VulnSea

CWE-400

CVEs classified under CWE-400, newest first.

622 CVEsRSS

CVE-2026-83459Medium· 5.3
1w ago

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-media-multipart)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-media-multipart). Supported versions that are affected are 3.0.0-3.2.20. Easily exploitable vulnerability allows unauthenticated attacker with network …

▾ SunlitOracle Corporation · HelidonEPSS 0.40%via NVD
CVE-2026-83458Medium· 5.3
1w ago

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: JSON)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: JSON). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to c…

▾ SunlitOracle Corporation · HelidonEPSS 0.40%via NVD
CVE-2026-83457High· 8.1
1w ago

Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged at…

▾ TwilightOracle Corporation · Oracle Demand Signal RepositoryEPSS 0.43%via NVD
CVE-2026-83436High· 7.1
1w ago

Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Recall Management)

Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Recall Management). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with ne…

▾ TwilightOracle Corporation · Oracle Depot RepairEPSS 0.40%via NVD
CVE-2026-83416Medium· 4.3
1w ago

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privil…

▾ Sunlitoracle · coherenceEPSS 0.37%via NVD
CVE-2026-83369Low· 3.1
1w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Access SDK)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Access SDK). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attack…

▾ Sunlitoracle · access_managerEPSS 0.29%via NVD
CVE-2026-83350High· 7.5
1w ago

Vulnerability in the Oracle Net Services component of Oracle Database Server

Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access …

▾ TwilightOracle Corporation · Oracle Database ServerEPSS 0.46%via NVD
CVE-2026-83349High· 7.5
1w ago

Vulnerability in the Oracle Net Services component of Oracle Database Server

Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with net…

▾ TwilightOracle Corporation · Oracle Database ServerEPSS 0.46%via NVD
CVE-2026-83347Medium· 6.5
1w ago

Vulnerability in the Oracle Net Services component of Oracle Database Server

Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCPS to comp…

▾ SunlitOracle Corporation · Oracle Database ServerEPSS 0.36%via NVD
CVE-2026-83345High· 7.1
1w ago

Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install)

Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network acces…

▾ TwilightOracle Corporation · Oracle XML GatewayEPSS 0.40%via NVD
CVE-2026-83333High· 7.5
1w ago

Vulnerability in the Oracle Net Services component of Oracle Database Server

Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net t…

▾ TwilightOracle Corporation · Oracle Database ServerEPSS 0.46%via NVD
CVE-2026-83330High· 7.5
1w ago

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP…

▾ TwilightOracle Corporation · HelidonEPSS 0.46%via NVD
CVE-2026-83281High· 7.5
1w ago

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access …

▾ TwilightOracle Corporation · HelidonEPSS 0.46%via NVD
CVE-2026-83280High· 7.5
1w ago

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-http2)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-http2). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network a…

▾ TwilightOracle Corporation · HelidonEPSS 0.46%via NVD
CVE-2026-83276High· 7.5
1w ago

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webclient-http2)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webclient-http2). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network a…

▾ TwilightOracle Corporation · HelidonEPSS 0.46%via NVD
CVE-2026-83251Medium· 6.5
1w ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthen…

▾ SunlitOracle Corporation · Oracle Commerce Guided Search / Oracle Commerce Experience ManagerEPSS 0.34%via NVD
CVE-2026-83248High· 8.2
1w ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenti…

▾ TwilightOracle Corporation · Oracle Commerce Guided Search / Oracle Commerce Experience ManagerEPSS 0.43%via NVD
CVE-2026-83228High· 7.5
1w ago

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure)

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with networ…

▾ Twilightoracle · siebel_crmEPSS 0.47%via NVD
CVE-2026-83225High· 7.5
1w ago

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure)

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with networ…

▾ Twilightoracle · siebel_crmEPSS 0.47%via NVD
CVE-2026-83222High· 7.5
1w ago

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure)

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with networ…

▾ Twilightoracle · siebel_crmEPSS 0.47%via NVD
CVE-2026-83183High· 7.5
1w ago

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure)

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with networ…

▾ Twilightoracle · siebel_crmEPSS 0.47%via NVD
CVE-2026-73960High· 7.5
1w ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Ren Server)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Ren Server). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows unauthenticated attacker with netwo…

▾ TwilightOracle Corporation · PeopleSoft Enterprise PeopleToolsEPSS 0.46%via NVD
CVE-2026-76679High· 8.6
1w ago

Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct denial-of-service attacks

Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct denial-of-service attacks. Successful exploitation could allow an attacker to crash the system, preventing it from …

▾ TwilightHewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN GatewaysEPSS 0.46%via NVD
CVE-2026-76686High· 7.5
1w ago

A vulnerability exists in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways

A vulnerability exists in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an unauthenticated remote attacker to conduct a denial-of-service attack on the affected service.

▾ TwilightHewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN GatewaysEPSS 0.57%via NVD
CVE-2026-76693High· 7.0
1w ago

A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service against certain services running on impacted Gateways.

A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service against certain services running on impacted Gateways.

▾ TwilightHewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN GatewaysEPSS 0.36%via NVD
CVE-2026-76696Medium· 6.5
1w ago

A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct a denial of service attack

A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to crash the system, preventing it from…

▾ SunlitHewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN GatewaysEPSS 0.27%via NVD
CVE-2026-76700Medium· 5.9
1w ago

Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service

Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected …

▾ SunlitHewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN GatewaysEPSS 0.46%via NVD
CVE-2026-76702Medium· 5.8
1w ago

A vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways could allow an authenticated local attacker to cause a denial-of-service

A vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways could allow an authenticated local attacker to cause a denial-of-service. Successful exploitation could allow an attacker to disrupt system operations,…

▾ SunlitHewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN GatewaysEPSS 0.11%via NVD
CVE-2026-88975High· 7.5
1w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses a frame’s 24-bit declared length but waits to buffer the entire payload before comparing it with SETTINGS_MAX_FRAME_SIZE. An u…

▾ Twilighthttp4s · http4sEPSS 0.63%via NVD
CVE-2026-69203High· 7.5
1w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, An Ember server with HTTP/2 enabled through withHttp2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS for peer-created streams. One unauthenticated connectio…

▾ Twilighthttp4s · org.http4s:http4s-ember-core_2.12EPSS 0.63%via NVD
CWE-400 vulnerabilities (CVEs) — page 5 · VulnSea