Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2026-60950 PUBLISHED LOW 2.2 N/A cvelistv5 2026-07-24
cve-2026-60948 PUBLISHED HIGH 8.1 N/A cvelistv5 2026-07-24
cve-2026-60945 PUBLISHED HIGH 7.3 N/A cvelistv5 2026-07-24
cve-2026-60943 PUBLISHED HIGH 7.5 N/A cvelistv5 2026-07-24
cve-2026-60942 PUBLISHED HIGH 8.1 N/A cvelistv5 2026-07-24
cve-2026-60941 Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment En... HIGH 8.7 N/A cvelistv5 2026-08-13
cve-2026-60940 Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Internal Operations) MEDIUM 5.7 N/A cvelistv5 2026-08-11
cve-2026-60939 PUBLISHED LOW 3.1 N/A cvelistv5 2026-07-24
cve-2026-60938 PUBLISHED MEDIUM 4.1 N/A cvelistv5 2026-07-24
cve-2026-60937 PUBLISHED LOW 3.1 N/A cvelistv5 2026-07-24
cve-2026-60936 PUBLISHED LOW 3.1 N/A cvelistv5 2026-07-24
cve-2026-60932 PUBLISHED HIGH 8.8 N/A cvelistv5 2026-07-24
cve-2026-60931 PUBLISHED HIGH 7.5 N/A cvelistv5 2026-07-24
cve-2026-60930 Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Public Sector Financials accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N). LOW 3.1 N/A cvelistv5 2026-07-29
cve-2026-60929 PUBLISHED LOW 3.1 N/A cvelistv5 2026-07-24
cve-2026-60927 PUBLISHED HIGH 7.5 N/A cvelistv5 2026-07-24
cve-2026-60926 Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations) HIGH 7.2 N/A cvelistv5 2026-08-13
cve-2026-60925 Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations) HIGH 7.2 N/A cvelistv5 2026-08-13
cve-2026-60924 Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations) HIGH 8.8 N/A cvelistv5 2026-08-13
cve-2026-60923 PUBLISHED HIGH 7.7 N/A cvelistv5 2026-07-24
cve-2026-60922 Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSupplier Portal. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle iSupplier Portal accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N). LOW 3.1 N/A cvelistv5 2026-08-06
cve-2026-60920 PUBLISHED HIGH 8.8 N/A cvelistv5 2026-07-24
cve-2026-60919 PUBLISHED LOW 3.7 N/A cvelistv5 2026-07-24
cve-2026-60918 PUBLISHED HIGH 7.2 N/A cvelistv5 2026-07-24
cve-2026-60917 Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Core Receiving). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Inventory Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Inventory Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Inventory Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). HIGH 8.1 N/A cvelistv5 2026-08-06
cve-2026-60913 Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Property Manager executes to compromise Oracle Property Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Property Manager accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N). LOW 1.9 N/A cvelistv5 2026-08-11
cve-2026-60912 Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations) MEDIUM 5.4 N/A cvelistv5 2026-08-11
cve-2026-60911 Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Property Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Property Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Property Manager accessible data as well as unauthorized read access to a subset of Oracle Property Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N). MEDIUM 5.4 N/A cvelistv5 2026-08-11
cve-2026-60910 Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations) HIGH 7.2 N/A cvelistv5 2026-08-11
cve-2026-60908 Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Installed Base accessible data as well as unauthorized update, insert or delete access to some of Oracle Installed Base accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N). HIGH 7.1 N/A cvelistv5 2026-08-13