Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2026-5598 Covert timing channel vulnerability in Legion of the Bouncy Castle Inc HIGH 8.9 0.96% cvelistv5 2026-09-18
cve-2026-5588 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc MEDIUM 6.3 0.69% cvelistv5 2026-09-18
cve-2026-54518 jackson-databind: jackson-databind: Information disclosure and data manipulation via view-based access control bypass MEDIUM 6.5 0.35% cvelistv5 2026-07-13
cve-2026-54515 SUSE CVE CVE-2026-54515 MEDIUM 5.3 0.44% cvelistv5 2026-07-24
cve-2026-54285 @opentelemetry/core: opentelemetry-js: @opentelemetry/core: Denial of Service via oversized baggage HTTP headers MEDIUM 5.3 0.40% cvelistv5 2026-06-29
cve-2026-4800 Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the vari... HIGH 8.1 2.62% cvelistv5 2026-09-10
cve-2026-4738 GDAL Bundled zlib (inftree9.c) Pointer Offset Optimization Undefined Behavior Allows Heap Corruption or Remote Code Execution CRITICAL 9.4 0.43% cvelistv5 2026-06-17
cve-2026-47064 mysql: Optimizer unspecified vulnerability (CPU Jul 2026) MEDIUM 6.5 0.37% cvelistv5 2026-08-19
cve-2026-47063 openjdk: Enhance Jar handling (Oracle CPU 2026-07) HIGH 7.5 0.35% cvelistv5 2026-08-10
cve-2026-47062 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). MEDIUM 5.5 0.14% cvelistv5 2026-07-27
cve-2026-47061 PUBLISHED MEDIUM 5.6 0.24% cvelistv5 2026-07-23
cve-2026-47060 PUBLISHED MEDIUM 6.5 0.32% cvelistv5 2026-07-23
cve-2026-47059 SUSE CVE CVE-2026-47059 LOW 3.7 0.31% cvelistv5 2026-08-31
cve-2026-47058 SUSE CVE CVE-2026-47058 HIGH 7.4 0.39% cvelistv5 2026-09-16
cve-2026-47057 SUSE CVE CVE-2026-47057 HIGH 7.5 0.47% cvelistv5 2026-09-16
cve-2026-47056 PUBLISHED CRITICAL 10.0 0.51% cvelistv5 2026-07-23
cve-2026-47055 PUBLISHED LOW 3.2 0.15% cvelistv5 2026-07-23
cve-2026-47054 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability applies to Windows host only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). HIGH 7.8 0.16% cvelistv5 2026-07-28
cve-2026-47053 PUBLISHED MEDIUM 5.6 0.14% cvelistv5 2026-07-23
cve-2026-47052 SUSE CVE CVE-2026-47052 UNKNOWN N/A 0.45% cvelistv5 2026-08-25
cve-2026-47051 PUBLISHED MEDIUM 5.4 0.21% cvelistv5 2026-07-23
cve-2026-47050 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H). HIGH 7.4 0.16% cvelistv5 2026-07-27
cve-2026-47049 PUBLISHED MEDIUM 4.9 0.40% cvelistv5 2026-07-23
cve-2026-47048 PUBLISHED MEDIUM 5.4 0.21% cvelistv5 2026-07-23
cve-2026-47047 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). HIGH 7.8 0.16% cvelistv5 2026-07-28
cve-2026-47046 PUBLISHED HIGH 8.2 0.41% cvelistv5 2026-07-23
cve-2026-47045 PUBLISHED MEDIUM 6.8 0.40% cvelistv5 2026-07-23
cve-2026-47044 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). MEDIUM 5.5 0.15% cvelistv5 2026-07-27
cve-2026-47043 PUBLISHED LOW 3.2 0.17% cvelistv5 2026-07-23
cve-2026-47041 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H). MEDIUM 6.0 0.17% cvelistv5 2026-07-27