VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

17365 CVEsRSS

CVE-2026-73946Critical· 9.1
2w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privile…

▾ Midnightoracle · access_managerEPSS 0.49%via NVD
CVE-2026-73945Critical· 9.9
2w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileg…

▾ Midnightoracle · access_managerEPSS 0.43%via NVD
CVE-2026-73944Critical· 9.1
2w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthentica…

▾ Midnightoracle · access_managerEPSS 0.43%via NVD
CVE-2026-73943High· 7.6
2w ago

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI)

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged at…

▾ Twilightoracle · identity_managerEPSS 0.34%via NVD
CVE-2026-73942High· 8.8
2w ago

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI)

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged att…

▾ Twilightoracle · identity_managerEPSS 0.43%via NVD
CVE-2026-73941High· 8.6
2w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthentica…

▾ Twilightoracle · access_managerEPSS 0.41%via NVD
CVE-2026-73940Critical· 9.8
2w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthentica…

▾ Midnightoracle · access_managerEPSS 0.51%via NVD
CVE-2026-73926High· 8.7
2w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privile…

▾ Twilightoracle · access_managerEPSS 0.41%via NVD
CVE-2026-71163Critical· 9.9
2w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileg…

▾ Midnightoracle · access_managerEPSS 0.39%via NVD
CVE-2026-71133Critical· 10.0
2w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthentica…

▾ Midnightoracle · access_managerEPSS 0.51%via NVD
CVE-2026-71047High· 8.8
2w ago

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker wit…

▾ Twilightoracle · identity_managerEPSS 0.43%via NVD
CVE-2026-70915High· 8.8
2w ago

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker wit…

▾ Twilightoracle · identity_managerEPSS 0.43%via NVD
CVE-2026-70913Critical· 9.8
2w ago

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker wi…

▾ Midnightoracle · identity_managerEPSS 0.51%via NVD
CVE-2026-70757Critical· 9.8
2w ago

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unau…

▾ Midnightoracle · weblogic_serverEPSS 0.51%via NVD
CVE-2026-70756Critical· 9.8
2w ago

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unau…

▾ Midnightoracle · weblogic_serverEPSS 0.51%via NVD
CVE-2026-70755Medium· 6.5
2w ago

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download)

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileg…

▾ SunlitOracle Corporation · Oracle Web Applications Desktop IntegratorEPSS 0.34%via NVD
CVE-2026-70748Critical· 9.8
2w ago

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unau…

▾ Midnightoracle · weblogic_serverEPSS 0.48%via NVD
CVE-2026-62597Medium· 6.5
2w ago

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management)

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privil…

▾ SunlitOracle Corporation · Oracle Enterprise Manager Base PlatformEPSS 0.30%via NVD
CVE-2026-61544High· 8.2PoC
2w ago

libp2p-rust is the official Rust language implementation of the libp2p networking stack

libp2p-rust is the official Rust language implementation of the libp2p networking stack. Prior to 0.13.1, libp2p-quic could panic during an inbound QUIC handshake when a remote peer presented a valid short-lived libp2p TLS certificate an…

▾ Midnightlibp2p · rust-libp2pEPSS 0.28%via NVD
CVE-2026-51134High· 7.5PoC
2w ago

The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameter in show-movies.pml.

The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameter in show-movies.pml.

▾ MidnightEPSS 1.7%via NVD
CVE-2026-51133Medium· 6.1PoC
2w ago

Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary code via the size parameter in ptzpreset.pml component and the showmovies.pml component

Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary code via the size parameter in ptzpreset.pml component and the showmovies.pml component

▾ TwilightEPSS 0.91%via NVD
CVE-2026-32599Medium· 5.3
2w ago

Netmaker makes networks with WireGuard

Netmaker makes networks with WireGuard. Prior to version 1.5.0, the `sqliteDeleteRecord` function in Netmaker's database layer constructs SQL `DELETE` statements using direct string concatenation of user-supplied input. This allows an au…

▾ Sunlitgravitl · netmakerEPSS 0.36%via NVD
CVE-2026-18425Low· 2.7
2w ago

Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashboard\SitemapUpdate) using only the global access_sitemap task permission and did not check per-page edit permission before upda…

Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashboard\SitemapUpdate) using only the global access_sitemap task permission and did not check per-page edit permission before upda…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.12%via NVD
CVE-2026-18424High· 7.1⚖ disputed
2w ago

Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Request Forgery iremote file import via cross-port reuse of a host's validated DNS pin

Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Request Forgery iremote file import via cross-port reuse of a host's validated DNS pin. When multiple remote URLs share the same host, only the first `ValidatedRemoteUrl` is retain…

▾ Twilightconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-88743Medium· 6.1PoC
2w ago

Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in director tags.

Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in director tags.

▾ TwilightEPSS 0.26%via NVD
CVE-2026-88742Medium· 5.4
2w ago

Bacularis 1.0.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in the client address field.

Bacularis 1.0.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in the client address field.

▾ SunlitEPSS 0.24%via NVD
CVE-2026-13327High· 8.3
2w ago

Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept privileged directory service credentials via a spoofed domain controll…

Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept privileged directory service credentials via a spoofed domain controll…

▾ TwilightDevolutions · ServerEPSS 0.13%via NVD
CVE-2026-69217High· 8.7
2w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HTTP/1.1 parser accepts differing duplicate Content-Length headers and uses the last value instead of rejecting the message. When an Ember server is b…

▾ Twilighthttp4s · http4sEPSS 0.50%via NVD
CVE-2026-69215Medium· 6.8
2w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware uses unanchored substring checks instead of RFC 6265 domain and path matching when deciding whether to attach a stored cookie.…

▾ Sunlithttp4s · org.http4s:http4s-client_2.12EPSS 0.51%via NVD
CVE-2026-69210High· 7.5
2w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, WebSocket FrameTranscoder.bodyLength rejects extended payload lengths above Integer.MAX_VALUE but permits negative 64-bit lengths. A remote client that comple…

▾ Twilighthttp4s · http4sEPSS 0.63%via NVD
CVEs tagged “cve.org” — page 266 · VulnSea