Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-46984 Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions th… Enterprise Manager Base Platform No fix yet Fix from $1,6002026-07-21 CRITICAL 9.8 CVE-2026-46983 Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is aff… Retail Integration Bus No fix yet Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2026-46982 Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is aff… Retail Integration Bus No fix yet Fix from $2,3002026-07-21 MEDIUM 5.9 CVE-2026-46968 Vulnerability in Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.… Jre No fix yet Fix from $1,6002026-07-21 HIGH 7.5 CVE-2026-46941 Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Maintenance). Supported versions that are affected a… Cost Management No fix yet Fix from $1,9502026-07-21 CRITICAL 9.8 CVE-2026-46924 Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unau… Application Testing Suite No fix yet Fix from $2,3002026-07-21 MEDIUM 5.3 CVE-2026-46917 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supporte… Graalvm No fix yet Fix from $1,6002026-07-21 CRITICAL 9.8 CVE-2026-46876 Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unau… Application Testing Suite No fix yet Fix from $2,3002026-07-21 HIGH 8.9 CVE-2026-43945 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to ach… Mitigation only Fix from $1,9502026-07-21 CRITICAL 9.8 CVE-2026-35290 Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unau… Application Testing Suite No fix yet Fix from $2,3002026-07-21 HIGH 7.5 CVE-2026-35287 Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unau… Application Testing Suite No fix yet Fix from $1,9502026-07-21 MEDIUM 6.1 CVE-2026-34316 Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center). The supported version that is … Commerce Service Center No fix yet Fix from $1,6002026-07-21 HIGH 7.3 CVE-2026-16484 A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file… No fix yet Fix from $1,9502026-07-21 CRITICAL 9.3 CVE-2026-65057 Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary … Mitigation only Fix from $2,3002026-07-21 HIGH 8.2 CVE-2026-65056 mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loo… No fix yet Fix from $1,9502026-07-21 MEDIUM 5.3 CVE-2026-65055 Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full member roster and internal wor… No fix yet Fix from $1,6002026-07-21 HIGH 7.5 CVE-2026-52476 SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the getPageData method in the Datacenter… No fix yet Fix from $1,9502026-07-21 MEDIUM 6.1 CVE-2026-52475 Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the UploadController.java file No fix yet Fix from $1,6002026-07-21 HIGH 7.5 CVE-2026-52474 An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUtil.java file. No fix yet Fix from $1,9502026-07-21 MEDIUM 6.5 CVE-2026-63080 Aptabase through commit 5a89368 contains a SQL injection vulnerability in the ClickHouse query backend that allows authenticated attackers to read ev… No fix yet Fix from $1,6002026-07-21 CRITICAL 9.8 CVE-2026-52472 SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml file No fix yet Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2026-52470 SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml file Mitigation only Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2026-52469 SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.xml file No fix yet Fix from $2,3002026-07-21 HIGH 7.1 CVE-2026-47697 Shelf is a platform for tracking physical assets. Shelf is multi-tenant; data is isolated per organization (workspace). Prior to version 1.20.2, seve… No fix yet Fix from $1,9502026-07-21 HIGH 7.1 CVE-2026-47695 CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to version 1.119.0, CC-Tweaked's HTTP API … No fix yet Fix from $1,9502026-07-21 MEDIUM 6.9 CVE-2026-45383 libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.0.19 have a heap buffer overflow (out-of-bounds READ) exists … No fix yet Fix from $1,6002026-07-21 MEDIUM 6.9 CVE-2026-45382 libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.19, `decoder_context::decode_slice_unit_tiles` (libde265/dec… No fix yet Fix from $1,6002026-07-21 HIGH 7.2 CVE-2026-44879 A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote attacker to perform command injec… No fix yet Fix from $1,9502026-07-21 HIGH 7.2 CVE-2026-44878 A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the … No fix yet Fix from $1,9502026-07-21 MEDIUM 5.3 CVE-2026-16318 The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store the peer's transport parameters… No fix yet Fix from $1,6002026-07-21