LIVE FEED
1821 events · 4 sources · newest first
Events in view
1821
all sources
Critical
1821
severity
Active sources
4
collectors
Last sync
2026-08-26 06:00
UTC
2026-07-21
NVD CVE
CVE-2026-64825: Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that
CRITICAL
Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive...
arbitrary-file-writebackup-archivecve-2026-64825cybersecuritydata-integrityfile-writefilesystem-accesseshome-assistant
2026-07-21
NVD CVE
CVE-2026-60457: Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio
CRITICAL
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60458: Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio
CRITICAL
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-28307: SolarWinds Serv-U is affected by a privilege escalation vulnerability that allow
CRITICAL
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.
administrator-privilegescve-2026-28307cybersecurityincident-responsenetwork-securitynvd-cvepatch-managementprivileges-escalation
2026-07-21
NVD CVE
CVE-2026-28308: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vuln
CRITICAL
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.
cve-2026-28308cybersecuritydomain-administratoridorincident-responsenvd-cvepatch-managementremote-code-execution
2026-07-21
NVD CVE
CVE-2026-60460: Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio
CRITICAL
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60456: Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio
CRITICAL
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60532: Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion
CRITICAL
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily...
2026-07-21
NVD CVE
CVE-2026-60445: Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio
CRITICAL
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60447: Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio
CRITICAL
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60446: Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio
CRITICAL
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60531: Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion
CRITICAL
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability...
2026-07-21
NVD CVE
CVE-2026-28306: SolarWinds Serv-U is affected by a privilege escalation vulnerability that allow
CRITICAL
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.
cve-2026-28306cybersecuritydomain-administratornvd-cvepatch-managementprivileges-escalationrisk-managementserv-u
2026-07-21
NVD CVE
CVE-2026-28309: SolarWinds Serv-U is affected by a broken access control vulnerability that allo
CRITICAL
SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.
broken-access-controlcve-2026-28309cybersecuritydfar-252-204-7012domain-administratorincident-responsenist-800-171nvd-cve
2026-07-21
NVD CVE
CVE-2026-60435: Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability...
2026-07-21
NVD CVE
CVE-2026-60438: Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (com
CRITICAL
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_ssl). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-60441: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-28302: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vuln
CRITICAL
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The...
cve-2026-28302cybersecuritydfar-252-204-7012groups-administratorsidorincident-responsenist-800-171nvd-cve
2026-07-21
NVD CVE
CVE-2026-28304: SolarWinds Serv-U is affected by a remote code execution vulnerability that, whe
CRITICAL
SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.
cmmccve-2026-28304cybersecuritydfar-252-204-7012incident-responsenist-800-171nvd-cverce
2026-07-21
NVD CVE
CVE-2026-60429: Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-28316: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vuln
CRITICAL
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This...
command-executioncve-2026-28316cybersecuritydfar-252-204-7012idorincident-responsenist-800-171nvd-cve
2026-07-21
NVD CVE
CVE-2026-60442: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60422: Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). The supported version that is affected is 14.1.2.1.0. Easily exploitable vulnerability allows low privileged...
2026-07-21
NVD CVE
CVE-2026-28305: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vuln
CRITICAL
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home...
cve-2026-28305cybersecuritydata-exposureidorincident-responsenvd-cvepatch-managementremote-code-execution
2026-07-21
NVD CVE
CVE-2026-60535: Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion
CRITICAL
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily...
2026-07-21
NVD CVE
CVE-2026-60424: Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-61201: Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle
CRITICAL
Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.2.23. Difficult to exploit vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-60387: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60388: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-16441: In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previo
CRITICAL
In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, execution is incorrectly delegated to an interface default method.
2026-07-21
NVD CVE
CVE-2026-60389: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60386: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60379: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60381: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60380: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60402: Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-M
CRITICAL
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-65007: The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize A
CRITICAL
The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks before the account-management ACL...
access-controlaccounts-managementaccounts-takeoverapi-keyapi-permissionsauthenticationauthorizationcve-2026-65007
2026-07-21
NVD CVE
CVE-2026-60375: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60376: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60377: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...