LIVE FEED
3576 events · 4 sources · newest first
Events in view
3576
all sources
Critical
1821
severity
Active sources
4
collectors
Last sync
2026-08-26 06:00
UTC
2026-07-21
NVD CVE
CVE-2026-62546: Vulnerability in the Oracle Applications Framework product of Oracle E-Business
CRITICAL
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows high...
2026-07-21
NVD CVE
CVE-2026-64825: Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that
CRITICAL
Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive...
arbitrary-file-writebackup-archivecve-2026-64825cybersecuritydata-integrityfile-writefilesystem-accesseshome-assistant
2026-07-21
NVD CVE
CVE-2026-28306: SolarWinds Serv-U is affected by a privilege escalation vulnerability that allow
CRITICAL
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.
cve-2026-28306cybersecuritydomain-administratornvd-cvepatch-managementprivileges-escalationrisk-managementserv-u
2026-07-21
NVD CVE
CVE-2026-60173: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component:
CRITICAL
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows...
availabilitybi-platform-securitybi-publisherscompromiseconfidentialitycve-2026-60173cvss-31http
2026-07-21
NVD CVE
CVE-2026-28307: SolarWinds Serv-U is affected by a privilege escalation vulnerability that allow
CRITICAL
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.
administrator-privilegescve-2026-28307cybersecurityincident-responsenetwork-securitynvd-cvepatch-managementprivileges-escalation
2026-07-21
NVD CVE
CVE-2026-28321: SolarWinds Serv-U is affected by a broken access control vulnerability that coul
CRITICAL
SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator...
arbitrary-file-readsarbitrary-file-writebroken-access-controlcode-executioncve-2026-28321cybersecuritydfar-252-204-7012domain-administrator
2026-07-21
NVD CVE
CVE-2026-46983: Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Appl
CRITICAL
Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows...
availabilitycompromiseconfidentialitycve-2026-46983cvss-31httpintegration-busintegrity
2026-07-21
NVD CVE
CVE-2026-28312: SolarWinds Serv-U is affected by a privilege escalation vulnerability. This woul
CRITICAL
SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments.
code-executioncve-2026-28312cybersecuritydefense-industrial-basedfar-252-204-7012incident-responsenist-800-171nvd-cve
2026-07-21
NVD CVE
CVE-2026-28316: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vuln
CRITICAL
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This...
command-executioncve-2026-28316cybersecuritydfar-252-204-7012idorincident-responsenist-800-171nvd-cve
2026-07-21
NVD CVE
CVE-2026-28308: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vuln
CRITICAL
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.
cve-2026-28308cybersecuritydomain-administratoridorincident-responsenvd-cvepatch-managementremote-code-execution
2026-07-21
NVD CVE
CVE-2026-28317: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vuln
CRITICAL
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.
cve-2026-28317cybersecuritydfar-252-204-7012domain-administratoridorincident-responsenist-800-171nvd-cve
2026-07-21
NVD CVE
CVE-2026-60564: Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware
CRITICAL
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability...
2026-07-21
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-09.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability...
1734-point-iocisa-advisorycritical-manufacturingcve-2026-10573cvss-v3cvss-v4cybersecuritydenial
2026-07-21
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-07.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability...
cisacisa-advisorycritical-infrastructurecve-2026-10714cybersecuritydefensedepthfactorytalk-services-platform
2026-07-21
NVD CVE
CVE-2026-28313: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vuln
CRITICAL
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments.
accounts-takeoverarbitrary-accessescve-2026-28313cybersecuritydata-exposureidorincident-responsenvd-cve
2026-07-21
NVD CVE
CVE-2026-28314: SolarWinds Serv-U is affected by an insecure direct object reference vulnerabili
CRITICAL
SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.
accounts-takeovercve-2026-28314cybersecuritydata-compromisedfar-252-204-7012incident-responseinsecure-direct-object-referencenist-800-171
2026-07-21
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-05.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Multiple Siemens products are affected by unquoted...
cisacisa-advisorycmmccomocritical-infrastructurecve-2025-40945cybersecuritydesigncenter-nx
2026-07-21
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-10.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of these vulnerabilities...
cisacisa-advisorycritical-manufacturingcve-2026-9108cve-2026-9127cve-2026-9128cybersecurityic
2026-07-21
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-02.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Palo Alto Networks has published [1] information...
ape1808cisacisa-advisorycommand-injectioncritical-infrastructurecritical-manufacturingcross-site-scriptingcve-2026-0266
2026-07-21
NVD CVE
CVE-2016-20096: Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated S
CRITICAL
Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name parameter in a POST...
authenticationcredentialcves-2016-20096databasedba-privilegeslinknatlogins-endpointsnvd-cve
2026-07-21
NVD CVE
CVE-2026-60561: Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware
CRITICAL
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability...
2026-07-21
NVD CVE
CVE-2026-46924: Vulnerability in Oracle Application Testing Suite. The supported version that
CRITICAL
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise...
applications-testing-suiteavailabilitycompromiseconfidentialitycve-2026-46924cvss-31integritynetwork-access
2026-07-21
NVD CVE
CVE-2026-35290: Vulnerability in Oracle Application Testing Suite. The supported version that
CRITICAL
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise...
applications-testing-suiteavailabilityconfidentialitycve-2026-35290cvss-31data-compromiseintegritynetwork-access
2026-07-21
NVD CVE
CVE-2026-46876: Vulnerability in Oracle Application Testing Suite. The supported version that
CRITICAL
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to...
applications-testing-suiteavailabilityconfidentialitycve-2026-46876cvss-31data-compromiseintegritynetwork-access
2026-07-21
NVD CVE
CVE-2026-65057: Keep (commit 91c75e0) contains a server-side request forgery vulnerability that
CRITICAL
Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the...
cloud-credentialscloud-metadatacve-2026-65057cybersecuritydefense-industrial-basedfar-252-204-7012healthcheck-endpointhttps-requests
2026-07-21
NVD CVE
CVE-2026-60456: Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio
CRITICAL
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60566: Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware
CRITICAL
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability...
2026-07-21
NVD CVE
CVE-2026-60249: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
availabilitycompromiseconfidentialitycore-componentcve-2026-60249cvss-31integritylow-privileged-attacker
2026-07-21
NVD CVE
CVE-2026-60441: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-47036: Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (compon
CRITICAL
Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Siebel Approval Manager). Supported versions that are affected are 17.0-26.3. Easily exploitable vulnerability allows...
availabilitycompromiseconfidentialitycrmcve-2026-47036cvss-31development-toolshttp
2026-07-21
NVD CVE
CVE-2026-46982: Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Appl
CRITICAL
Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 14.1.3.2. Easily exploitable vulnerability allows...
availabilitycompromiseconfidentialitycve-2026-46982cvss-31httpintegration-busintegrity
2026-07-21
NVD CVE
CVE-2026-47040: Vulnerability in the Oracle Net Services component of Oracle Database Server. S
CRITICAL
Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows...
critical-datacve-2026-47040cvss-31data-availabilitydata-compromisedata-confidentialitydenialdos
2026-07-21
NVD CVE
CVE-2026-46989: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle E
CRITICAL
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability...
critical-datacve-2026-46989cvss-31data-accessdata-compromisedata-integritydenialenterprises-managers
2026-07-21
NVD CVE
CVE-2026-46994: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle E
CRITICAL
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable...
agent-next-genavailabilitybase-platformcompromiseconfidentialitycve-2026-46994cvss-31enterprises-managers
2026-07-21
NVD CVE
CVE-2026-60230: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
availabilityconfidentialitycore-componentcve-2026-60230cvss-31data-compromiseintegritynetwork-access
2026-07-21
NVD CVE
CVE-2026-60442: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60168: Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beve
CRITICAL
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10. Easily exploitable...
critical-datacvss-31data-compromisedata-modificationdenialdoshospitalityhttp
2026-07-21
NVD CVE
CVE-2026-60197: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
availabilitycoherenceconfidentialitycore-componentcve-2026-60197cvss-31data-compromiseintegrity
2026-07-21
NVD CVE
CVE-2026-60445: Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio
CRITICAL
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60204: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware
CRITICAL
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
availabilityconfidentialitycore-componentcve-2026-60204cvss-31iiop-protocolintegritynetwork-access