prolink 13A Smart Plug Model Version: DS-3202M-UKv3 Wi-Fi and App… |
| CVE-2026-11926 | 7.5 | — | IBM | Verify Identity Access | CWE-400 | Security vulnerabilities have been addressed in IBM Verify Identity Access an… |
| CVE-2026-11929 | 7.5 | — | IBM | Verify Identity Access | CWE-327 | Security vulnerabilities have been addressed in IBM Verify Identity Access an… |
| CVE-2026-12354 | 7.5 | — | IBM | MQ | CWE-913 | IBM MQ Resource Adapter IVT message-driven bean is vulnerable to remote code … |
| CVE-2026-12358 | 7.5 | — | IBM | Verify Identity Access | CWE-674 | Security vulnerabilities have been addressed in IBM Verify Identity Access an… |
| CVE-2026-18113 | 7.5 | — | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS 9.0 to 9.5.2 is vulnerable to Stored XSS in the Top Navigation B… |
| CVE-2026-55149 | 7.5 | — | vouch | vouch-proxy | CWE-789 | Vouch Proxy: Unbounded Multipart Cookie Allocation DoS |
| CVE-2026-55178 | 7.5 | — | geolens-io | geolens | CWE-200 | GeoLens: Cross-dataset authorization bypass discloses private dataset metadat… |
| CVE-2026-55690 | 7.5 | — | StarCitizenWiki | mediawiki-extensions-EmbedVideo | CWE-79 | EmbedVideo Extension: Stored XSS via unsanitized service name in exception text |
| CVE-2026-55692 | 7.5 | — | StarCitizenWiki | mediawiki-extensions-EmbedVideo | CWE-79 | EmbedVideo Extension: Stored XSS via malformed src url with $wgEmbedVideoRequ… |
| CVE-2026-58483 | 7.5 | — | ihor-sokoliuk | mcp-searxng | CWE-400 | mcp-searxng: Unbounded Response Body Read Bypasses URL Size Limit in `web_url… |
| CVE-2026-61554 | 7.5 | — | jm33-m0 | emp3r0r | CWE-400 | emp3r0r has an unauthenticated HTTP Polling DoS |
| CVE-2026-69202 | 7.5 | — | http4s | http4s | CWE-400 | Http4s Ember HTTP/2: unbounded inbound body buffering |
| CVE-2026-69203 | 7.5 | — | http4s | http4s | CWE-400 | Http4s Ember HTTP/2: does not enforce SETTINGS_MAX_CONCURRENT_STREAMS |
| CVE-2026-69208 | 7.5 | — | http4s | http4s | CWE-400 | Http4s: DigestAuth nonce map grows unbounded |
| CVE-2026-69209 | 7.5 | — | http4s | http4s | CWE-400 | Http4s: WebSocket decoder accepts unbounded message sizes |
| CVE-2026-69210 | 7.5 | — | http4s | http4s | CWE-835 | Http4s: WebSocket decoder accepts negative length, causing infinite decode loop |
| CVE-2026-69213 | 7.5 | — | http4s | http4s | CWE-400 | Http4s Ember HTTP/2: unbounded outbound frame queue |
| CVE-2026-69218 | 7.5 | — | http4s | http4s | CWE-770 | Http4s Ember HTTP/2: unbounded continuation frame accumulation |
| CVE-2026-73960 | 7.5 | — | Oracle Corporation | PeopleSoft Enterprise PeopleTools | CWE-400 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-76686 | 7.5 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | — | Unauthenticated Denial-of-Service (DoS) Vulnerability leads to Service Disrup… |
| CVE-2026-76687 | 7.5 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | — | Authenticated Arbitrary File Write Leading to Remote Code Execution in EdgeCo… |
| CVE-2026-76688 | 7.5 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | — | Authentication Bypass Vulnerabilities in the Web-Based Management Interface o… |
| CVE-2026-81238 | 7.5 | — | Dell | Wyse Management Suite | CWE-306 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing… |
| CVE-2026-81898 | 7.5 | — | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via country-less… |
| CVE-2026-83028 | 7.5 | — | Oracle Corporation | Oracle Identity Manager Connector | — | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-83034 | 7.5 | — | Oracle Corporation | Oracle WebCenter Sites | — | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-83051 | 7.5 | — | Oracle Corporation | Oracle WebCenter Portal | — | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-83065 | 7.5 | — | Oracle Corporation | Oracle WebCenter Portal | — | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-83075 | 7.5 | — | Oracle Corporation | Siebel CRM Cloud Applications | — | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-83106 | 7.5 | — | Oracle Corporation | Oracle Forms | — | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (compon… |
| CVE-2026-83110 | 7.5 | — | Oracle Corporation | Oracle Marketing | — | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (com… |
| CVE-2026-83114 | 7.5 | — | Oracle Corporation | Oracle Quality | — | Vulnerability in the Oracle Quality product of Oracle E-Business Suite (compo… |
| CVE-2026-83115 | 7.5 | — | Oracle Corporation | Oracle Applications Manager | — | Vulnerability in the Oracle Applications Manager product of Oracle E-Business… |
| CVE-2026-83128 | 7.5 | — | Oracle Corporation | Oracle Sales Offline | — | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite … |
| CVE-2026-83133 | 7.5 | — | Oracle Corporation | Oracle iStore | — | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (compon… |
| CVE-2026-83156 | 7.5 | — | Oracle Corporation | Oracle Database Server | — | Vulnerability in the Oracle XML Developers Kit component of Oracle Database S… |
| CVE-2026-83167 | 7.5 | — | Oracle Corporation | Oracle Application Object Library | — | Vulnerability in the Oracle Application Object Library product of Oracle E-Bu… |
| CVE-2026-83182 | 7.5 | — | Oracle Corporation | Siebel CRM Development | — | Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (com… |
| CVE-2026-83183 | 7.5 | — | Oracle Corporation | Siebel CRM Deployment | CWE-400 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-83204 | 7.5 | — | Oracle Corporation | Oracle Sourcing | — | Vulnerability in the Oracle Sourcing product of Oracle E-Business Suite (comp… |
| CVE-2026-83213 | 7.5 | — | Oracle Corporation | Siebel CRM End User | — | Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (compon… |
| CVE-2026-83222 | 7.5 | — | Oracle Corporation | Siebel CRM Deployment | CWE-400 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-83223 | 7.5 | — | Oracle Corporation | Siebel CRM Deployment | — | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-83225 | 7.5 | — | Oracle Corporation | Siebel CRM Deployment | CWE-400 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-83226 | 7.5 | — | Oracle Corporation | Siebel CRM Deployment | — | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-83227 | 7.5 | — | Oracle Corporation | Siebel CRM Integration | — | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-83228 | 7.5 | — | Oracle Corporation | Siebel CRM Deployment | CWE-400 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-83235 | 7.5 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83241 | 7.5 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83257 | 7.5 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83262 | 7.5 | — | Oracle Corporation | Oracle Product Lifecycle Analytics | — | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Sup… |
| CVE-2026-83263 | 7.5 | — | Oracle Corporation | Oracle Product Lifecycle Analytics | — | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Sup… |
| CVE-2026-83270 | 7.5 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83276 | 7.5 | — | Oracle Corporation | Helidon | CWE-400 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-83280 | 7.5 | — | Oracle Corporation | Helidon | CWE-400 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-83281 | 7.5 | — | Oracle Corporation | Helidon | CWE-400 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-83289 | 7.5 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83292 | 7.5 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83295 | 7.5 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83296 | 7.5 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83318 | 7.5 | — | Oracle Corporation | Oracle BI Publisher | — | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-83323 | 7.5 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83326 | 7.5 | — | Oracle Corporation | Siebel CRM Integration | — | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-83330 | 7.5 | — | Oracle Corporation | Helidon | CWE-400 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-83333 | 7.5 | — | Oracle Corporation | Oracle Database Server | CWE-400 | Vulnerability in the Oracle Net Services component of Oracle Database Server.… |
| CVE-2026-83341 | 7.5 | — | Oracle Corporation | Oracle Applications Manager | — | Vulnerability in the Oracle Applications Manager product of Oracle E-Business… |
| CVE-2026-83349 | 7.5 | — | Oracle Corporation | Oracle Database Server | CWE-400 | Vulnerability in the Oracle Net Services component of Oracle Database Server.… |
| CVE-2026-83350 | 7.5 | — | Oracle Corporation | Oracle Database Server | CWE-400 | Vulnerability in the Oracle Net Services component of Oracle Database Server.… |
| CVE-2026-83415 | 7.5 | — | Oracle Corporation | Oracle Coherence | — | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-83424 | 7.5 | — | Oracle Corporation | Oracle JDeveloper | — | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (c… |
| CVE-2026-83463 | 7.5 | — | Oracle Corporation | Oracle Mobile Application Server | — | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Bus… |
| CVE-2026-83489 | 7.5 | — | Oracle Corporation | Oracle Banking Origination | — | Vulnerability in the Oracle Banking Origination product of Oracle Financial S… |
| CVE-2026-85234 | 7.5 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Tftp: tftp-hpa: denial of service due to out-of-bounds read/write in remap en… |
| CVE-2026-87136 | 7.5 | — | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-87138 | 7.5 | — | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-400 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-87139 | 7.5 | — | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-87140 | 7.5 | — | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-87148 | 7.5 | — | Oracle Corporation | Oracle Hyperion Data Relationship Management | CWE-400 | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-87190 | 7.5 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87193 | 7.5 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87194 | 7.5 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87199 | 7.5 | — | Oracle Corporation | Oracle Hyperion Financial Management | CWE-400 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87203 | 7.5 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87205 | 7.5 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87211 | 7.5 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87215 | 7.5 | — | Oracle Corporation | Oracle Hyperion Financial Management | CWE-400 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87221 | 7.5 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87222 | 7.5 | — | Oracle Corporation | Oracle Hyperion Financial Management | CWE-400 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87237 | 7.5 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87247 | 7.5 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87254 | 7.5 | — | Oracle Corporation | Oracle Agile PLM | — | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-87276 | 7.5 | — | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-87277 | 7.5 | — | Oracle Corporation | Oracle VM VirtualBox | CWE-400 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-87289 | 7.5 | — | Oracle Corporation | Helidon | CWE-400 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-88065 | 7.5 | — | NIAEFEUP | tts-be | CWE-200 | `tts-be` application has a Broken Access Control vulnerability |
| CVE-2026-88975 | 7.5 | — | http4s | http4s | CWE-400 | Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTI… |
| CVE-2026-18115 | 7.4 | — | Concrete CMS | Concrete CMS | CWE-862 | In Concrete CMS 9.2.0 to 9.5.2, Missing Authorization in REST API Users updat… |
| CVE-2026-54547 | 7.4 | — | pipeboard-co | meta-ads-mcp | CWE-287 | Meta Ads MCP: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token |
| CVE-2026-83102 | 7.4 | — | Oracle Corporation | Oracle Forms | — | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (compon… |
| CVE-2026-83162 | 7.4 | — | Oracle Corporation | Oracle Application Object Library | — | Vulnerability in the Oracle Application Object Library product of Oracle E-Bu… |
| CVE-2026-83184 | 7.4 | — | Oracle Corporation | Oracle Application Object Library | — | Vulnerability in the Oracle Application Object Library product of Oracle E-Bu… |
| CVE-2026-83218 | 7.4 | — | Oracle Corporation | Siebel CRM Deployment | — | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-83334 | 7.4 | — | Oracle Corporation | Oracle Web Services Manager | — | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Mid… |
| CVE-2026-87130 | 7.4 | — | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-87143 | 7.4 | — | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-87195 | 7.4 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87198 | 7.4 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87206 | 7.4 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87212 | 7.4 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87213 | 7.4 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87235 | 7.4 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87242 | 7.4 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-91734 | 7.4 | — | Chrome | CWE-863 | Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0… | |
| CVE-2026-73955 | 7.3 | — | Oracle Corporation | PeopleSoft Enterprise PeopleTools | — | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-81899 | 7.3 | — | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS 9.0 to 9.5.2 is vulnerable to Stored XSS via group folder name o… |
| CVE-2026-83155 | 7.3 | — | Oracle Corporation | Siebel CRM Deployment | — | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-83185 | 7.3 | — | Oracle Corporation | Oracle Common Applications | — | Vulnerability in the Oracle Common Applications product of Oracle E-Business … |
| CVE-2026-83190 | 7.3 | — | Oracle Corporation | Siebel CRM Deployment | — | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-83193 | 7.3 | — | Oracle Corporation | Siebel Apps - Life Sciences | — | Vulnerability in the Siebel Apps - Life Sciences product of Oracle Siebel CRM… |
| CVE-2026-83242 | 7.3 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83277 | 7.3 | — | Oracle Corporation | Oracle Agile PLM MCAD Connector | — | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply… |
| CVE-2026-85013 | 7.3 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-78 | Environment-modules: command injection in environment-modules bash completion… |
| CVE-2026-87145 | 7.3 | — | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-87260 | 7.3 | — | Oracle Corporation | Oracle Agile Engineering Data Management | — | Vulnerability in the Oracle Agile Engineering Data Management product of Orac… |
| CVE-2026-87261 | 7.3 | — | Oracle Corporation | Oracle Agile Engineering Data Management | — | Vulnerability in the Oracle Agile Engineering Data Management product of Orac… |
| CVE-2026-11934 | 7.2 | — | IBM | Verify Identity Access | CWE-285 | Security vulnerabilities have been addressed in IBM Verify Identity Access an… |
| CVE-2026-54544 | 7.2 | — | ShaneIsrael | fireshare | CWE-918 | Fireshare has unauthenticated SSRF via missing login_required on webhook test… |
| CVE-2026-73966 | 7.2 | — | Oracle Corporation | Siebel Apps - Marketing | — | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co… |
| CVE-2026-76689 | 7.2 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | — | Authenticated Buffer Overflow Vulnerability leads to Remote Code Execution or… |
| CVE-2026-76690 | 7.2 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | — | Authenticated Remote Code Execution Vulnerability in HPE Networking EdgeConne… |
| CVE-2026-76691 | 7.2 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | — | Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution i… |
| CVE-2026-76853 | 7.2 | — | Netcore | NR268 | CWE-353 | Netcore NR268 1.7.121109 Security Check Bypass in parame_put_file.cgi |
| CVE-2026-83004 | 7.2 | — | Oracle Corporation | Oracle WebCenter Enterprise Capture | — | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-83016 | 7.2 | — | Oracle Corporation | PeopleSoft Enterprise PeopleTools | — | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-83063 | 7.2 | — | Oracle Corporation | Oracle Internet Directory | — | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middl… |
| CVE-2026-83082 | 7.2 | — | Oracle Corporation | Oracle Marketing | — | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (com… |
| CVE-2026-83112 | 7.2 | — | Oracle Corporation | Oracle Lease and Finance Management | — | Vulnerability in the Oracle Lease and Finance Management product of Oracle E-… |
| CVE-2026-83117 | 7.2 | — | Oracle Corporation | Applications DBA | — | Vulnerability in the Applications DBA product of Oracle E-Business Suite (com… |
| CVE-2026-83176 | 7.2 | — | Oracle Corporation | Oracle Common Applications | — | Vulnerability in the Oracle Common Applications product of Oracle E-Business … |
| CVE-2026-83188 | 7.2 | — | Oracle Corporation | Oracle Depot Repair | — | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (… |
| CVE-2026-83195 | 7.2 | — | Oracle Corporation | Siebel CRM Deployment | — | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-83273 | 7.2 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83298 | 7.2 | — | Oracle Corporation | Oracle BI Publisher | — | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-83322 | 7.2 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83325 | 7.2 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83328 | 7.2 | — | Oracle Corporation | Oracle Applications Framework | — | Vulnerability in the Oracle Applications Framework product of Oracle E-Busine… |
| CVE-2026-83344 | 7.2 | — | Oracle Corporation | Oracle Identity Manager Connector | — | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-83440 | 7.2 | — | Oracle Corporation | Oracle Product Hub | — | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c… |
| CVE-2026-83442 | 7.2 | — | Oracle Corporation | Oracle Product Hub | — | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c… |
| CVE-2026-83453 | 7.2 | — | Oracle Corporation | Oracle Document Management and Collaboration | — | Vulnerability in the Oracle Document Management and Collaboration product of … |
| CVE-2026-83481 | 7.2 | — | Oracle Corporation | Oracle Contracts | — | Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (com… |
| CVE-2026-83482 | 7.2 | — | Oracle Corporation | Oracle Contracts | — | Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (com… |
| CVE-2026-87207 | 7.2 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87239 | 7.2 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87244 | 7.2 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87246 | 7.2 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-90650 | 7.2 | — | jetmonsters | MotoPress Hotel Booking | CWE-79 | MotoPress Hotel Booking <= 6.2.4 - Unauthenticated Stored Cross-Site Scriptin… |
| CVE-2026-10144 | 7.1 | — | web-infra-dev | rsbuild | CWE-78 | Rsbuild < 2.0.9 Command Injection via openBrowser() URL Handling |
| CVE-2026-12667 | 7.1 | — | IBM | MQ | CWE-611 | IBM MQ .NET client is vulnerable to XML external entity injection |
| CVE-2026-12752 | 7.1 | — | IBM | Business Automation Workflow containers and traditional | CWE-611 | Multiple security vulnerabilities addressed with IBM Business Automation Work… |
| CVE-2026-19655 | 7.1 | — | Arista Networks | EOS | CWE-20 | On affected platforms running Arista EOS with Dynamic Host Configuration Prot… |
| CVE-2026-19774 | 7.1 | — | BlueZ | BlueZ | CWE-121 | BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability |
| CVE-2026-21586 | 7.1 | — | Atlassian | Confluence Data Center | CWE-285 | This High severity Improper Authorization vulnerability was introduced in ver… |
| CVE-2026-21587 | 7.1 | — | Atlassian | Jira Service Management Data Center | CWE-285 | This High severity Improper Authorization vulnerability was introduced in ver… |
| CVE-2026-21588 | 7.1 | — | Atlassian | Confluence Data Center | CWE-400 | This High severity DoS (Denial of Service) vulnerability was introduced in ve… |
| CVE-2026-53966 | 7.1 | — | xwiki | xwiki-platform | CWE-862 | XWiki Platform: Privilege escalation from edit to script right through Live D… |
| CVE-2026-54077 | 7.1 | — | ArcadeData | arcadedb | CWE-22 | ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authen… |
| CVE-2026-58200 | 7.1 | — | jhb-software | payload-plugins | CWE-347 | @jhb.software/payload-cloudinary-plugin: Arbitrary Cloudinary API Parameter S… |
| CVE-2026-58485 | 7.1 | — | ihor-sokoliuk | mcp-searxng | CWE-918 | mcp-searxng: DNS-resolved Private Hostname SSRF in `web_url_read` |
| CVE-2026-58502 | 7.1 | — | gouef | githubtoplanguages | CWE-78 | githubtoplanguages: Command Injection via Issue Title in Discord Notification… |
| CVE-2026-59965 | 7.1 | — | jhb-software | payload-plugins | CWE-863 | @jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass… |
| CVE-2026-68953 | 7.1 | — | Digital Watchdog | VMAX A1 G4 DVR | CWE-306 | Missing Authentication for Critical Function in Digital Watchdog VMAX DVR and… |
| CVE-2026-76692 | 7.1 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | CWE-200 | Unauthenticated Adjacent Information Disclosure and Denial-of-Service Vulnera… |
| CVE-2026-76821 | 7.1 | — | OpenCTI-Platform | opencti | CWE-400 | OpenCTI: User-Controlled ReDoS in JSON Ingestion Mapper |
| CVE-2026-76854 | 7.1 | — | Netcore | NR255-V | CWE-522 | Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via l7_web_auth_u… |
| CVE-2026-76855 | 7.1 | — | Netcore | NR255-V | CWE-359 | Netcore NR255-V 1.5.130703 Cross-User Session Disclosure via Audit Endpoints |
| CVE-2026-76857 | 7.1 | — | Netcore | NR255-V | CWE-522 | Netcore NR255-V 1.5.130703 Plaintext DDNS Credential Disclosure via ddns_wan_… |
| CVE-2026-76859 | 7.1 | — | Netcore | NR255-V | CWE-522 | Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via user_pass_sho… |
| CVE-2026-76870 | 7.1 | — | Netcore | NR255-V | CWE-125 | Netcore NR255-V 1.5.130703 Out-of-Bounds Read in mtd_write Firmware Upload Va… |
| CVE-2026-76871 | 7.1 | — | Netcore | NR255-V | CWE-522 | Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via VPN Read Hand… |
| CVE-2026-78081 | 7.1 | — | j2commerce.com | J2Store extension for Joomla | CWE-352 | Joomla Extension - j2commerce.com - Missing CSRF protection on cart, checkout… |
| CVE-2026-83044 | 7.1 | — | Oracle Corporation | Oracle XML Gateway | — | Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (c… |
| CVE-2026-83046 | 7.1 | — | Oracle Corporation | Oracle WebCenter Portal | — | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-83050 | 7.1 | — | Oracle Corporation | Oracle WebCenter Portal | — | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-83080 | 7.1 | — | Oracle Corporation | Oracle Banking Branch | — | Vulnerability in the Oracle Banking Branch product of Oracle Financial Servic… |
| CVE-2026-83092 | 7.1 | — | Oracle Corporation | Oracle Field Service | — | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite … |
| CVE-2026-83111 | 7.1 | — | Oracle Corporation | Oracle Partner Management | — | Vulnerability in the Oracle Partner Management product of Oracle E-Business S… |
| CVE-2026-83113 | 7.1 | — | Oracle Corporation | Oracle Quality | — | Vulnerability in the Oracle Quality product of Oracle E-Business Suite (compo… |
| CVE-2026-83123 | 7.1 | — | Oracle Corporation | Oracle Report Manager | — | Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite… |
| CVE-2026-83130 | 7.1 | — | Oracle Corporation | Oracle Site Hub | — | Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (comp… |
| CVE-2026-83158 | 7.1 | — | Oracle Corporation | Oracle Applications Manager | — | Vulnerability in the Oracle Applications Manager product of Oracle E-Business… |
| CVE-2026-83161 | 7.1 | — | Oracle Corporation | Oracle Project Intelligence | — | Vulnerability in the Oracle Project Intelligence product of Oracle E-Business… |
| CVE-2026-83171 | 7.1 | — | Oracle Corporation | Oracle One-to-One Fulfillment | — | Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Busine… |
| CVE-2026-83173 | 7.1 | — | Oracle Corporation | Oracle One-to-One Fulfillment | — | Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Busine… |
| CVE-2026-83179 | 7.1 | — | Oracle Corporation | Oracle Common Applications Calendar | — | Vulnerability in the Oracle Common Applications Calendar product of Oracle E-… |
| CVE-2026-83186 | 7.1 | — | Oracle Corporation | Oracle Common Applications Calendar | — | Vulnerability in the Oracle Common Applications Calendar product of Oracle E-… |
| CVE-2026-83187 | 7.1 | — | Oracle Corporation | Oracle Common Applications Calendar | — | Vulnerability in the Oracle Common Applications Calendar product of Oracle E-… |
| CVE-2026-83206 | 7.1 | — | Oracle Corporation | Oracle Banking Corporate Lending Process Management | — | Vulnerability in the Oracle Banking Corporate Lending Process Management prod… |
| CVE-2026-83217 | 7.1 | — | Oracle Corporation | Siebel CRM End User | — | Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (compon… |
| CVE-2026-83219 | 7.1 | — | Oracle Corporation | Siebel CRM Deployment | — | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-83221 | 7.1 | — | Oracle Corporation | Siebel CRM Integration | — | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-83224 | 7.1 | — | Oracle Corporation | Siebel CRM Deployment | — | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-83230 | 7.1 | — | Oracle Corporation | Siebel CRM Deployment | — | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-83237 | 7.1 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83238 | 7.1 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83240 | 7.1 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83244 | 7.1 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83259 | 7.1 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83300 | 7.1 | — | Oracle Corporation | Oracle XML Gateway | — | Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (c… |
| CVE-2026-83324 | 7.1 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83332 | 7.1 | — | Oracle Corporation | Oracle Applications Framework | — | Vulnerability in the Oracle Applications Framework product of Oracle E-Busine… |
| CVE-2026-83345 | 7.1 | — | Oracle Corporation | Oracle XML Gateway | — | Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (c… |
| CVE-2026-83352 | 7.1 | — | Oracle Corporation | Oracle XML Gateway | — | Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (c… |
| CVE-2026-83417 | 7.1 | — | Oracle Corporation | Oracle Communications Cloud Native Core Security Edge Protection Proxy | — | Vulnerability in the Oracle Communications Cloud Native Core Security Edge Pr… |
| CVE-2026-83436 | 7.1 | — | Oracle Corporation | Oracle Depot Repair | — | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (… |
| CVE-2026-83484 | 7.1 | — | Oracle Corporation | Oracle US Federal Human Resources | — | Vulnerability in the Oracle US Federal Human Resources product of Oracle E-Bu… |
| CVE-2026-87126 | 7.1 | — | Oracle Corporation | Oracle Report Manager | — | Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite… |
| CVE-2026-87135 | 7.1 | — | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-87142 | 7.1 | — | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-87146 | 7.1 | — | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-87149 | 7.1 | — | Oracle Corporation | Oracle Contract Lifecycle Management for Public Sector | — | Vulnerability in the Oracle Contract Lifecycle Management for Public Sector p… |
| CVE-2026-87156 | 7.1 | — | Oracle Corporation | Oracle Product Hub | — | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c… |
| CVE-2026-87158 | 7.1 | — | Oracle Corporation | Oracle Order Management | — | Vulnerability in the Oracle Order Management product of Oracle E-Business Sui… |
| CVE-2026-87160 | 7.1 | — | Oracle Corporation | Oracle HRMS (India) | — | Vulnerability in the Oracle HRMS (India) product of Oracle E-Business Suite (… |
| CVE-2026-87191 | 7.1 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87192 | 7.1 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87208 | 7.1 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87209 | 7.1 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87220 | 7.1 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87225 | 7.1 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87236 | 7.1 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87249 | 7.1 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-87262 | 7.1 | — | Oracle Corporation | Oracle Agile Engineering Data Management | — | Vulnerability in the Oracle Agile Engineering Data Management product of Orac… |
| CVE-2026-91945 | 7.1 | — | FreeRDP | FreeRDP | CWE-125 | FreeRDP before 3.31.0 Out-of-bounds Read via Smartcard ATR |
| CVE-2026-91946 | 7.1 | — | FreeRDP | FreeRDP | CWE-908 | FreeRDP before 3.31.0 Information Disclosure via RDPGFX ResetGraphics |
| CVE-2026-91950 | 7.1 | — | FreeRDP | FreeRDP | CWE-125 | FreeRDP before 3.31.0 Out-of-Bounds Read via UINT32 Wraparound |
| CVE-2026-91951 | 7.1 | — | FreeRDP | FreeRDP | CWE-617 | FreeRDP 3.14.0 through 3.30.0 Out-of-bounds Write via urbdrc |
| CVE-2026-91952 | 7.1 | — | FreeRDP | FreeRDP | CWE-835 | FreeRDP before 3.31.0 Denial of Service via pool_decode_rect |
| CVE-2026-91953 | 7.1 | — | FreeRDP | FreeRDP | CWE-120 | FreeRDP before 3.31.0 Heap Buffer Overflow via LB_LOAD_BALANCE_INFO |
| CVE-2026-91954 | 7.1 | — | FreeRDP | FreeRDP | CWE-476 | FreeRDP before 3.31.0 NULL Pointer Dereference via NSCodec |
| CVE-2026-91956 | 7.1 | — | FreeRDP | FreeRDP | CWE-125 | FreeRDP before 3.31.0 Out-of-Bounds Read via URBDRC |
| CVE-2026-91959 | 7.1 | — | FreeRDP | FreeRDP | CWE-125 | FreeRDP before 3.31.0 Buffer Over-read via RTS Gateway |
| CVE-2026-91960 | 7.1 | — | FreeRDP | FreeRDP | CWE-190 | FreeRDP before 3.31.0 Integer Overflow Double Free |
| CVE-2026-91961 | 7.1 | — | FreeRDP | FreeRDP | CWE-617 | FreeRDP before 3.31.0 Denial of Service via URBDRC |