LIVE FEED
1853 events · 13 sources · newest first
Events in view
1853
all sources
Critical
1853
severity
Active sources
13
collectors
Last sync
2026-08-29 00:00
UTC
All sources
NVD CVE · 1803CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2026-07-21
NVD CVE
CVE-2026-60168: Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beve
CRITICAL
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10. Easily exploitable...
critical-datacvss-31data-compromisedata-modificationdenialdoshospitalityhttp
2026-07-21
NVD CVE
CVE-2026-60565: Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware
CRITICAL
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability...
2026-07-21
NVD CVE
CVE-2026-60631: Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability...
2026-07-21
NVD CVE
CVE-2026-60460: Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio
CRITICAL
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60532: Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion
CRITICAL
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily...
2026-07-21
NVD CVE
CVE-2026-60463: Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middlew
CRITICAL
Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-46983: Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Appl
CRITICAL
Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows...
availabilitycompromiseconfidentialitycve-2026-46983cvss-31httpintegration-busintegrity
2026-07-21
NVD CVE
CVE-2026-46989: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle E
CRITICAL
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability...
critical-datacve-2026-46989cvss-31data-accessdata-compromisedata-integritydenialenterprises-managers
2026-07-21
NVD CVE
CVE-2026-61145: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience
CRITICAL
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily...
2026-07-21
NVD CVE
CVE-2026-60524: Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio
CRITICAL
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-8984: Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remot
CRITICAL
Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download,...
2026-07-21
NVD CVE
CVE-2026-60531: Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion
CRITICAL
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability...
2026-07-21
NVD CVE
CVE-2026-60459: Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio
CRITICAL
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60447: Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio
CRITICAL
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60456: Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio
CRITICAL
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60457: Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio
CRITICAL
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-28314: SolarWinds Serv-U is affected by an insecure direct object reference vulnerabili
CRITICAL
SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.
accounts-takeovercve-2026-28314cybersecuritydata-compromisedfar-252-204-7012incident-responseinsecure-direct-object-referencenist-800-171
2026-07-21
NVD CVE
CVE-2026-46994: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle E
CRITICAL
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable...
agent-next-genavailabilitybase-platformcompromiseconfidentialitycve-2026-46994cvss-31enterprises-managers
2026-07-21
NVD CVE
CVE-2026-8985: Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command
CRITICAL
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to...
2026-07-21
NVD CVE
CVE-2026-60424: Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-60446: Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio
CRITICAL
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60422: Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). The supported version that is affected is 14.1.2.1.0. Easily exploitable vulnerability allows low privileged...
2026-07-21
NVD CVE
CVE-2026-60429: Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-28306: SolarWinds Serv-U is affected by a privilege escalation vulnerability that allow
CRITICAL
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.
cve-2026-28306cybersecuritydomain-administratornvd-cvepatch-managementprivileges-escalationrisk-managementserv-u
2026-07-21
NVD CVE
CVE-2026-28307: SolarWinds Serv-U is affected by a privilege escalation vulnerability that allow
CRITICAL
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.
administrator-privilegescve-2026-28307cybersecurityincident-responsenetwork-securitynvd-cvepatch-managementprivileges-escalation
2026-07-21
NVD CVE
CVE-2026-47036: Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (compon
CRITICAL
Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Siebel Approval Manager). Supported versions that are affected are 17.0-26.3. Easily exploitable vulnerability allows...
availabilitycompromiseconfidentialitycrmcve-2026-47036cvss-31development-toolshttp
2026-07-21
NVD CVE
CVE-2026-60389: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60386: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-8986: Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command
CRITICAL
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that...
2026-07-21
NVD CVE
CVE-2026-28309: SolarWinds Serv-U is affected by a broken access control vulnerability that allo
CRITICAL
SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.
broken-access-controlcve-2026-28309cybersecuritydfar-252-204-7012domain-administratorincident-responsenist-800-171nvd-cve
2026-07-21
NVD CVE
CVE-2026-60375: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60385: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60377: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-65008: Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Bl
CRITICAL
Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments...
authenticate-accountsblueprint-dynamicdatacalls-user-func-arraycve-2026-65008form-plugingravgrav-blueprintsgrav-common-data
2026-07-21
NVD CVE
CVE-2026-60384: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-28302: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vuln
CRITICAL
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The...
cve-2026-28302cybersecuritydfar-252-204-7012groups-administratorsidorincident-responsenist-800-171nvd-cve
2026-07-21
NVD CVE
CVE-2026-60362: Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-60358: Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (
CRITICAL
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60360: Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-13439: The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unaut
CRITICAL
The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow...
administrators-accesscve-2026-13439cybersecuritydata-exposureeasy-form-buildernonce-refreshesnvd-cvepassword-reset