LIVE FEED
3560 events · 4 sources · newest first
Events in view
3560
all sources
Critical
1814
severity
Active sources
4
collectors
Last sync
2026-08-25 18:00
UTC
2026-08-18
NVD CVE
CVE-2026-61003: Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middl
CRITICAL
Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
availability-impactconfidentiality-impactcve-2026-61003cvss-31data-breachesiiop-protocolintegrity-impactnetworks-vulnerabilities
2026-08-18
NVD CVE
CVE-2026-62617: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
availability-impactconfidentiality-impactcve-2026-62617cvss-31cvss-98integrity-impactnetwork-accessnvd-cve
2026-08-18
NVD CVE
CVE-2026-70669: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
availabilityconfidentialitycve-2026-70669cvss-31httpintegritynetwork-accessnvd-cve
2026-08-18
NVD CVE
CVE-2026-70668: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
confidentiality-impactcve-2026-70668cvss-31data-compromiseintegrity-impactnvd-cveoracleoracle-fusion-middleware
2026-08-18
NVD CVE
CVE-2026-70673: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
confidentiality-impactcve-2026-70673cvss-31data-compromisehttpintegrity-impactnetwork-accessnvd-cve
2026-08-18
NVD CVE
CVE-2026-70670: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
2026-08-18
NVD CVE
CVE-2026-62457: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle
CRITICAL
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows...
2026-08-18
NVD CVE
CVE-2026-62621: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
availabilityconfidentialitycve-2026-62621cvss-31integritynetwork-accessnvd-cveoracle-fusion-middleware
2026-08-18
NVD CVE
CVE-2026-70921: Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hype
CRITICAL
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows...
2026-08-18
NVD CVE
CVE-2026-70926: Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (compone
CRITICAL
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows...
availabilitycompromiseconfidentialitycve-2026-70926cvss-31cvss-98integritynetwork-access
2026-08-18
NVD CVE
CVE-2026-62613: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
confidentiality-impactcritical-data-accesscve-2026-62613cvss-31data-compromiseintegrity-impactmiddleware-vulnerabilitiesnvd-cve
2026-08-18
NVD CVE
CVE-2026-75913: CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an
CRITICAL
CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv...
arbitrary-file-writeargument-injectionbashrccode-executioncodewhalecodewhale-tuicve-2026-75913git-show
2026-08-18
NVD CVE
CVE-2026-62626: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
2026-08-18
NVD CVE
CVE-2026-61258: Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability...
availability-impactcompromiseconfidentiality-impactcve-2026-61258cvss-31cvss-98integrity-impactldap
2026-08-18
NVD CVE
CVE-2026-12564: A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The
CRITICAL
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and...
api-accessesawxcredentials-theftcve-2026-12564database-credentialsdjangohashicorphashicorp-vault
2026-08-18
NVD CVE
CVE-2026-62539: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle
CRITICAL
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable...
2026-08-18
NVD CVE
CVE-2026-62637: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
2026-08-18
NVD CVE
CVE-2026-70817: Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hype
CRITICAL
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows...
2026-08-18
NVD CVE
CVE-2026-74943: Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed
CRITICAL
Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
cve-2026-74943firefoxfreegraphicimagelibmozillanvd-cvepatch
2026-08-18
NVD CVE
CVE-2026-60977: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware
CRITICAL
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable...
availability-impactconfidentiality-impactcve-2026-60977cvss-31integrity-impactnetwork-accessnvd-cveoracle
2026-08-18
NVD CVE
CVE-2026-60990: Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion
CRITICAL
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability...
cve-2026-60990cvss-31cvss-99network-securitynvd-cveoracleoracle-fusionoracle-identity-manager-connector
2026-08-18
NVD CVE
CVE-2026-18963: A flaw was found in the reset-credentials flow of the keycloak-services componen
CRITICAL
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated...
accounts-takeovercredentials-compromisecve-2026-18963email-verification-bypassidentity-and-access-managementkeycloakkeycloak-servicenvd-cve
2026-08-18
CISA advisory
<p>CISA has added four new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation....
bod-26-04cisacisa-advisorycve-2026-33824cve-2026-55040cve-2026-59310cve-2026-65400cyber-attacks
2026-08-18
NVD CVE
CVE-2026-60995: Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion
CRITICAL
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability...
cve-2026-60995cvss-31cvss-99network-securitynvd-cveoracleoracle-fusionoracle-identity-manager-connector
2026-08-18
NVD CVE
CVE-2026-62614: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
availabilityconfidentialitycve-2026-62614cvss-31httpintegritynetwork-accessnvd-cve
2026-08-18
NVD CVE
CVE-2026-74940: Use-after-free in the Graphics: Text component. This vulnerability was fixed in
CRITICAL
Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
cve-2026-74940firefoxfirefox-esrfreegraphic-text-componentmozillanvd-cvesecurity-patch
2026-08-18
NVD CVE
CVE-2026-75784: A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this
CRITICAL
A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the...
buffer-overflowcve-2026-75784cybersecurityhttps-header-handlernetwork-securitynginxnvd-cvepublic-exploit
2026-08-18
NVD CVE
CVE-2026-62629: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
cve-2026-62629data-compromisedata-creationdata-deletiondata-modificationdata-readdosdose-attack
2026-08-18
NVD CVE
CVE-2026-70905: Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (
CRITICAL
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Agent infrastructure). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability...
2026-08-18
NVD CVE
CVE-2026-61001: Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middle
CRITICAL
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
confidentiality-impactcve-2026-61001cvss-31data-modificationhttpintegrity-impactlow-privileged-attackernetwork-access
2026-08-18
NVD CVE
CVE-2026-62618: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
confidentiality-impactcve-2026-62618cvss-31data-compromisehttpintegrity-impactnetwork-accessnvd-cve
2026-08-18
NVD CVE
CVE-2026-62630: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
availabilityconfidentialitycve-2026-62630cvss-31integritynetwork-accessnvd-cveoracle-fusion-middleware
2026-08-18
NVD CVE
CVE-2026-62633: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
availabilityconfidentialitycve-2026-62633cvss-31httpintegritynetwork-accessnvd-cve
2026-08-18
NVD CVE
CVE-2026-62638: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
2026-08-18
NVD CVE
CVE-2026-71014: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience
CRITICAL
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0....
2026-08-18
NVD CVE
CVE-2026-62632: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
availabilityconfidentialitycve-2026-62632cvss-31httpintegritynetwork-accessnvd-cve
2026-08-18
NVD CVE
CVE-2026-62463: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle
CRITICAL
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability...
2026-08-17
NVD CVE
CVE-2026-74878: openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP bru
CRITICAL
openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on server restart. Attackers can distribute authentication attempts...
authenticationbrute-forcecve-2026-74878incident-responsenvd-cveopensslopenssl-encryptrate-limiter
2026-08-17
NVD CVE
CVE-2026-75110: MemOS is a memory operating system for LLMs and AI agents. In deployments where
CRITICAL
MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment variable is unset,...
ai-agentapi-key-managementauthenticationauthorizationcve-2026-75110data-endpointenvironment-variablesinternal-services
2026-08-17
NVD CVE
CVE-2026-74880: openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query paramet
CRITICAL
openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP...
attackerbrowser-historycve-2026-74880https-referer-headerskeyservernvd-cveopensslopenssl-encrypt