LIVE FEED
1767 events · 4 sources · newest first
Events in view
1767
all sources
Critical
1492
severity
Active sources
4
collectors
Last sync
2026-08-26 12:00
UTC
2026-07-21
NVD CVE
CVE-2026-61130: Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (compon
CRITICAL
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-28317: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vuln
CRITICAL
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.
cve-2026-28317cybersecuritydfar-252-204-7012domain-administratoridorincident-responsenist-800-171nvd-cve
2026-07-21
NVD CVE
CVE-2026-61097: Vulnerability in the Oracle Banking Trade Finance Process Management product of
CRITICAL
Vulnerability in the Oracle Banking Trade Finance Process Management product of Oracle Financial Services Applications (component: Common). Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60275: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
availabilitycompromiseconfidentialitycore-componentcve-2026-60275cvss-31httpintegrity
2026-07-21
NVD CVE
CVE-2026-61100: Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio
CRITICAL
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60374: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-61129: Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (compon
CRITICAL
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: ATG Portals). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker...
2026-07-21
NVD CVE
CVE-2026-61146: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience
CRITICAL
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily...
2026-07-21
NVD CVE
CVE-2026-60239: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
confidentialitycore-componentcritical-datacve-2026-60239cvss-31data-compromisedata-modificationhttp
2026-07-21
NVD CVE
CVE-2026-65057: Keep (commit 91c75e0) contains a server-side request forgery vulnerability that
CRITICAL
Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the...
cloud-credentialscloud-metadatacve-2026-65057cybersecuritydefense-industrial-basedfar-252-204-7012healthcheck-endpointhttps-requests
2026-07-21
NVD CVE
CVE-2026-60377: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-61059: Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracl
CRITICAL
Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-61072: Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office Brazil prod
CRITICAL
Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office Brazil product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-46982: Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Appl
CRITICAL
Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 14.1.3.2. Easily exploitable vulnerability allows...
availabilitycompromiseconfidentialitycve-2026-46982cvss-31httpintegration-busintegrity
2026-07-21
NVD CVE
CVE-2026-61204: Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Ora
CRITICAL
Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration). The supported version that is affected is 9.2. Easily exploitable vulnerability...
2026-07-21
NVD CVE
CVE-2026-60289: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-61065: Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (
CRITICAL
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-47036: Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (compon
CRITICAL
Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Siebel Approval Manager). Supported versions that are affected are 17.0-26.3. Easily exploitable vulnerability allows...
availabilitycompromiseconfidentialitycrmcve-2026-47036cvss-31development-toolshttp
2026-07-21
NVD CVE
CVE-2026-60300: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-47056: Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware
CRITICAL
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows...
availabilityconfidentialitycve-2026-47056cvss-31data-compromisehttpintegritynetwork-access
2026-07-21
NVD CVE
CVE-2026-60242: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows...
availabilitycompromiseconfidentialitycore-componentcve-2026-60242cvss-31httpintegrity
2026-07-21
NVD CVE
CVE-2026-60173: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component:
CRITICAL
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows...
availabilitybi-platform-securitybi-publisherscompromiseconfidentialitycve-2026-60173cvss-31http
2026-07-21
NVD CVE
CVE-2026-60880: Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (
CRITICAL
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-60380: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60276: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
availabilityconfidentialitycore-componentcve-2026-60276cvss-31data-compromisehttpintegrity
2026-07-21
NVD CVE
CVE-2026-60200: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware
CRITICAL
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
availabilitycompromiseconfidentialitycore-componentcve-2026-60200cvss-31integritynetwork-access
2026-07-21
NVD CVE
CVE-2026-60287: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60463: Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middlew
CRITICAL
Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-61076: Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager produc
CRITICAL
Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager product of Oracle PeopleSoft (component: Job Opening). The supported version that is affected is 9.2. Easily exploitable vulnerability...
2026-07-21
NVD CVE
CVE-2026-60206: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware
CRITICAL
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
availabilitycompromiseconfidentialitycore-componentcve-2026-60206cvss-31integritynetwork-access
2026-07-21
NVD CVE
CVE-2026-61153: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience
CRITICAL
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily...
2026-07-21
NVD CVE
CVE-2026-60365: Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusi
CRITICAL
Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). The supported version that is affected is...
2026-07-21
NVD CVE
CVE-2026-60217: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
availabilityconfidentialitycore-componentcve-2026-60217cvss-31data-compromiseintegritynetwork-access
2026-07-20
NVD CVE
CVE-2026-28220: Wazuh is a free and open source platform used for threat prevention, detection,
HIGH
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a cluster peer, or any actor able to...
2026-07-20
NVD CVE
CVE-2026-12341: This vulnerability
impacts all versions of IdentityIQ and allows an unauthentica
HIGH
This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated attacker
unauthorized access to protected APIs and data due to improper validation of
OAuth bearer tokens.
2026-07-20
NVD CVE
CVE-2026-41521: xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer
HIGH
xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A malicious remote VNC server can send...
2026-07-20
NVD CVE
CVE-2026-64625: AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync
CRITICAL
AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary...
avideocommand-injectioncve-2026-45578cve-2026-64625cybersecuritydefense-industrial-basedfar-252-204-7012escapeshellarg
2026-07-20
NVD CVE
CVE-2026-63767: ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticate
CRITICAL
ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to...
arbitrary-command-executioncve-2026-63767cybersecuritydefense-industrial-basedfar-252-204-7012ktraansformernist-800-171nvd-cve
2026-07-20
NVD CVE
CVE-2026-63766: GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability
CRITICAL
GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into shell commands...
arbitrary-command-executionauthenticationcve-2026-63766cybersecuritygpt-sovitgradioinformation-securitynvd-cve
2026-07-20
NVD CVE
CVE-2026-12701: A path traversal vulnerability was found in pulpcore. The relative_path_validato
CRITICAL
A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directory traversal sequences such as "../"...
administrator-privilegesartifacts-handlingcybersecuritydata-exposurefile-integrityfile-writefilesystem-exportincident-response