LIVE FEED
1516 events · 13 sources · newest first
Events in view
1516
all sources
Critical
1516
severity
Active sources
13
collectors
Last sync
2026-08-28 12:00
UTC
All sources
NVD CVE · 1794CISA KEV · 1686News · 424CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2026-08-18
NVD CVE
CVE-2026-61206: Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyper
CRITICAL
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low...
availability-impactcompromiseconfidentiality-impactcve-2026-61206cvss-31cvss-99https-vulnerabilityintegrity-impact
2026-08-18
NVD CVE
CVE-2026-61066: Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware
CRITICAL
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability...
availabilityconfidentialitycve-2026-61066cvss-31integritylow-privileged-attackernetwork-accessnvd-cve
2026-08-18
NVD CVE
CVE-2026-70978: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience
CRITICAL
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily...
2026-08-18
NVD CVE
CVE-2026-71014: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience
CRITICAL
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0....
2026-08-18
NVD CVE
CVE-2026-62610: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
confidentiality-impactcritical-datacve-2026-62610cvss-31data-compromisehttpintegrity-impactnetwork-access
2026-08-18
NVD CVE
CVE-2026-62611: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
availability-impactcompromiseconfidentiality-impactcve-2026-62611cvss-31cvss-98iiopintegrity-impact
2026-08-18
NVD CVE
CVE-2026-12564: A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The
CRITICAL
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and...
api-accessesawxcredentials-theftcve-2026-12564database-credentialsdjangohashicorphashicorp-vault
2026-08-18
NVD CVE
CVE-2026-75784: A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this
CRITICAL
A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the...
buffer-overflowcve-2026-75784cybersecurityhttps-header-handlernetwork-securitynginxnvd-cvepublic-exploit
2026-08-18
NVD CVE
CVE-2026-75913: CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an
CRITICAL
CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv...
arbitrary-file-writeargument-injectionbashrccode-executioncodewhalecodewhale-tuicve-2026-75913git-show
2026-08-18
NVD CVE
CVE-2026-18963: A flaw was found in the reset-credentials flow of the keycloak-services componen
CRITICAL
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated...
accounts-takeovercredentials-compromisecve-2026-18963email-verification-bypassidentity-and-access-managementkeycloakkeycloak-servicenvd-cve
2026-08-18
NVD CVE
CVE-2026-70920: Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hype
CRITICAL
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low...
2026-08-18
NVD CVE
CVE-2026-70954: Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (compon
CRITICAL
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows...
availabilityconfidentialitycve-2026-70954cvss-31cvss-98dynamo-application-frameworkhttpintegrity
2026-08-18
NVD CVE
CVE-2026-75626: SpiderFoot fails to HTML-escape correlation titles built from external scan data
CRITICAL
SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation...
api-keys-theftcorrelationcross-site-scriptingcve-2026-75626event-handlerexternal-datahtml-escapemalicious-html
2026-08-18
NVD CVE
CVE-2026-15748: The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload
CRITICAL
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in...
arbitrary-files-uploadcve-2026-15748executable-filefile-validationfiles-uploadforminatormime-typenvd-cve
2026-08-18
NVD CVE
CVE-2026-75627: Bastillion fails to properly validate request URI paths in its controller dispat
CRITICAL
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers...
administrative-controllerauthentication-bypassbastillioncontrollers-dispatcherscve-2026-75627fleet-controlmanaged-systemsmanagers-accounts
2026-08-18
NVD CVE
CVE-2026-75837: Grav before 2.0.14 fails to guard the access field in the core group blueprint w
CRITICAL
Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to...
access-controlaccess-fieldsblueprintcore-groupcve-2026-75837delegated-adminsgravgrav-2-0-14
2026-08-18
NVD CVE
CVE-2026-75094: A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_
CRITICAL
A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid of the component CGI Interface. This manipulation of the argument...
attack-surfacecf-n1-scgi-bincgi-interfacecomfastcve-2026-75094networks-devicesnvd-cve
2026-08-18
NVD CVE
CVE-2026-74944: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed i
CRITICAL
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
cve-2026-74944domdom-corefirefoxfreehtml-componentmozillanvd-cve
2026-08-18
NVD CVE
CVE-2026-70958: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle
CRITICAL
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable...
nvd-cve
2026-08-18
NVD CVE
CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component. This vulnerability was
CRITICAL
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
browsers-vulnerabilitiescode-executioncve-2026-74936firefoxfirefox-esrfreejavascriptmemory-corruption
2026-08-18
NVD CVE
CVE-2026-62638: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
2026-08-18
NVD CVE
CVE-2026-62621: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
availabilityconfidentialitycve-2026-62621cvss-31integritynetwork-accessnvd-cveoracle-fusion-middleware
2026-08-18
NVD CVE
CVE-2026-70976: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience
CRITICAL
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily...
availability-impactcontent-acquisition-systemscve-2026-70976cvss-31data-creationdata-deletiondata-modificationdos
2026-08-18
NVD CVE
CVE-2026-71152: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CRITICAL
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker...
2026-08-18
NVD CVE
CVE-2026-70880: Vulnerability in the Oracle Hyperion Data Relationship Management product of Ora
CRITICAL
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable...
2026-08-18
NVD CVE
CVE-2026-70876: Vulnerability in the Oracle Hyperion Data Relationship Management product of Ora
CRITICAL
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable...
2026-08-18
NVD CVE
CVE-2026-70953: Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (compon
CRITICAL
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows...
2026-08-18
NVD CVE
CVE-2026-70862: Vulnerability in Oracle Application Testing Suite. The supported version that
CRITICAL
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise...
2026-08-18
NVD CVE
CVE-2026-70855: Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (co
CRITICAL
Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpdesk/Training). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows...
2026-08-18
NVD CVE
CVE-2026-70871: Vulnerability in the Oracle Hyperion Data Relationship Management product of Ora
CRITICAL
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable...
2026-08-18
NVD CVE
CVE-2026-70846: Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (comp
CRITICAL
Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows low...
2026-08-18
NVD CVE
CVE-2026-70817: Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hype
CRITICAL
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows...
2026-08-18
NVD CVE
CVE-2026-71036: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience
CRITICAL
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily...
2026-08-18
NVD CVE
CVE-2026-71065: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CRITICAL
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated...
2026-08-18
NVD CVE
CVE-2026-70854: Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hype
CRITICAL
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows...
2026-08-18
NVD CVE
CVE-2026-70872: Vulnerability in the Oracle Hyperion Data Relationship Management product of Ora
CRITICAL
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable...
2026-08-18
NVD CVE
CVE-2026-70740: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyper
CRITICAL
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows...
2026-08-18
NVD CVE
CVE-2026-70739: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyper
CRITICAL
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows...
availabilityconfidentialitycve-2026-70739cvss-31httpintegritynetwork-accessnvd-cve
2026-08-18
NVD CVE
CVE-2026-70741: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyper
CRITICAL
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows...
2026-08-18
NVD CVE
CVE-2026-70745: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyper
CRITICAL
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows...