Known Exploited Vulnerabilities (KEV)
| ID | Title | Severity | CVSS | EPSS | Source | Updated |
|---|---|---|---|---|---|---|
| cve-2026-60170 | PUBLISHED | HIGH | 7.5 | 0.41% | cvelistv5 | 2026-07-23 |
| cve-2026-60169 | PUBLISHED | HIGH | 8.1 | 0.39% | cvelistv5 | 2026-07-23 |
| cve-2026-60168 | PUBLISHED | CRITICAL | 9.1 | 0.45% | cvelistv5 | 2026-07-23 |
| cve-2026-60167 | PUBLISHED | HIGH | 7.5 | 0.44% | cvelistv5 | 2026-07-23 |
| cve-2026-60166 | SUSE CVE CVE-2026-60166 | LOW | 3.1 | 0.27% | cvelistv5 | 2026-08-31 |
| cve-2026-60165 | PUBLISHED | MEDIUM | 6.5 | 0.41% | cvelistv5 | 2026-09-17 |
| cve-2026-60164 | SUSE CVE CVE-2026-60164 | LOW | 3.1 | 0.27% | cvelistv5 | 2026-08-31 |
| cve-2026-60163 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin) | HIGH | 8.4 | 0.19% | cvelistv5 | 2026-09-15 |
| cve-2026-60162 | PUBLISHED | MEDIUM | 6.1 | 0.14% | cvelistv5 | 2026-07-29 |
| cve-2026-60161 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H). | MEDIUM | 6.1 | 0.13% | cvelistv5 | 2026-07-30 |
| cve-2026-60160 | PUBLISHED | LOW | 3.2 | 0.17% | cvelistv5 | 2026-07-23 |
| cve-2026-60159 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H). | HIGH | 7.5 | 0.15% | cvelistv5 | 2026-07-28 |
| cve-2026-60158 | PUBLISHED | MEDIUM | 6.4 | 0.12% | cvelistv5 | 2026-07-23 |
| cve-2026-60157 | PUBLISHED | HIGH | 8.8 | 0.43% | cvelistv5 | 2026-07-23 |
| cve-2026-60156 | Vulnerability in Oracle APEX (component: General). Supported versions that are affected are 24.1, 24.2 and 26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle APEX. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle APEX accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). | MEDIUM | 5.3 | 0.34% | cvelistv5 | 2026-08-06 |
| cve-2026-60155 | PUBLISHED | HIGH | 7.5 | 0.15% | cvelistv5 | 2026-07-28 |
| cve-2026-60154 | PUBLISHED | MEDIUM | 5.4 | 0.23% | cvelistv5 | 2026-08-05 |
| cve-2026-60153 | PUBLISHED | HIGH | 7.2 | 0.49% | cvelistv5 | 2026-07-28 |
| cve-2026-60152 | PUBLISHED | MEDIUM | 5.4 | 0.24% | cvelistv5 | 2026-07-23 |
| cve-2026-60151 | CVE-2026-60151 | HIGH | N/A | N/A | cvelistv5 | 2026-07-14 |
| cve-2026-60150 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). | HIGH | 7.8 | 0.16% | cvelistv5 | 2026-07-28 |
| cve-2026-60149 | PUBLISHED | MEDIUM | 5.2 | 0.13% | cvelistv5 | 2026-07-23 |
| cve-2026-60147 | openjdk: Improve certification checking (Oracle CPU 2026-07) | MEDIUM | 6.5 | 0.29% | cvelistv5 | 2026-08-10 |
| cve-2026-60146 | PUBLISHED | MEDIUM | 6.1 | 0.24% | cvelistv5 | 2026-07-23 |
| cve-2026-60145 | SUSE CVE CVE-2026-60145 | UNKNOWN | N/A | 0.42% | cvelistv5 | 2026-08-25 |
| cve-2026-60144 | PUBLISHED | LOW | 3.6 | 0.11% | cvelistv5 | 2026-07-23 |
| cve-2026-60143 | PUBLISHED | HIGH | 7.3 | 0.31% | cvelistv5 | 2026-07-23 |
| cve-2026-5795 | In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variabl... | HIGH | 7.4 | 0.61% | cvelistv5 | 2026-09-14 |
| cve-2026-56164 | Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability | MEDIUM | 5.3 | 1.01% | cvelistv5 | 2026-07-14 |
| cve-2026-56155 | Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability | HIGH | 7.8 | 0.35% | cvelistv5 | 2026-07-14 |