|
cve-2026-73942
|
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). |
HIGH
|
8.8
|
N/A
|
cvelistv5 |
2026-09-22 |
|
cve-2026-73941
|
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N). |
HIGH
|
8.6
|
N/A
|
cvelistv5 |
2026-09-21 |
|
cve-2026-73940
|
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2026-09-21 |
|
cve-2026-73926
|
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Access Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N). |
HIGH
|
8.7
|
N/A
|
cvelistv5 |
2026-09-21 |
|
cve-2026-73508
|
io.netty/netty-codec-dns: Netty: Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names |
HIGH
|
7.5
|
N/A
|
cvelistv5 |
2026-09-04 |
|
cve-2026-73194
|
perl-DBI: DBI for Perl: Heap out-of-bounds write via unvalidated numeric placeholder |
HIGH
|
7.3
|
N/A
|
cvelistv5 |
2026-08-25 |
|
cve-2026-73193
|
perl-DBI: DBI: Arbitrary Code Execution on 32-bit Perl via Integer Wraparound |
HIGH
|
7.8
|
N/A
|
cvelistv5 |
2026-08-24 |
|
cve-2026-71290
|
org.apache.httpcomponents/httpclient5: Apache HttpComponents Client: Server impersonation via improper TLS hostname verification |
HIGH
|
8.1
|
N/A
|
cvelistv5 |
2026-09-03 |
|
cve-2026-71163
|
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Access Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Access Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Access Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L). |
CRITICAL
|
9.9
|
N/A
|
cvelistv5 |
2026-09-21 |
|
cve-2026-71133
|
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). |
CRITICAL
|
10.0
|
N/A
|
cvelistv5 |
2026-09-21 |
|
cve-2026-71047
|
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). |
HIGH
|
8.8
|
N/A
|
cvelistv5 |
2026-09-22 |
|
cve-2026-70915
|
cve-2026-70915 |
HIGH
|
8.8
|
N/A
|
cvelistv5 |
unknown |
|
cve-2026-70913
|
cve-2026-70913 |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
unknown |
|
cve-2026-70757
|
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2026-09-16 |
|
cve-2026-70756
|
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2026-09-16 |
|
cve-2026-70755
|
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Web Applications Desktop Integrator accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). |
MEDIUM
|
6.5
|
N/A
|
cvelistv5 |
2026-09-16 |
|
cve-2026-70748
|
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2026-09-16 |
|
cve-2026-69148
|
cve-2026-69148 |
HIGH
|
7.1
|
N/A
|
cvelistv5 |
unknown |
|
cve-2026-69146
|
cve-2026-69146 |
MEDIUM
|
6.5
|
N/A
|
cvelistv5 |
unknown |
|
cve-2026-67355
|
guzzlehttp/guzzle: guzzlehttp/guzzle: Information disclosure from host-only cookie scope issue |
MEDIUM
|
5.9
|
N/A
|
cvelistv5 |
2026-08-27 |
|
cve-2026-67354
|
guzzlehttp/guzzle: guzzlehttp/guzzle: URI Fragment Disclosure in Referer Header |
MEDIUM
|
5.9
|
N/A
|
cvelistv5 |
2026-08-27 |
|
cve-2026-67353
|
guzzlehttp/guzzle: guzzlehttp/guzzle: Denial of Service via unbounded cookie storage |
MEDIUM
|
5.3
|
N/A
|
cvelistv5 |
2026-08-27 |
|
cve-2026-67339
|
guzzlehttp/guzzle: guzzlehttp/guzzle: Proxy-Authorization header disclosure via improper isolation |
MEDIUM
|
5.3
|
N/A
|
cvelistv5 |
2026-08-27 |
|
cve-2026-66299
|
SUSE CVE CVE-2026-66299 |
HIGH
|
7.5
|
N/A
|
cvelistv5 |
2026-09-18 |
|
cve-2026-63308
|
Helm: Helm: Denial of Service via malformed chart files |
MEDIUM
|
4.3
|
N/A
|
cvelistv5 |
2026-08-25 |
|
cve-2026-62597
|
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N). |
MEDIUM
|
6.5
|
N/A
|
cvelistv5 |
2026-09-16 |
|
cve-2026-59943
|
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem |
MEDIUM
|
6.3
|
N/A
|
cvelistv5 |
2026-07-29 |
|
cve-2026-59942
|
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps |
MEDIUM
|
6.3
|
N/A
|
cvelistv5 |
2026-07-29 |
|
cve-2026-59941
|
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions |
MEDIUM
|
6.3
|
N/A
|
cvelistv5 |
2026-07-29 |
|
cve-2026-59921
|
io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder |
MEDIUM
|
5.7
|
N/A
|
cvelistv5 |
2026-08-06 |