Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

13,088 CVEs

CVEs (13,088, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 201–225 of 13,088 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-61021 CRITICAL 9.9 2026-08-18 Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1…
CVE-2026-60995 CRITICAL 9.9 2026-08-18 Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1…
CVE-2026-61003 CRITICAL 9.9 2026-08-18 Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 …
CVE-2026-60990 CRITICAL 9.9 2026-08-18 Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1…
CVE-2026-60916 CRITICAL 9.9 2026-08-18 Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.…
CVE-2026-60720 CRITICAL 9.9 2026-08-18 Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.…
CVE-2026-60730 CRITICAL 9.9 2026-08-18 Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0…
CVE-2026-60702 CRITICAL 9.9 2026-08-18 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.…
CVE-2026-75877 CRITICAL 9.9 2026-08-18 A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function SystemNetworkChanged/SystemDDNSChanged/SystemEmailChanged/SystemFTPChanged/w…
CVE-2026-55166 CRITICAL Patched 9.9 2026-08-18 Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-side destination restrict…
CVE-2026-66627 CRITICAL 9.9 2026-08-18 Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion. This issue affects GP Premium: from n/a throu…
CVE-2026-32474 CRITICAL 9.9 2026-08-18 Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.
CVE-2026-32444 CRITICAL 9.9 2026-08-18 Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
CVE-2026-32463 CRITICAL 9.9 2026-08-18 Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
CVE-2026-75851 CRITICAL Patched 9.9 2026-08-18 ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an&hellip;
CVE-2026-75843 CRITICAL Patched 9.9 2026-08-18 ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute Java&hellip;
CVE-2026-66795 CRITICAL 9.9 2026-08-17 A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not &hellip;
CVE-2026-65974 CRITICAL Patched 9.9 2026-08-17 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe sa&hellip;
CVE-2026-47686 CRITICAL Patched 9.9 2026-08-17 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and Ag&hellip;
CVE-2026-66792 CRITICAL 9.9 2026-08-17 A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscr&hellip;
CVE-2026-19961 CRITICAL 9.9 2026-08-16 A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the arg&hellip;
CVE-2026-19959 CRITICAL 9.9 2026-08-16 A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argume&hellip;
CVE-2026-72493 CRITICAL 9.9 2026-08-15 In the Linux kernel, the following vulnerability has been resolved: net: serialize netif_running() check in enqueue_to_backlog() Syzbot reported a KASAN slab-use-after-fr&hellip;
CVE-2026-17186 CRITICAL Patched 9.9 2026-08-14 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.
CVE-2026-19681 CRITICAL Patched 9.9 2026-08-14 An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially &hellip;