Search
485 CVEs · Critical severity
CVEs (485)
Showing 251–275 of 485
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-60198 | CRITICAL | 9.8 | 2026-07-21 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.… | |
| CVE-2026-60197 | CRITICAL | 9.8 | 2026-07-21 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 an… | |
| CVE-2026-60173 | CRITICAL | 9.8 | 2026-07-21 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 12.2.1.4.0.… | |
| CVE-2026-60168 | CRITICAL | 9.1 | 2026-07-21 | Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 1… | |
| CVE-2026-47731 | CRITICAL | Patched | 9.1 | 2026-07-21 | The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to handle Ground Data Syst… |
| CVE-2026-47056 | CRITICAL | 10.0 | 2026-07-21 | Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.… | |
| CVE-2026-47040 | CRITICAL | 9.1 | 2026-07-21 | Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily e… | |
| CVE-2026-47036 | CRITICAL | 9.8 | 2026-07-21 | Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Siebel Approval Manager). Supported versions that are affected are 17.0-26.3. Easily e… | |
| CVE-2026-46994 | CRITICAL | 9.8 | 2026-07-21 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.… | |
| CVE-2026-46989 | CRITICAL | 9.1 | 2026-07-21 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.5 … | |
| CVE-2026-46983 | CRITICAL | 9.8 | 2026-07-21 | Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 16.0.3. Easily… | |
| CVE-2026-46982 | CRITICAL | 9.8 | 2026-07-21 | Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 14.1.3.2. Easi… | |
| CVE-2026-46924 | CRITICAL | 9.8 | 2026-07-21 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker wi… | |
| CVE-2026-46876 | CRITICAL | 9.8 | 2026-07-21 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker wi… | |
| CVE-2026-35290 | CRITICAL | 9.8 | 2026-07-21 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker wi… | |
| CVE-2026-65057 | CRITICAL | 9.3 | 2026-07-21 | Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supply… | |
| CVE-2026-52472 | CRITICAL | 9.8 | 2026-07-21 | SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml file | |
| CVE-2026-52470 | CRITICAL | 9.8 | 2026-07-21 | SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml file | |
| CVE-2026-52469 | CRITICAL | 9.8 | 2026-07-21 | SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.xml file | |
| CVE-2026-30631 | CRITICAL | 9.8 | 2026-07-21 | An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers to execute arbitrary code via crafted path to `comp… | |
| CVE-2026-64879 | CRITICAL | 9.9 | 2026-07-21 | A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achi… | |
| CVE-2026-64878 | CRITICAL | 9.9 | 2026-07-21 | Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user… | |
| CVE-2026-59147 | CRITICAL | Patched | 9.8 | 2026-07-21 | Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find. The attach-time validator dsu_val… |
| CVE-2026-59145 | CRITICAL | Patched | 9.1 | 2026-07-21 | Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find. The attach-time validator si… |
| CVE-2026-59144 | CRITICAL | Patched | 9.8 | 2026-07-21 | Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time validator ring_validate… |