VulnSea

CWE-200

CVEs classified under CWE-200, newest first.

823 CVEsRSS

CVE-2026-61185High· 7.4
2mo ago

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation)

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticat…

▾ Twilightoracle · agile_product_lifecycle_management_for_processEPSS 0.34%via NVD
CVE-2026-61116High· 7.5
2mo ago

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core)

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with …

▾ Twilightoracle · application_object_libraryEPSS 0.44%via NVD
CVE-2026-60647High· 7.1
2mo ago

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management)

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low priv…

▾ Twilightoracle · webcenter_contentEPSS 0.38%via NVD
CVE-2026-60611Medium· 5.3
2mo ago

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security)

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with …

▾ Sunlitoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.34%via NVD
CVE-2026-60610Medium· 5.9
2mo ago

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security)

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker wit…

▾ Sunlitoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.35%via NVD
CVE-2026-60609Medium· 6.5
2mo ago

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Communication)

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Communication). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker w…

▾ Sunlitoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.39%via NVD
CVE-2026-60558High· 8.1
2mo ago

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites)

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated…

▾ Twilightoracle · webcenter_sitesEPSS 0.39%via NVD
CVE-2026-60555Critical· 9.8
2mo ago

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites)

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated a…

▾ Midnightoracle · webcenter_sitesEPSS 0.51%via NVD
CVE-2026-60553High· 8.7
2mo ago

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites)

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated…

▾ Twilightoracle · webcenter_sitesEPSS 0.34%via NVD
CVE-2026-60552Critical· 9.9
2mo ago

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites)

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged at…

▾ Midnightoracle · webcenter_sitesEPSS 0.43%via NVD
CVE-2026-60551Critical· 9.8
2mo ago

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites)

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated a…

▾ Midnightoracle · webcenter_sitesEPSS 0.51%via NVD
CVE-2026-60408Medium· 4.3
2mo ago

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator)

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileg…

▾ Sunlitoracle · timesten_in-memory_databaseEPSS 0.30%via NVD
CVE-2026-60405Low· 3.8
2mo ago

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator)

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileg…

▾ Sunlitoracle · timesten_in-memory_databaseEPSS 0.15%via NVD
CVE-2026-60395Medium· 4.3
2mo ago

Vulnerability in Oracle GoldenGate (component: Admin Server Executable)

Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with …

▾ Sunlitoracle · goldengateEPSS 0.30%via NVD
CVE-2026-60394Medium· 5.3
2mo ago

Vulnerability in Oracle GoldenGate (component: Admin Server Executable)

Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTT…

▾ Sunlitoracle · goldengateEPSS 0.34%via NVD
CVE-2026-60354Low· 3.7
2mo ago

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Data Visualization Tools)

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Data Visualization Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthentic…

▾ Sunlitoracle · jdeveloperEPSS 0.27%via NVD
CVE-2026-60352Low· 3.7
2mo ago

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces)

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker w…

▾ Sunlitoracle · jdeveloperEPSS 0.27%via NVD
CVE-2026-60350Medium· 6.5
2mo ago

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces)

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with…

▾ Sunlitoracle · jdeveloperEPSS 0.17%via NVD
CVE-2026-60349Medium· 5.9
2mo ago

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Java Business Objects)

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Java Business Objects). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged…

▾ Sunlitoracle · jdeveloperEPSS 0.32%via NVD
CVE-2026-47009Medium· 6.5
2mo ago

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments)

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with netw…

▾ Sunlitoracle · agile_product_lifecycle_managementEPSS 0.39%via NVD
CVE-2026-60548High· 7.7
2mo ago

Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight)

Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privil…

▾ TwilightEPSS 0.39%via NVD
GHSA-rwj8-pgh3-r573High· 7.5
2mo ago

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

▾ Twilightgitpython · gitpythonvia GHSA
CVE-2026-58419High· 7.5
2mo ago

Gitea: Notification API leaks private issue metadata after access revocation

Gitea: Notification API leaks private issue metadata after access revocation

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.51%via GHSA
CVE-2026-58427Medium
2mo ago

Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

▾ Sunlitgitea.dev · gitea.devEPSS 0.47%via GHSA
CVE-2026-58510Medium· 4.3
2mo ago

Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private

Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.33%via GHSA
CVE-2026-57897Medium· 6.5
2mo ago

Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs

Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.41%via GHSA
CVE-2026-58511Low· 2.7
2mo ago

Gitea: Webhook Authorization Header Returned in Plaintext via API

Gitea: Webhook Authorization Header Returned in Plaintext via API

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.39%via GHSA
CVE-2026-58432Medium· 5.9
2mo ago

Gitea: draft release attachment disclosure via missing web authorization

Gitea: draft release attachment disclosure via missing web authorization

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.43%via GHSA
CVE-2026-58425Medium· 4.3
2mo ago

Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)

Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.33%via GHSA
CVE-2026-58507Medium· 5.3
2mo ago

Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint

Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.38%via GHSA
CWE-200 vulnerabilities (CVEs) — page 19 · VulnSea