Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2026-60680 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H). HIGH 8.1 N/A cvelistv5 2026-08-21
cve-2026-60679 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). HIGH 7.5 N/A cvelistv5 2026-08-21
cve-2026-60672 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core) CRITICAL 9.8 N/A cvelistv5 2026-08-21
cve-2026-60592 Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator) HIGH 8.2 N/A cvelistv5 2026-09-02
cve-2026-60591 Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS) CRITICAL 9.1 N/A cvelistv5 2026-09-04
cve-2026-60590 Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS) HIGH 7.5 N/A cvelistv5 2026-09-04
cve-2026-60589 SUSE CVE CVE-2026-60589 LOW 3.7 N/A cvelistv5 2026-09-12
cve-2026-60415 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). HIGH 8.1 N/A cvelistv5 2026-08-21
cve-2026-60414 Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). HIGH 7.8 N/A cvelistv5 2026-08-21
cve-2026-60413 Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). HIGH 7.8 N/A cvelistv5 2026-08-21
cve-2026-60412 Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). HIGH 7.8 N/A cvelistv5 2026-08-21
cve-2026-60393 Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). HIGH 7.5 N/A cvelistv5 2026-08-25
cve-2026-60392 Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). HIGH 7.8 N/A cvelistv5 2026-08-21
cve-2026-60391 Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). HIGH 7.5 N/A cvelistv5 2026-08-24
cve-2026-59889 com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Privilege escalation via improper handling of @JsonUnwrapped properties MEDIUM 6.5 N/A cvelistv5 2026-09-02
cve-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerability CRITICAL N/A N/A cvelistv5 2026-08-18
cve-2026-59084 SUSE CVE CVE-2026-59084 HIGH 7.3 N/A cvelistv5 2026-08-31
cve-2026-59083 tomcat: Apache Tomcat: Security constraint bypass via improper URL encoding in rewrite valve LOW 3.7 N/A cvelistv5 2026-08-06
cve-2026-55955 tomcat: Apache Tomcat: Replay attack via improper authentication in EncryptionInterceptor MEDIUM 4.2 N/A cvelistv5 2026-07-08
cve-2026-55276 SUSE CVE CVE-2026-55276 LOW 3.3 N/A cvelistv5 2026-08-31
cve-2026-55040 Microsoft SharePoint Weak Authentication Vulnerability HIGH N/A N/A cvelistv5 2026-08-18
cve-2026-53434 SUSE CVE CVE-2026-53434 MEDIUM 6.5 N/A cvelistv5 2026-08-31
cve-2026-53404 SUSE CVE CVE-2026-53404 MEDIUM 6.5 N/A cvelistv5 2026-08-31
cve-2026-50229 SUSE CVE CVE-2026-50229 MEDIUM 6.1 N/A cvelistv5 2026-08-31
cve-2026-49978 SUSE CVE CVE-2026-49978 UNKNOWN N/A N/A cvelistv5 2026-09-15
cve-2026-49975 SUSE CVE CVE-2026-49975 HIGH 7.5 N/A cvelistv5 2026-09-10
cve-2026-49459 SUSE CVE CVE-2026-49459 UNKNOWN N/A N/A cvelistv5 2026-07-16
cve-2026-49458 SUSE CVE CVE-2026-49458 UNKNOWN N/A N/A cvelistv5 2026-07-16
cve-2026-48913 SUSE CVE CVE-2026-48913 MEDIUM 5.9 N/A cvelistv5 2026-08-31
cve-2026-45446 SUSE CVE CVE-2026-45446 MEDIUM 5.3 N/A cvelistv5 2026-09-20